Summary | ZeroBOX

AeroAdmin.exe

Category Machine Started Completed
FILE s1_win7_x6401 April 21, 2021, 3:59 p.m. April 21, 2021, 4 p.m.
Size 3.1MB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 42cf36e9d42beb230502e33d34ea0b05
SHA256 657cebf189115e7b8c2c64102392bd56299eef02711e6807331f992247206029
CRC32 35DFD2CE
ssdeep 49152:OcxFrsKnp7e7K6npEIGAJdfbgrWRmD86RKu+XT/4dKHMxfk0d/bYnadM02p:76KnvygcebVKafk
PDB Path aeroadmin.pdb
Yara
  • network_tcp_listen - Listen for incoming communication
  • network_dropper - File downloader/dropper
  • network_tcp_socket - Communications over RAW socket
  • network_dns - Communications use DNS
  • escalate_priv - Escalade priviledges
  • screenshot - Take screenshot
  • keylogger - Run a keylogger
  • sniff_audio - Record Audio
  • win_registry - Affect system registries
  • win_token - Affect system token
  • win_files_operation - Affect private profile
  • Str_Win32_Winsock2_Library - Match Winsock 2 API library declaration
  • PE_Header_Zero - PE File Signature Zero
  • OS_Processor_Check_Zero - OS Processor Check Signature Zero
  • IsPE32 - (no description)
  • IsWindowsGUI - (no description)
  • HasOverlay - Overlay Check
  • HasDigitalSignature - DigitalSignature Check
  • HasDebugData - DebugData Check
  • HasRichSignature - Rich Signature Check

Name Response Post-Analysis Lookup
auth11.aeroadmin.com 37.48.87.53
IP Address Status Action
164.124.101.2 Active Moloch
37.48.87.53 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49200 -> 37.48.87.53:5665 2260001 SURICATA Applayer Wrong direction first Data Generic Protocol Command Decode

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0
pdb_path aeroadmin.pdb
Time & API Arguments Status Return Repeated

CreateServiceW

service_start_name:
start_type: 2
password:
display_name: AeroadminService
filepath: C:\Users\test22\AppData\Local\Temp\"C:\Users\test22\AppData\Local\Temp\AeroAdmin.exe" s -sid 1
service_name: AeroadminService
filepath_r: "C:\Users\test22\AppData\Local\Temp\AeroAdmin.exe" s -sid 1
desired_access: 983551
service_handle: 0x00731040
error_control: 1
service_type: 16
service_manager_handle: 0x00730fa0
1 7540800 0
service_name AeroadminService service_path C:\Users\test22\AppData\Local\Temp\"C:\Users\test22\AppData\Local\Temp\AeroAdmin.exe" s -sid 1