AuroraKernelService.exe

Aurora Server

AURORA NETWORK COMPANY LIMITED

The executable AuroraKernelService.exe has been detected as malware by 3 anti-virus scanners. It runs as a separate (within the context of its own process) windows Service named “Aurora Kernel Service”.
Publisher:
AuroraBrowser.COM  (signed by AURORA NETWORK COMPANY LIMITED)

Product:
Aurora Server

Version:
1.0.0.7

MD5:
db44e64a58857549683d132fe5c0e416

SHA-1:
539c7452386aeb537c14bd8485ddf1969232c87e

SHA-256:
cd84d5ed071fe640396840edf04ca3836dee4e2d0a57cc999317aec84782c8b4

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
11/23/2024 3:36:49 AM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
Win32/Floxif.H virus
6.3.12010.0

F-Prot
W32/Floxif.B
4.6.5.141

F-Secure
Win32.Floxif.A
5.15.154

File size:
257 KB (263,159 bytes)

Product version:
1.0.0.7

Copyright:
Copyright @ 2015 AuroraBrowser.COM. All Rights Reserved.

Original file name:
AuroraKernelService.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\aurorabrowser\installer\aurorakernelservice.exe

Digital Signature
Authority:
DigiCert Inc

Valid from:
7/23/2015 5:00:00 PM

Valid to:
7/26/2016 5:00:00 AM

Subject:
CN=AURORA NETWORK COMPANY LIMITED, O=AURORA NETWORK COMPANY LIMITED, L=Hong Kong, C=HK, PostalCode=HK, STREET="Unit 04, 7/F Bright Way Tower No.33 Mong Kok Rd, Kln", SERIALNUMBER=2237249, OID.1.3.6.1.4.1.311.60.2.1.3=HK, OID.2.5.4.15=Private Organization

Issuer:
CN=DigiCert EV Code Signing CA (SHA2), OU=www.digicert.com, O=DigiCert Inc, C=US

Serial number:
0BDEC9C484B67149205C8B50942140A6

File PE Metadata
Compilation timestamp:
12/9/2015 6:26:44 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

Entry address:
0xE257

Entry point:
E9, FA, 6B, FF, FF, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 20, 57, 56, E8, 00, 05, 00, 00, 33, FF, 59, 3B, F7, 75, 1D, E8, BC, 18, 00, 00, 57, 57, 57, 57, 57, C7, 00, 16, 00, 00, 00, E8, D0, FD, FF, FF, 83, C4, 14, 83, C8, FF, EB, 34, 39, 7D, 0C, 74, DE, B9, FF, FF, FF, 7F, C7, 45, EC, 49, 00, 00, 00, 89, 75, E8, 89, 75, E0, 89, 4D, E4, 3B, C1, 77, 03, 89, 45, E4, FF, 75, 14, 8D, 45, E0, FF, 75, 10, FF, 75, 0C, 50, FF, 55, 08, 83, C4, 10, 5F, C9, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 08, 8D, 45, 10...
 
[+]

Entropy:
7.0674

Packer / compiler:
tElock 0.99 - 1.0 private

Code size:
125.5 KB (128,512 bytes)

Service
Display name:
Aurora Kernel Service

Description:
Aurora Kernel Service ...

Type:
Win32OwnProcess


Remove AuroraKernelService.exe - Powered by Reason Core Security