ares_setup.exe

Ares

This is a setup and installation application. The file has been seen being downloaded from www.signtowntoday.com and multiple other hosts.
Publisher:
Ares

Product:
Ares

Description:
Ares Setup

Version:
3.1.9.4045

MD5:
bbcfbe58c06422736d9c9b8df3b81230

SHA-1:
1fb773ec7a1cb7b6f49159592de49555b260ad2b

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 9:55:37 PM UTC  (today)

File size:
4.6 MB (4,848,168 bytes)

Product version:
3.1.9.4045

File type:
Executable application (Win32 EXE)

Common path:
C:\Documents and Settings\{user}\Local settings\temporary internet files\content.ie5\{random}\ares_setup.exe

File PE Metadata
Compilation timestamp:
7/16/2015 3:24:20 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
98304:9njHB+9KLB9AjGSc0Z2sPewyQ8R1cv/RJx5buuMpnvBkLkrjdMHlG:9nFaxqR0Z2sHy5RkTx1uuMpnjyFG

Entry address:
0x113BC

Entry point:
55, 8B, EC, 83, C4, A4, 53, 56, 57, 33, C0, 89, 45, C4, 89, 45, C0, 89, 45, A4, 89, 45, D0, 89, 45, C8, 89, 45, CC, 89, 45, D4, 89, 45, D8, 89, 45, EC, B8, 34, 00, 41, 00, E8, E8, 51, FF, FF, 33, C0, 55, 68, 9E, 1A, 41, 00, 64, FF, 30, 64, 89, 20, 33, D2, 55, 68, 5A, 1A, 41, 00, 64, FF, 32, 64, 89, 22, A1, 48, 5B, 41, 00, E8, 1E, D8, FF, FF, E8, 6D, D3, FF, FF, 80, 3D, DC, 2A, 41, 00, 00, 74, 0C, E8, 33, D9, FF, FF, 33, C0, E8, 80, 32, FF, FF, 8D, 55, EC, 33, C0, E8, E2, A3, FF, FF, 8B, 55, EC, B8, 54, 86...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
63.5 KB (65,024 bytes)

The file ares_setup.exe has been seen being distributed by the following 29 URLs.

http://www.signtowntoday.com/WVl6OTRQVlkwZUZacWVUVjFZMDFHWW1oSmIzVTRRelpGZUVwRmVETndhbFZSYjNRd1ZYZE1TMnc1TjJwdFpXc2xNMFFtWXowNGVsSmtiblZoYWpkVVpqbHVTMEl5U0dweGJITjNSRWRHVlRaQ1VscHNWVzlXTVdoV1dVTklObXRPZEVaSk5XVllaSGxNWTB4QmJFTTBkems0VWxkNVRrWkZZbFZaWmt0YWNDVXlRa2xqUkRSa2IyTk1WemhwVmxCT2RtdHJTa1o2Y25jbE1rSjFkRE5FU21saVFrZHpORmNsTWtad0pUSkNOMlpuTW10dlNXNWpTamhKTTBoQ1JpVXlRbVZ6VlVsWE4ydDZaa2R6SlRKQ0pUSkdhbWsxTUhsaVp5VXpSQ1V6UkNabFBURW1abUZzYkdKaFkydGZkWEpzUFdoMGRIQWxNMkVsTW1ZbE1tWm1hV3hsY3kxa2IzZHViRzloWkM1d2IzSmhaRzVwYTJSdlozSjVMbkJzSlRKbVNXNTBaWEp1WlhSSlUybGxZMmtsTW1aUVpXVnlWRzlRWldWeUpUSm1RWEpsY3lVeVprRnlaWE5mVTJWMGRYQXVaWGhsSm1SdmQyNXNiMkZrUVhNOVFYSmxjeXN6TGpFdVpYaGw=

http://www.bytesendclear.com/WVl6OTRQVWxIV2xCeFJsWlRZa0pyZVd0SlpXWk1jbEpoTm5aUU4wMVNjRFJEWjFoNEpUSkdORzl3SlRKQ01rNUZXa0p6SlRORUptTTlWVFphUm1GbFdVdHBiME5vTlVKV1UzRXhWa0o1SlRKR1ozVnBSbTE0VUVSSWRGSjFSbTVrUzFoaE1HSm9aQ1V5UWs4MmJ6TkRVamxMZGxKcVRWTkhjRzVSVEVSNGVHVnVNVzV2V0d0cllXWlFPWGN6UTBGa1duSkxhbGQxU3pJbE1rWXdiWFJzTUhaNlZHOWhkREZoY3poVmJ5VXlRbk1sTWtKRGIxTXhURXhrVFU1clV6VndPRFJGVmxoS2FIVlZkU1V5Um1WTmRXUnFhR2xJYTBJeGVUVm5KVE5FSlRORUptVTlNU1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6WVNVeVppVXlabVpwYkdWekxXUnZkMjVzYjJGa0xuQnZjbUZrYm1sclpHOW5jbmt1Y0d3bE1tWkpiblJsY201bGRFbFRhV1ZqYVNVeVpsQmxaWEpVYjFCbFpYSWxNbVpCY21WekpUSm1RWEpsYzE5VFpYUjFjQzVsZUdVbVpHOTNibXh2WVdSQmN6MUJjbVZ6S3pNdU1TNWxlR1U9

http://www.farmchucklevaults.com/4MoU0_B0ns8X2qPBShkQh6DMekpCRtY8cw6DEbBvJWZVTK _4ojyfLKgeZ kPMdKCf4d51tGoaZq8fkhvBsaPCic4xtAjz411oK7wGy vtBZrU1BbhEtBCjTfYbw9SZb35HjbcZ1bjUvy nWK09qo6SU3tqP7Vp5kmz7gkZbW Ric5pSMiFJ3CUVyEhd2Zb210JPLbCRsI40CM5nJPlXOWoojzTsA e7bcgCrI9Tv_R842Vug3BzHv2z96Z340t92Ya9V8HtwVxfcf3IqvjOQ8DsiwOESf9B 9B4AHIwHVwp1gUdMgmvQnH5asWUVdUYu9dXOFZnMFhWBm8I91sDLQbixjUgHsYJOcl2kWiniq wEowaJgO_qVRPnSMF4cWsQ6GUl0QRpXYPEp6dKE4WFMQm14Ud BPtjydVk_L68T HYPj_YfMqjy_CT1bByPVyPHO mnxgfDgx2 Eh3fEP8R7LDleM3mWHnfVRmsdye1XPZDZEMrX83cQeb5J81U8Z1PuPf5WGDZNQ1vt_1ZAkJs81OF6mFscClbBnQtLclrGJFBoEYnsHcRVdG4tx9ry9ZKaUF91oB67TzVcL27sMkv7shpOYhMvWwRqkRTt6dPjxKa3rbjJMMfJDU9DzSD56qcA7s5Ny4yeNbQZHPABNwgtGJoch1hUiZIYnUjupxWmI2M_GRLBfusyHQywVdm_gvwfibPJSsNTZbDHdvvQaW50exx6vknjTz7Suppl8RrAicYff9JlYnjWrxygkYgF8DNE3vM6uhFuEePY7aYuM_areesm iq77kH oIP7mRX9ck_2_FFHHDvGoiNoZkBfDZP6CAWv3ZjmcgzXSvzLcQlzDodvCNwviElawJ6pUxzpHJ6xynOp 8zVxodMjz zMLLsN CKtmXIFyb4LWfaQEAlq6Ek1w==-G 0CAOR znebzk0ihzWl8l1Ti48AJvwCgn3qpm

https://d2lbygqu0tqwrz.cloudfront.net/Ares_Galaxy_2.4.3y_Setup.exe

http://www.bytesendclear.com/c?x=vWzgNyszpIJhiu80qaoyLMUTA5QWj MW9BhA9zccWRM=&e=1&c=kV1R53TwkVsrF4YLrvDf3GOtLvKCwFM0oXx8mWVLrwMmMcd4zL4OM9iXEkHnkhHjsHjbOW1aX575AEGpXVPmFJsdb4 rvDb06sjxmGBAD/HjyJ6fs4Pobcrcvmi8T9HMo8eAq5kMeBge0xNN1vE GK2Vn2anM3v0F k32EmX9SY=&fallback_url=http://files-download.poradnikdogry.pl/InternetISieci/PeerToPeer/.../Ares_Setup.exe&downloadAs=Ares 3.1.exe

http://www.signtowntoday.com/WVl6OTRQWFZpYjJkSk1ua2xNa0ptVFZFNEpUSkdSRmNsTWtZeWJsWjFSbXBYWkhNM2MySm1VSFpHUkdjMVNXTXhka1IxU1c4bE0wUW1ZejFrYkc0d2NEVjZlR2xvVlZWRE1Fc3dVMUJFU0hkelUzVmtaR2MyVFZWWGVUaFlheVV5Um1SMmF6Tm5OMlJzWld3d01FWkNla2hVYkhvNVNIVXdNbEEzZVZScFkzZFNSV1ZtTlVkbWNsUXpTWGhUUVZVbE1rWnpjM1pzVTJWdFZrMUxheVV5Um1aYU0zaEpVSEpRWkVWWGNrTlJjU1V5Um5KUmNVRk5iRVJYYlhwcVpUWWxNa0pEU1dwblExbHZRamRoTlVkRGRFbHRVemh5WTB4c1NqVkJKVE5FSlRORUptVTlNU1ptWVd4c1ltRmphMTkxY213OWFIUjBjQ1V6WVNVeVppVXlabVpwYkdWekxXUnZkMjVzYjJGa0xuQnZjbUZrYm1sclpHOW5jbmt1Y0d3bE1tWkpiblJsY201bGRFbFRhV1ZqYVNVeVpsQmxaWEpVYjFCbFpYSWxNbVpCY21WekpUSm1RWEpsYzE5VFpYUjFjQzVsZUdVbVpHOTNibXh2WVdSQmN6MUJjbVZ6S3pNdU1TNWxlR1U9

Scan ares_setup.exe - Powered by Reason Core Security