uninstbb.exe

Babylon Ltd.

This is part of the Babylon web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application uninstbb.exe by Babylon has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. While running, it connects to the Internet address ba-sh-nl-dc1-.005.com on port 80 using the HTTP protocol.
Publisher:
Babylon Ltd.  (signed and verified)

MD5:
f9b1db0627faf9b0f1a460786a6c0eb7

SHA-1:
b244f8d1448504b91f5eaad4e5f455f469c2674d

SHA-256:
743e604a243076ae9d2d4cc1c497a8f16dbf5281ed71ea66023ce101c4257dda

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/24/2024 12:02:07 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Babylon.I
14.8.7.19

File size:
295.7 KB (302,816 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\babylon\babylon-pro\utils\uninstbb.exe

Digital Signature
Signed by:

Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
2/8/2007 1:00:00 AM

Valid to:
3/4/2008 12:59:59 AM

Subject:
CN=Babylon Ltd., OU=SECURE APPLICATION DEVELOPMENT, O=Babylon Ltd., L=Or-Yehuda, S=Or-Yehuda, C=IL

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
5B4F1D6192C4E67D48917FA06B93483F

File PE Metadata
Compilation timestamp:
12/18/2007 1:37:48 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
3072:TJIYlpL2LjUnEK3TOysT0MEYOfuEieESp5ytY7fq9e13tBM6nxHit2D:TjfCL6EKCyXHfchfV9stpFD

Entry address:
0x208DA

Entry point:
E8, 3C, 85, 00, 00, E9, 16, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, 54, 24, 0C, 8B, 4C, 24, 04, 85, D2, 74, 69, 33, C0, 8A, 44, 24, 08, 84, C0, 75, 16, 81, FA, 00, 01, 00, 00, 72, 0E, 83, 3D, 34, A3, 44, 00, 00, 74, 05, E9, EA, 85, 00, 00, 57, 8B, F9, 83, FA, 04, 72, 31, F7, D9, 83, E1, 03, 74, 0C, 2B, D1, 88, 07, 83, C7, 01, 83, E9, 01, 75, F6, 8B, C8, C1, E0, 08, 03, C1, 8B, C8, C1, E0, 10, 03, C1, 8B, CA, 83, E2, 03, C1, E9, 02, 74, 06, F3, AB, 85, D2, 74, 0A, 88, 07, 83, C7, 01...
 
[+]

Entropy:
6.2157

Code size:
195.5 KB (200,192 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to ba-sh-nl-dc-006.babsft.com  (107.6.141.14:80)

TCP (HTTP):
Connects to DedLoadLM2200.babylon.com  (184.154.27.235:80)

TCP (HTTP):
Connects to LB2200.babylon.com  (69.175.64.72:80)

TCP (HTTP):
Connects to ba-sh-nl-dc1-.005.com  (198.20.96.179:80)

TCP (HTTP):
Connects to singhop0014.babylon.com  (96.127.151.131:80)

TCP (HTTP):
Connects to ba-sh-nl-dc1-007.babsft.com  (198.20.106.254:80)

TCP (HTTP):
Connects to ba-sh-us-dc4-010.babsft.com  (65.60.2.78:80)

TCP (HTTP):
Connects to ba-sh-us-dc1-020.babsft.com  (69.175.51.134:80)

Remove uninstbb.exe - Powered by Reason Core Security