handbrake-0.9.6-i686-win_gui.exe

Babylon Ltd.

This is part of the Babylon web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application handbrake-0.9.6-i686-win_gui.exe by Babylon has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider.
Publisher:
Babylon Ltd.  (signed and verified)

MD5:
af627306c30b57b665d9c917c338608c

SHA-1:
e8047a26349d1d4cb4ec362af7bb68f48926ceb3

SHA-256:
2a37ca4a0098b5b8649580cb662c7c74686114e953531985804f7f43158edb6c

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/10/2024 4:10:13 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Babylon (M)
17.3.13.5

File size:
869.1 KB (890,008 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\handbrake-0.9.6-i686-win_gui.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
2/26/2012 4:00:00 PM

Valid to:
3/8/2014 3:59:59 PM

Subject:
CN=Babylon Ltd., O=Babylon Ltd., L=Or-Yehuda, S=Or-Yehuda, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
48C39FBA62460E24E169054FE518E0AF

File PE Metadata
Compilation timestamp:
2/4/2012 10:12:30 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0x1762

Entry point:
55, 8B, EC, 83, E4, F8, 81, EC, 38, 02, 00, 00, A1, 00, 50, 40, 00, 33, C4, 89, 84, 24, 34, 02, 00, 00, 56, 57, 33, FF, 57, FF, 15, 40, 40, 40, 00, 6A, 0A, 8B, F0, 68, E8, 41, 40, 00, 56, FF, 15, 5C, 40, 40, 00, 3B, C7, 74, 16, 50, 8D, 44, 24, 20, 50, 8D, 44, 24, 20, 50, 56, E8, 61, 03, 00, 00, 83, C4, 10, EB, 05, B8, 16, 07, 00, 00, 3B, C7, 0F, 85, BB, 00, 00, 00, 8B, C6, 8D, 4C, 24, 20, 89, 7C, 24, 08, 89, 7C, 24, 0C, 89, 7C, 24, 10, C7, 44, 24, 14, 03, 00, 00, 00, E8, 23, F8, FF, FF, 3B, C7, 0F, 85, 94...
 
[+]

Entropy:
7.9959

Developed / compiled with:
Microsoft Visual C++

Code size:
12 KB (12,288 bytes)

The file handbrake-0.9.6-i686-win_gui.exe has been seen being distributed by the following URL.

http://dl.cdn-services.com/files/prtnrp/.../HandBrake-0.9.6-i686-Win_GUI.exe

Remove handbrake-0.9.6-i686-win_gui.exe - Powered by Reason Core Security