aurora_1.0.0.3031.exe

AuroraBrowser

AURORA NETWORK COMPANY LIMITED

This is a setup program which is used to install the application. The file has been seen being downloaded from 95.141.193.17 and multiple other hosts.
Publisher:
AuroraBrowser.COM  (signed by AURORA NETWORK COMPANY LIMITED)

Product:
AuroraBrowser

Version:
1.0.0.3031

MD5:
a37503a97652da58cb21d4a728fe6b68

SHA-1:
63d51c6df42beee9616b7c368e875d855d603df1

SHA-256:
905434d47c3bed729cfd8b79b99c9a765ef6e59757a03e37db8729a11a7af9a4

Scanner detections:
1 / 68

Status:
Inconclusive  (not enough data for an accurate detection)

Analysis date:
11/23/2024 3:25:28 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Hao123.H potentially unwanted (variant)
9.12724

File size:
2.1 MB (2,162,736 bytes)

Product version:
1.0.0.3031

Copyright:
Copyright 2015 Aurora Network Company Limited. All rights reserved.

Original file name:
setup.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
DigiCert Inc

Valid from:
7/24/2015 5:30:00 AM

Valid to:
7/26/2016 5:30:00 PM

Subject:
CN=AURORA NETWORK COMPANY LIMITED, O=AURORA NETWORK COMPANY LIMITED, L=Hong Kong, C=HK, PostalCode=HK, STREET="Unit 04, 7/F Bright Way Tower No.33 Mong Kok Rd, Kln", SERIALNUMBER=2237249, OID.1.3.6.1.4.1.311.60.2.1.3=HK, OID.2.5.4.15=Private Organization

Issuer:
CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0BDEC9C484B67149205C8B50942140A6

File PE Metadata
Compilation timestamp:
12/11/2015 5:31:14 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:85+SHcRTRgDF9hVYR+EAbPoj+z5igrWrr87kVGCDrlLqJY+1IB:W+SHcRSxuR+fbPuYigraIKGCDrlG31m

Entry address:
0x2C37C

Entry point:
E8, 82, 97, 00, 00, E9, 78, FE, FF, FF, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 83, 3D, D8, 0C, 45, 00, 00, 74, 2D, 55, 8B, EC, 83, EC, 08, 83, E4, F8, DD, 1C, 24, F2, 0F, 2C, 04, 24, C9, C3, 83, 3D, D8, 0C, 45, 00, 00, 74, 11, 83, EC, 04, D9, 3C, 24, 58, 66, 83, E0, 7F, 66, 83, F8, 7F, 74, D3, 55, 8B, EC, 83, EC, 20, 83, E4, F0, D9, C0, D9, 54, 24, 18, DF, 7C, 24, 10, DF, 6C, 24, 10, 8B, 54, 24, 18, 8B, 44, 24, 10, 85, C0, 74, 3C, DE, E9, 85, D2, 79, 1E, D9, 1C, 24, 8B, 0C, 24, 81, F1, 00, 00, 00, 80, 81...
 
[+]

Entropy:
7.8978  (probably packed)

Code size:
238 KB (243,712 bytes)

The file aurora_1.0.0.3031.exe has been seen being distributed by the following 4 URLs.

http://95.141.193.17/users2/EfreeMaN1/.../rsload.net.Aurora_1.0.0.3031.exe

https://aurora-browser.softonic.com.br/download-tracker?th=1/6CH9aeXedl4L8u BHNJXWTW LP1LFlnGQpxqjlxAP8H3OMTgXJzFu/IPX5wqZixhBeibpo6fnk0V3NYM/XURBzQC8W9Rxb3OMb0Kc20IFHdb sK2/ITyWlcahkM38Qdfpkuza6XDeBsI/.../ckTWBJf7sy9b0iUa7gWBzvostJ8fcB4E8IFAsYtQ3OA==

http://www.softportal.com/getsoft-41301-aurora-browser-2.html

Scan aurora_1.0.0.3031.exe - Powered by Reason Core Security