install_reader10_fr_mssd_aih.exe

Babylon Ltd.

This is part of the Babylon web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application install_reader10_fr_mssd_aih.exe by Babylon has been detected as adware by 4 anti-malware scanners. This is a setup program which is used to install the application. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from dl.babylon.com.
Publisher:
Babylon Ltd.  (signed and verified)

MD5:
5d18918135d31d19bed5504153ee0c52

SHA-1:
f0be5a3e2779cb6ba364999162f2515be1b0c3e3

SHA-256:
d29dee061fa27b447565a39cfb8353b2c7b0ee496fb402a8ca2ffe596ef25b89

Scanner detections:
4 / 68

Status:
Adware

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
4/16/2024 9:41:03 PM UTC  (today)

Scan engine
Detection
Engine version

Dr.Web
Adware.Toolbar.146
9.0.1.0191

ESET NOD32
Win32/Toolbar.Babylon (variant)
8.8502

Reason Heuristics
PUP.Babylon.CC
14.8.7.19

VIPRE Antivirus
Babylon
19116

File size:
776.1 KB (794,776 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
2/27/2012 1:00:00 AM

Valid to:
3/9/2014 12:59:59 AM

Subject:
CN=Babylon Ltd., O=Babylon Ltd., L=Or-Yehuda, S=Or-Yehuda, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
48C39FBA62460E24E169054FE518E0AF

File PE Metadata
Compilation timestamp:
2/5/2012 7:12:30 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
12288:Pnf2QvBIcRiKMfXQBgwJp7vIkDXIBsofNX9O0lBjYLt9eEHG34XUJVgzlaQ4b:PuQ9RiDfXGgw59M9fi0rotYEm3preM

Entry address:
0x1762

Entry point:
55, 8B, EC, 83, E4, F8, 81, EC, 38, 02, 00, 00, A1, 00, 50, 40, 00, 33, C4, 89, 84, 24, 34, 02, 00, 00, 56, 57, 33, FF, 57, FF, 15, 40, 40, 40, 00, 6A, 0A, 8B, F0, 68, E8, 41, 40, 00, 56, FF, 15, 5C, 40, 40, 00, 3B, C7, 74, 16, 50, 8D, 44, 24, 20, 50, 8D, 44, 24, 20, 50, 56, E8, 61, 03, 00, 00, 83, C4, 10, EB, 05, B8, 16, 07, 00, 00, 3B, C7, 0F, 85, BB, 00, 00, 00, 8B, C6, 8D, 4C, 24, 20, 89, 7C, 24, 08, 89, 7C, 24, 0C, 89, 7C, 24, 10, C7, 44, 24, 14, 03, 00, 00, 00, E8, 23, F8, FF, FF, 3B, C7, 0F, 85, 94...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
12 KB (12,288 bytes)

The file install_reader10_fr_mssd_aih.exe has been seen being distributed by the following URL.

Remove install_reader10_fr_mssd_aih.exe - Powered by Reason Core Security