server.exe

The executable server.exe has been detected as malware by 3 anti-virus scanners. This is a setup program which is used to install the application. This backdoor trojan may be used to conduct distributed denial of service attacks, or used to install additional trojans or other forms of malicious software as well as can steal your sensitive information. The file has been seen being downloaded from fs10n5.sendspace.com.
MD5:
2845a181b87300beae72784f180c75db

SHA-1:
aad7dba966e24501beb6687befdab90d1ef35b0d

SHA-256:
14cd20a909c9e4fafd4820f2a892d39aab824bcde5c278706cf427dad3f6ca22

Scanner detections:
3 / 68

Status:
Malware

Analysis date:
1/13/2025 6:02:10 PM UTC  (today)

Scan engine
Detection
Engine version

ESET NOD32
MSIL/Bladabindi.AS trojan
6.3

F-Prot
W32/MSIL_Bladabindi.A2.gen
4.6.5.141

Microsoft Security Essentials
Backdoor:MSIL/Bladabindi.AJ
1.225.3525.0

File size:
28.5 KB (29,184 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\downloads\server.exe

File PE Metadata
Compilation timestamp:
8/4/2016 5:21:45 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
384:CwY29iLiYKpeddujzxxBzCyMVwY2S06D6Xl/9BuNluOofZlU0LE22WGabiNrxwJU:mVdezLBzCL5M6i59U3ofnU0L4W9bu6

Entry address:
0x893E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
26.5 KB (27,136 bytes)

The file server.exe has been seen being distributed by the following URL.

Remove server.exe - Powered by Reason Core Security