server.exe

The executable server.exe has been detected as malware by 36 anti-virus scanners.
Version:
1.6.0.0

MD5:
022b590d9289ca04aa5fd792e91221a3

SHA-1:
528575751e66261c1dbf4efaa0de8ed0249bdda1

SHA-256:
0c7fd07d4784749712b2650df4c2982471227cecdb7f5f12af05b027c1c6efc1

Scanner detections:
36 / 68

Status:
Malware

Analysis date:
4/3/2025 11:03:07 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Backdoor.Death.2.4.Dam.2
-40

AegisLab AV Signature
Backdoor.W32.Death.24!c
2.1.4+

Agnitum Outpost
Backdoor.Death
7.1.1

AhnLab V3 Security
Win-Trojan/Death.235008
2016.02.11

Avira AntiVirus
TR/Dearh.24.Srv
8.3.3.2

avast!
Win32:Death-C [Trj]
2014.9-170315

AVG
BackDoor.Death
2018.0.2438

Baidu Antivirus
Backdoor.Win32.Death
4.0.3.17315

Bitdefender
Backdoor.Death.2.4.Dam.2
1.0.20.370

Comodo Security
Backdoor.Win32.Death.24.A
24164

Dr.Web
BackDoor.Death.24
9.0.1.074

Emsisoft Anti-Malware
Backdoor.Death.2.4.Dam
8.17.03.15.04

ESET NOD32
Win32/Death.24
11.13011

Fortinet FortiGate
W32/Backdoor.LamersDeath-FP
3/15/2017

F-Prot
W32/Death.D
v6.4.7.1.166

F-Secure
Backdoor.Death.2.4.Dam.2
11.2017-15-03_4

G Data
Backdoor.Death.2.4.Dam
17.3.25

IKARUS anti.virus
Backdoor.Win32.Death
t3scan.2.0.6.0

K7 AntiVirus
Trojan
13.213.18713

Kaspersky
Backdoor.Win32.Death
14.0.0.-1313

McAfee
BackDoor-FP.svr
5600.6094

Microsoft Security Essentials
Backdoor:Win32/Death.2_4
1.1.12400.0

MicroWorld eScan
Backdoor.Death.2.4.Dam.2
18.0.0.222

NANO AntiVirus
Trojan.Win32.Death.gwpl
1.0.14.6071

nProtect
Backdoor/W32.Death.233315
16.02.05.01

Panda Antivirus
Trj/Genetic.gen
17.03.15.04

Qihoo 360 Security
Malware.Radar01.Gen
1.0.0.1120

Quick Heal
Backdoor.Death.24.n3
3.17.14.00

Rising Antivirus
PE:Malware.Generic(Thunder)!1.A1C4 [F]
23.00.65.17313

Sophos
Troj/Bdoor-FP
4.98

Trend Micro House Call
Mal_KSpy
7.2.74

Trend Micro
Mal_KSpy
10.465.15

Vba32 AntiVirus
BackDoor.Death
3.12.26.4

VIPRE Antivirus
Trojan.Win32.Generic
47126

ViRobot
Backdoor.Win32.Death.233315[h]
2014.3.20.0

Zillya! Antivirus
Backdoor.Death.Win32.54
2.0.0.2656

File size:
227.8 KB (233,315 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Language:
Russian (Russia)

Common path:
C:\users\{user}\downloads\ceh\cehv8 module 06 trojans and backdoors\miscellaneous trojans\death v2.4\server\server.exe

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
1.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0x934D0

Entry point:
60, BE, 00, C0, 45, 00, 8D, BE, 00, 50, FA, FF, C7, 87, D0, B4, 07, 00, F0, FD, 0C, B0, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 19, 8B, 1E, 83, EE, FC, 11, DB, 72, 10, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 78, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07...
 
[+]

Entropy:
7.8908

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
224 KB (229,376 bytes)

Remove server.exe - Powered by Reason Core Security