server.exe

The executable server.exe has been detected as malware by 39 anti-virus scanners.
MD5:
8e49dc029cf4f8c4ceb41052a96b6949

SHA-1:
b78a2ff65d388d2a7def1ee2668cce970b67a44f

SHA-256:
d8511ec3e07a977c2cc6c91a72f0b5ca2b69e647f360b4b0fa672d5c1ab3d662

Scanner detections:
39 / 68

Status:
Malware

Analysis date:
4/26/2024 3:06:59 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.Dropper.SAG
6486625

Agnitum Outpost
Trojan.Midgare.IQ
7.1.1

AhnLab V3 Security
Win-Trojan/Bifrose.Gen
2015.02.04

Avira AntiVirus
BDS/Bifrose.aec
7.11.206.214

avast!
Win32:Refroso-DE [Trj]
150129-1

AVG
BackDoor.Generic12
2016.0.3209

Bitdefender
Trojan.Dropper.SAG
1.0.20.175

Bkav FE
W32.Ise32NO
1.3.0.6379

Clam AntiVirus
W32.Trojan.Bifrose-37
0.98/21511

Comodo Security
Backdoor.Win32.Bifrost.~Q
20955

Dr.Web
BackDoor.Bifrost.21488
9.0.1.05190

Emsisoft Anti-Malware
Trojan.Dropper.SAG
9.0.0.4799

ESET NOD32
Win32/Bifrose.NEL trojan
7.0.302.0

Fortinet FortiGate
W32/Bifrose.NTA2!tr
2/4/2015

F-Prot
W32/Backdoor2.CBJB
4.6.5.141

F-Secure
Backdoor:W32/Bifrose.gen!E
5.13.68

G Data
Trojan.Dropper.SAG
15.2.25

IKARUS anti.virus
Virus.Trojan.Win32.Midgare
t3scan.1.8.6.0

K7 AntiVirus
Trojan
13.193.14853

Kaspersky
Backdoor.Win32.Bifrose
15.0.0.543

Malwarebytes
Trojan.Clicker
v2015.02.04.12

McAfee
Generic BackDoor.aab
5600.6865

Microsoft Security Essentials
Threat.Undefined
1.191.3639.0

MicroWorld eScan
Trojan.Dropper.SAG
16.0.0.105

NANO AntiVirus
Trojan.Win32.Bifrose.chutkd
0.30.0.65070

Norman
Trojan.Dropper.SAG
02.01.2015 13:58:24

nProtect
Trojan/W32.Midgare.32669.I
15.02.03.01

Panda Antivirus
Bck/Bifrose.BFX
15.02.04.12

Quick Heal
Backdoor.Bifrose.AE
2.15.14.00

Rising Antivirus
PE:Trojan.Win32.Midgare.hhn!1075147275
23.00.65.15202

Sophos
Virus 'Mal/Bifrose-X'
5.10

SUPERAntiSpyware
Rootkit.Agent/Gen-Frossi
10075

Total Defense
Win32/Backdrop.D
37.0.11420

Trend Micro House Call
BKDR_BIFROSE.SMA
7.2.35

Trend Micro
BKDR_BIFROSE.SMA
10.465.04

Vba32 AntiVirus
SScope.Trojan.Buzus.ak
3.12.26.3

VIPRE Antivirus
Threat.4150696
36694

ViRobot
Backdoor.Win32.A.Bifrose.32637.KZ[h]
2014.3.20.0

Zillya! Antivirus
Virus.Bitforse.Win32.1
2.0.0.2052

File size:
31.9 KB (32,669 bytes)

File type:
Executable application (Win32 EXE)

File PE Metadata
Compilation timestamp:
12/28/2007 3:11:35 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
768:Z+h7TzTBziifTeiZSVWihwEknh0L7OTLeNfQfR:kZ/nEkh8OTKN0

Entry address:
0x7C89

Entry point:
55, 8B, EC, 83, EC, 44, 56, FF, 15, 18, 10, 40, 00, 8B, F0, 8A, 06, 3C, 22, 75, 14, 8A, 46, 01, 46, 84, C0, 74, 04, 3C, 22, 75, F4, 80, 3E, 22, 75, 0D, 46, EB, 0A, 3C, 20, 7E, 06, 46, 80, 3E, 20, 7F, FA, 8A, 06, 84, C0, 74, 04, 3C, 20, 7E, E9, 83, 65, E8, 00, 8D, 45, BC, 50, FF, 15, 14, 10, 40, 00, E8, 5D, 00, 00, 00, 68, 30, 10, 40, 00, 68, 2C, 10, 40, 00, E8, 34, 00, 00, 00, F6, 45, E8, 01, 59, 59, 74, 06, 0F, B7, 45, EC, EB, 03, 6A, 0A, 58, 50, 56, 6A, 00, 6A, 00, FF, 15, 04, 10, 40, 00, 50, E8, BB, FC...
 
[+]

Entropy:
7.4505

Developed / compiled with:
Microsoft Visual C++

Code size:
28 KB (28,672 bytes)

Remove server.exe - Powered by Reason Core Security