ares_downloader.exe

The application ares_downloader.exe has been detected as a potentially unwanted program by 11 anti-malware scanners. This is a setup program which is used to install the application. It uses the InstallCore engine which may bundle additional software offers including toolbars and browser extensions. The file has been seen being downloaded from www.instalki.pl.
MD5:
a44066c5cc30c1898b028f1174277ad0

SHA-1:
8526f04800782b443cf9630922c975e24f5cd3d4

SHA-256:
1a2db180bbfcc6535a862aad583600c867f6645d11611c7b490296970334ad50

Scanner detections:
11 / 68

Status:
Potentially unwanted

Explanation:
Uses the InstallCore download manager to install additional potentially unwanted software which may include extensions such as DealPly and various toolbars.

Analysis date:
12/26/2024 12:41:54 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Gen:Variant.Adware.Strictor.53094
5813571

Avira AntiVirus
Adware/InstallCor.C
7.11.98.72

Comodo Security
UnclassifiedMalware
16831

Dr.Web
Adware.InstallCore.75
9.0.1.05190

Emsisoft Anti-Malware
Gen:Variant.Adware.Strictor.53094
16.01.11

ESET NOD32
Win32/InstallCore.AW potentially unwanted application
7.0.302.0

F-Prot
W32/InstallCore.P.gen
4.6.5.141

Norman
Gen:Variant.Adware.Strictor.53094
10.01.2016 08:42:03

Trend Micro House Call
TROJ_GEN.RCBH1A3
7.2.10

Vba32 AntiVirus
BScope.Malware-Cryptor.InstallCore.2691
3.12.22.3

VIPRE Antivirus
Trojan.Win32.Generic
20920

File size:
1.1 MB (1,125,744 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\ares_downloader.exe

File PE Metadata
Compilation timestamp:
6/20/1992 12:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
12288:Upu35FLxfZEVlgMdgdosf98cCT1xRorUCdgKk6YQDwHHMKMGql0Ju5PiFE+ZfqjN:UpM8dG81ITgK0J5JEiFyYt

Entry address:
0xCD3D0

Entry point:
55, 8B, EC, 83, C4, F0, B8, EC, 3D, 40, 00, E8, 12, F2, FF, FF, 8B, C0, FF, 25, 94, 71, 46, 00, 8B, C0, FF, 25, 90, 71, 46, 00, 8B, C0, FF, 25, 8C, 71, 46, 00, 8B, C0, FF, 25, 88, 71, 46, 00, 8B, C0, FF, 25, 84, 71, 46, 00, 8B, C0, FF, 25, 80, 71, 46, 00, 8B, C0, FF, 25, 7C, 71, 46, 00, 8B, C0, FF, 25, 78, 71, 46, 00, 8B, C0, FF, 25, 74, 71, 46, 00, 8B, C0, FF, 25, 70, 71, 46, 00, 8B, C0, FF, 25, 6C, 71, 46, 00, 8B, C0, FF, 25, D8, 71, 46, 00, 8B, C0, FF, 25, 68, 71, 46, 00, 8B, C0, FF, 25, 64, 71, 46, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
837.5 KB (857,600 bytes)

The file ares_downloader.exe has been seen being distributed by the following URL.

Remove ares_downloader.exe - Powered by Reason Core Security