terus russian-hebrew hebrew-russian.exe

Babylon Ltd.

This is part of the Babylon web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application terus russian-hebrew hebrew-russian.exe by Babylon has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider.
Publisher:
Babylon Ltd.  (signed and verified)

MD5:
67848afc3f557bdcd1bb69705c34aec9

SHA-1:
c7c8bd6a1fed2062a076fb1e48cbbb40bbd55479

SHA-256:
3233a3cda48df980d78be73f53a6556df6799aab65c5165addafe753169fe10d

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/20/2024 4:32:20 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Babylon (M)
15.8.3.8

File size:
4.3 MB (4,541,664 bytes)

File type:
Executable application (Win32 EXE)

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
2/13/2006 4:00:00 AM

Valid to:
2/28/2007 3:59:59 AM

Subject:
CN=Babylon Ltd., OU=SECURE APPLICATION DEVELOPMENT, O=Babylon Ltd., L=Or-Yehuda, S=Or-Yehuda, C=IL

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
1271E01D90B147DCF80E63DAC35146A7

File PE Metadata
Compilation timestamp:
1/7/2005 8:37:41 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:9t9RFL0BooxX6BtevcT91c8YV7daB46723IMi0+OjtrYgesH5c:rFLWoo16ys92X678Id0FZHu

Entry address:
0x3E1C

Entry point:
83, EC, 20, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 92, 40, 00, C6, 44, 24, 14, 20, FF, 15, 28, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 68, 54, 92, 40, 00, 68, 20, E8, 42, 00, A3, D0, F0, 42, 00, E8, 72, 2A, 00, 00, BE, 00, 64, 43, 00, BF, 00, 04, 00, 00, 56, 57, FF, 15, C4, 70, 40, 00, E8, 7A, FF, FF, FF, 8B, 2D, 8C, 70, 40, 00, 85, C0, 75, 21, 68, FB, 03, 00, 00, 56, FF, 15, C0, 70, 40, 00, 68, 4C, 92, 40, 00, 56, FF, D5, E8, 57, FF, FF, FF, 85, C0, 0F, 84, 47, 01, 00, 00, BE, 00, 50...
 
[+]

Code size:
23 KB (23,552 bytes)

Remove terus russian-hebrew hebrew-russian.exe - Powered by Reason Core Security