ares_tube_setup.exe

The application ares_tube_setup.exe has been detected as a potentially unwanted program by 12 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer, however the file is not signed with an authenticode signature from a trusted source. This will display context specific advertisements in the browser as well as attempt to modify the browser's search provider. The file has been seen being downloaded from ares.mp3.es.
MD5:
a23a3dd90d768c5030532b3e0230e4f2

SHA-1:
0bb11668825d218eb50be4b0e667d3d4a30b4f3f

SHA-256:
01415841d6c97c3207ef976543ffe6ceacf427606f4a3ceca7302da851c4a51d

Scanner detections:
12 / 68

Status:
Potentially unwanted

Explanation:
The installer may include an offer for the Babylon Toolbar (a homepage/search hijacker), which is potentially installed with minimal user consent.

Analysis date:
5/7/2024 12:58:29 PM UTC  (today)

Scan engine
Detection
Engine version

Agnitum Outpost
PUA.Toolbar.Babylon
7.1.1

avast!
NSIS:Toggle-H [PUP]
2014.9-160323

AVG
Toolbar
2017.0.2796

Baidu Antivirus
Adware.Win32.Bbylon
4.0.3.16323

Clam AntiVirus
Win.Trojan.Agent-588910
0.98/21511

Dr.Web
Adware.Toolbar
9.0.1.083

ESET NOD32
Win32/Toggle potentially unwanted
10.12746

Fortinet FortiGate
W32/Toggle
3/23/2016

IKARUS anti.virus
Hoax.Win32.ArchSMS
t3scan.1.9.5.0

Kaspersky
not-a-virus:HEUR:AdWare.NSIS.Gottle
14.0.0.474

NANO AntiVirus
Riskware.Text.Toolbar.dgrniq
1.0.10.5081

VIPRE Antivirus
Babylon
45930

File size:
1.6 MB (1,674,057 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\downloads\ares_tube_setup.exe

File PE Metadata
Compilation timestamp:
12/5/2009 4:50:52 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:aTzQgk+OLPbs2wk+y19xV3XZ1/wB9mMj9kYjZrGGBv+zEJSEZS0Gc3xY0gWSjAzD:+0eO7/FDdV51/w/kQJ+wdZhnjiG

Entry address:
0x30FA

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, 60, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 18, EC, 42, 00, E8, F1, 2B, 00, 00, A3, 64, EB, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 98, 8F, 42, 00, FF, 15, 58, 71, 40, 00, 68, 54, 91, 40, 00, 68, 60, E3, 42, 00, E8, A4, 28, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 40, 43, 00, 50, 57, E8, 92, 28, 00, 00...
 
[+]

Entropy:
7.4476

Packer / compiler:
Nullsoft install system v2.x

Code size:
23.5 KB (24,064 bytes)

The file ares_tube_setup.exe has been seen being distributed by the following URL.

Remove ares_tube_setup.exe - Powered by Reason Core Security