server.exe

Fxy1K5Gu1

vgrN0E

The executable server.exe has been detected as malware by 20 anti-virus scanners. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘{9D71D88C-C598-4935-C5D1-43AA4DB90836}’.
Publisher:
vgrN0E

Product:
Fxy1K5Gu1

Description:
vh7XRybkk

Version:
6.38.0081

MD5:
3c5820dc8db9d1c03d45065302262882

SHA-1:
64385f53ecbabcfdf7f9abce09b196630ab2a4d9

SHA-256:
474b53ae87326b8edf0ea7348872cd5da7f8874ab28f0078f68a2aab1f6e313f

Scanner detections:
20 / 68

Status:
Malware

Analysis date:
5/10/2024 2:01:10 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
TR/Offend.kdv.579742
7.11.32.70

avast!
Win32:Trojan-gen
2014.9-140926

Bitdefender
Trojan.Generic.KDV.579742
1.0.20.1345

Clam AntiVirus
PUA.Win32.Packer.EzipJohnathonCl
0.98/18155

Comodo Security
Backdoor.Win32.Rbot.~d5
12548

Dr.Web
Trojan.Siggen3.18213
9.0.1.0269

Emsisoft Anti-Malware
Trojan.SuspectCRC!IK
8.14.09.26.12

ESET NOD32
Win32/Bifrose
8.7206

F-Prot
W32/Agent.OX.gen
v6.4.6.5.141

F-Secure
Trojan.Generic.KDV.579742
11.2014-26-09_6

G Data
Trojan.Generic.KDV.579742
14.9.22

IKARUS anti.virus
Trojan.SuspectCRC
t3scan.1.1.118.0

K7 AntiVirus
Backdoor
13.143.7012

Kaspersky
Backdoor.Win32.Rbot
14.0.0.3192

McAfee
W32/Sdbot.worm!nv
5600.6995

nProtect
Worm/W32.Agent.140893
12.06.08.01

Panda Antivirus
Bck/Bifrost.gen
14.09.26.12

Trend Micro House Call
TROJ_SPNR.15DJ12
7.2.269

Vba32 AntiVirus
Backdoor.Rbot.aznj
3.12.16.8

VIPRE Antivirus
Trojan.Win32.Generic
12023

File size:
137.6 KB (140,893 bytes)

Product version:
6.38.0081

Copyright:
YXP4

Trademarks:
OnBo

Original file name:
stub.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\roaming\bifrost\server.exe

File PE Metadata
OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
3072:IEWDUuuzPx+c4p75lBPfqCCw4W04/9ubeG:8YuuzgcU7M80j

Entry address:
0x270BE

Entry point:
E9, 19, 32, 00, 00, E9, 7C, 2A, 00, 00, E9, 19, 24, 00, 00, E9, FF, 23, 00, 00, E9, 1E, 2E, 00, 00, E9, 88, 2E, 00, 00, E9, 2C, 25, 00, 00, E9, AE, 15, 00, 00, E9, 77, 2B, 00, 00, E9, 87, 02, 00, 00, E9, 70, 2E, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, FC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC...
 
[+]

Entropy:
7.4261

Packer / compiler:
EZIP v1.0

Code size:
20 KB (20,480 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
{9D71D88C-C598-4935-C5D1-43AA4DB90836}

Command:
C:\users\{user}\appdata\roaming\bifrost\server.exe


Remove server.exe - Powered by Reason Core Security