vlc-2.0.1-win32.exe

Babylon Ltd.

This is part of the Babylon web browser toolbar and extension that will modify the browser's default search provider, DNS, and home page functions. The application vlc-2.0.1-win32.exe by Babylon has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. This is a setup program which is used to install the application. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from dl.cdn-services.com.
Publisher:
Babylon Ltd.  (signed and verified)

MD5:
4729982ca9be7ce17b41491cc3de3b9a

SHA-1:
950f52d02d24b30deed5c84ebca5e59a01a5e574

SHA-256:
7e0067d8e291581516bfcb92536853018a4451759647f520430f4a168c911c44

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 3:42:23 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Babylon (M)
15.12.19.19

File size:
865.6 KB (886,424 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\vlc-2.0.1-win32.exe

Digital Signature
Signed by:

Authority:
Thawte, Inc.

Valid from:
2/27/2012 5:45:00 AM

Valid to:
3/9/2014 5:44:59 AM

Subject:
CN=Babylon Ltd., O=Babylon Ltd., L=Or-Yehuda, S=Or-Yehuda, C=IL

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
48C39FBA62460E24E169054FE518E0AF

File PE Metadata
Compilation timestamp:
2/5/2012 11:57:30 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
24576:+UvpohWx/Cm1gTxafnRlFQQzMSelfPOYtgeKOz9ne9:bpOW5yTiFxzMFfmYp+

Entry address:
0x1762

Entry point:
55, 8B, EC, 83, E4, F8, 81, EC, 38, 02, 00, 00, A1, 00, 50, 40, 00, 33, C4, 89, 84, 24, 34, 02, 00, 00, 56, 57, 33, FF, 57, FF, 15, 40, 40, 40, 00, 6A, 0A, 8B, F0, 68, E8, 41, 40, 00, 56, FF, 15, 5C, 40, 40, 00, 3B, C7, 74, 16, 50, 8D, 44, 24, 20, 50, 8D, 44, 24, 20, 50, 56, E8, 61, 03, 00, 00, 83, C4, 10, EB, 05, B8, 16, 07, 00, 00, 3B, C7, 0F, 85, BB, 00, 00, 00, 8B, C6, 8D, 4C, 24, 20, 89, 7C, 24, 08, 89, 7C, 24, 0C, 89, 7C, 24, 10, C7, 44, 24, 14, 03, 00, 00, 00, E8, 23, F8, FF, FF, 3B, C7, 0F, 85, 94...
 
[+]

Entropy:
7.9956

Developed / compiled with:
Microsoft Visual C++

Code size:
12 KB (12,288 bytes)

The file vlc-2.0.1-win32.exe has been seen being distributed by the following URL.

Remove vlc-2.0.1-win32.exe - Powered by Reason Core Security