installer_ares_spanish.exe

One Installer LLC

This is the Vittalia Filewon Installer which bundles applications with offers for additional 3rd party software, mostly unwanted adware, and may be installed with minimal consent. The application installer_ares_spanish.exe by One Installer has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the Vittalia DM installer. The file has been seen being downloaded from dv.1aab813gfl.com.
Publisher:
One Installer LLC  (signed and verified)

MD5:
511b523924672b4019a0c79d271ce61b

SHA-1:
2660ad1ba1a63b90ec0c3fd56a5430a3af461407

SHA-256:
72588ec45317dfa22fe12134aff3c4690924e0578aaf0dd6d0dec523675f5bce

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Bundles additional software, mostly toolbars and other potentially unwanted applications using the Vittalia monitization installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/25/2024 2:41:17 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Vittalia (M)
17.3.13.1

File size:
811.8 KB (831,248 bytes)

File type:
Executable application (Win32 EXE)

Bundler/Installer:
Vittalia DM (using Nullsoft Install System)

Common path:
C:\users\{user}\downloads\installer_ares_spanish.exe

Digital Signature
Authority:
GoDaddy.com, Inc.

Valid from:
11/6/2013 4:20:03 PM

Valid to:
6/24/2016 6:26:08 PM

Subject:
CN=One Installer LLC, O=One Installer LLC, L=Wilmington, S=Delaware, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
280F69FCB8F054

File PE Metadata
Compilation timestamp:
12/5/2009 11:52:12 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, 1C, 45, 00, E8, F1, 2B, 00, 00, A3, 64, 1B, 45, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 37, 43, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, DB, 44, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, A0, 47, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file installer_ares_spanish.exe has been seen being distributed by the following URL.

http://dv.1aab813gfl.com/installers/axtan_installers/get.php?ne=1&ik=36HlJ5/h8NfauHGI99d2BWW /N WMqjV5HgvPuOExys=&ut=9c54eac9028844a9171b8c027c4335ab&aa=lp/1/seo//&ua=chrome&u=vQPR0N6tLf6wzDrTqVe9hOQJHVfQxl8LkBPI/LFt eOBFrO6OlsZt6GphOdGIR8WK8lCDoCWJDt AY72dOgFwJCaB78igKJBTDAIwIPPXbHND/5Wlkq dmy3vm e3nQD8xSRzW822hnFzRLOf41rTcQXxu1eAz43D11TtH0oTFDpZINjFoNi/T9BpDbcQ9mkhoeWvRzbteTgOA2BhMMRs6nzxP7Nuqt17dJkhcja5LY SFHg0rcHecAuZGPcTFQIUefsQaVMZkQuaQlaSuJulHXy/MfZA dfYBy5w4cauXuBPrunYUXfRjaR4Ts4GydQYV41XHlWkHDSz6rj8570BQl1B3d6dTAF4boYJRjB18EMzQXLp1arPGD7QZxqdF4/&p=U0VP&x=R9ZctQHiGMl3Cpa0Fncem/7onx KO4b5sIA5E1S2vvidsITwHo2cSmJPq7gVIXd2skTaBUzi9trqVvkk5po4N8Vk vW3RpI/SHybcSENeja5wCmlzbzpC9V0NNNA/PqkWDWwq0D4fBhE2/8ipImq6i0CzhfTLVID3MxxIYqnHRkuaW6wFD8Iugb5PQN81389dzLIDO2xeWukwMAGEWr4yLY61PuhpQ2cUoFFT EBIc8rwavCF5dXd/.../W4=&loop=0&s=&popito=1

Remove installer_ares_spanish.exe - Powered by Reason Core Security