server.exe

The executable server.exe has been detected as malware by 35 anti-virus scanners. This backdoor trojan may be used to conduct distributed denial of service attacks, or used to install additional trojans or other forms of malicious software as well as can steal your sensitive information. The file has been seen being downloaded from s1.directxex.com.
MD5:
b84668819d14f8562b6fcfbef565a2a4

SHA-1:
80fde361f2e854441727bfa290d74514e1617e5c

SHA-256:
a46538900a712a12121ec20a2bb8672215ce9e975c977f921d24cb84f6224083

Scanner detections:
35 / 68

Status:
Malware

Analysis date:
11/30/2024 3:45:42 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKDZ.24293
884

Agnitum Outpost
Trojan.Agent
7.1.1

AhnLab V3 Security
Win-Trojan/Zbot.24064
2014.08.07

Avira AntiVirus
TR/Dropper.Gen7
7.11.165.192

avast!
MSIL:GenMalicious-AV [Trj]
2014.9-140904

AVG
BackDoor.Generic18
2015.0.3362

Baidu Antivirus
Trojan.MSIL.Bladabindi
4.0.3.1494

Bitdefender
Trojan.GenericKDZ.24293
1.0.20.1235

Comodo Security
Backdoor.MSIL.Bladabindi.A
19110

Dr.Web
BackDoor.Bladabindi.1056
9.0.1.0247

Emsisoft Anti-Malware
Trojan.GenericKDZ.24293
8.14.09.04.10

ESET NOD32
MSIL/Bladabindi.BH (variant)
8.10217

Fortinet FortiGate
MSIL/Bladabindi.Q!tr
9/4/2014

F-Prot
W32/MSIL_Bladabindi.G.gen
v6.4.7.1.166

F-Secure
Trojan.GenericKDZ.24293
11.2014-04-09_5

G Data
Trojan.GenericKDZ.24293
14.9.24

IKARUS anti.virus
Backdoor.MSIL
t3scan.1.6.1.0

K7 AntiVirus
Trojan
13.183.12981

Kaspersky
Trojan.MSIL.Agent
14.0.0.3303

Malwarebytes
Trojan.MSIL
v2014.09.04.10

McAfee
BackDoor-FBIB!B84668819D14
5600.7018

Microsoft Security Essentials
Backdoor:MSIL/Bladabindi.AJ
1.10802

MicroWorld eScan
Trojan.GenericKDZ.24293
15.0.0.741

NANO AntiVirus
Trojan.Win32.DownLoader11.cxfbrl
0.28.2.61349

nProtect
Trojan/W32.Agent.24064.UQ
14.08.07.01

Panda Antivirus
Generic Malware
14.09.04.10

Qihoo 360 Security
HEUR/Malware.QVM03.Gen
1.0.0.1015

Quick Heal
Backdoor.Bladabindi.AL3
9.14.14.00

Sophos
Troj/DotNet-P
4.98

SUPERAntiSpyware
Trojan.Agent/Gen-Bladabindi
10380

Total Defense
Win32/DotNetDl.A!generic
37.0.11104

Trend Micro House Call
TROJ_GEN.F0C2H00F614
7.2.247

Trend Micro
BKDR_BLBINDI.SMN
10.465.04

Vba32 AntiVirus
Trojan.MSIL.Disfa
3.12.26.3

VIPRE Antivirus
Backdoor.MSIL.Bladabindi.a
32006

File size:
23.5 KB (24,064 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\server.exe

File PE Metadata
Compilation timestamp:
5/21/2014 5:36:11 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:VsqS+ER6vRKXGYKRWVSujUtX9w6Dglo61Z5DVmRvR6JZlbw8hqIusZzZdlX:ef65K2Yf1jKRpcnuE

Entry address:
0x747E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
5.5202

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
21.5 KB (22,016 bytes)

The file server.exe has been seen being distributed by the following URL.

Remove server.exe - Powered by Reason Core Security