server.exe

Explorer

The executable server.exe has been detected as malware by 37 anti-virus scanners.
Product:
Explorer

Version:
2.0.0.0

MD5:
16caf6e0edddfb99a31da85c0230ba6f

SHA-1:
fb47be55135fd6245a5b0f70bf5fa7440d2feebb

SHA-256:
9dba4ed539c74b93680969f1af8be38273ada028b0e12b987fea264cabfab581

Scanner detections:
37 / 68

Status:
Malware

Analysis date:
5/2/2024 6:40:50 PM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Backdoor.Generic.277453
-40

AegisLab AV Signature
Backdoor.W32.Amitis.143!c
2.1.4+

Agnitum Outpost
Backdoor.Amitis
7.1.1

AhnLab V3 Security
Win-Trojan/Amitis.334223
2016.02.15

Avira AntiVirus
BDS/Amitis.143.B
8.3.3.2

Arcabit
Backdoor.Generic.D43BCD
1.0.0.653

avast!
Win32:Amitis-C [Trj]
2014.9-170315

AVG
BackDoor.Generic3
2018.0.2438

Baidu Antivirus
Backdoor.Win32.Amitis
4.0.3.17315

Bitdefender
Backdoor.Generic.277453
1.0.20.370

Clam AntiVirus
Trojan.Amitis.143-srv-upx
0.98/21511

Comodo Security
Backdoor.Win32.Amitis.143.B
24206

Dr.Web
Trojan.PWS.Banker.10574
9.0.1.074

Emsisoft Anti-Malware
Backdoor.Generic.277453
8.17.03.15.04

ESET NOD32
Win32/Amitis.143
11.13028

Fortinet FortiGate
W32/Amitis.B!tr
3/15/2017

F-Prot
W32/Amitis.B@bd
v6.4.7.1.166

F-Secure
Backdoor.Generic.277453
11.2017-15-03_4

G Data
Backdoor.Generic.277453
17.3.25

IKARUS anti.virus
Backdoor.Win32.Amitis
t3scan.2.0.6.0

K7 AntiVirus
Trojan
13.213.18735

Kaspersky
Backdoor.Win32.Amitis
14.0.0.-1313

McAfee
BackDoor-AKZ
5600.6094

Microsoft Security Essentials
Backdoor:Win32/Amitis.A
1.1.12400.0

MicroWorld eScan
Backdoor.Generic.277453
18.0.0.222

NANO AntiVirus
Trojan.Win32.Amitis.fdmb
1.0.14.6181

nProtect
Backdoor/W32.Amitis.304128
16.02.12.01

Panda Antivirus
Bck/Amitis.E
17.03.15.04

Qihoo 360 Security
Malware.Radar01.Gen
1.0.0.1120

Rising Antivirus
PE:Malware.Generic/QRS!1.9E2D [F]
23.00.65.17313

Sophos
Troj/Amitis-B
4.98

Trend Micro House Call
BKDR_AMITIS.D
7.2.74

Trend Micro
BKDR_AMITIS.D
10.465.15

Vba32 AntiVirus
Backdoor.Amitis
3.12.26.4

VIPRE Antivirus
Backdoor.Win32.Amitis.143
47208

ViRobot
Backdoor.Win32.Amitis.344958[h]
2014.3.20.0

Zillya! Antivirus
Backdoor.Amitis.Win32.33
2.0.0.2665

File size:
297 KB (304,128 bytes)

Product version:
1.0.0.0

Original file name:
Explorer

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\ceh\cehv8 module 06 trojans and backdoors\miscellaneous trojans\amitis v1.4.3b trojan\amitis 1.4.3\server.exe

File PE Metadata
Compilation timestamp:
6/19/1992 3:22:17 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

Entry address:
0xCF5B0

Entry point:
60, BE, 00, 60, 48, 00, 8D, BE, 00, B0, F7, FF, C7, 87, 10, 17, 0B, 00, 02, 5B, 1C, 2A, 57, 83, CD, FF, EB, 0E, 90, 90, 90, 90, 8A, 06, 46, 88, 07, 47, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 72, ED, B8, 01, 00, 00, 00, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, 01, DB, 73, 0B, 75, 19, 8B, 1E, 83, EE, FC, 11, DB, 72, 10, 48, 01, DB, 75, 07, 8B, 1E, 83, EE, FC, 11, DB, 11, C0, EB, D4, 31, C9, 83, E8, 03, 72, 11, C1, E0, 08, 8A, 06, 46, 83, F0, FF, 74, 78, D1, F8, 89, C5, EB, 0B, 01, DB, 75, 07...
 
[+]

Entropy:
7.9098

Packer / compiler:
UPX v0.89.6 - v1.02 / v1.05 -v1.22 (Delphi) stub

Code size:
296 KB (303,104 bytes)

Remove server.exe - Powered by Reason Core Security