server.exe
Classification: Malicious
server.exe is a malicious file sample. Linked to Runningrat malware. Reported by 1 threat source, last seen 2022-02-15. Detected by 48 antivirus engines.
Detection summary
- 48 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: RUNNINGRAT (S0253)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| RunningRAT | MalwareBazaar Abuse.ch | 2022-02-15 16:44:25 | 2022-02-15 16:44:25 | malicious-activity | S0253 RunningRAT |
| Generic.Malware | MalwareBazaar Abuse.ch | 2022-02-15 16:44:25 | 2022-02-15 16:44:25 | malicious-activity |
Sample information
- Filenames
- server.exe
- File type
- application/x-dosexec
- MD5
6db6ec5bae1438faf87e2ad4378e083c- SHA-1
f0788c41222dade479d857e2fea59b8967ab196e- SHA-256
7e785932bf809a672845f139212961959daaa5804e838e5817298c328effdfed- First indexed
- 2022-02-15 18:15:09
- Last updated
- 2026-03-13 09:20:08
Antivirus detections
| Engine | Detection |
|---|---|
| Bkav | W32.SlaviaC.Trojan |
| Elastic | malicious (high confidence) |
| Cynet | Malicious (score: 100) |
| ALYac | Gen:Heur.RI.1 |
| Malwarebytes | Spyware.PasswordStealer.VB |
| VIPRE | Trojan.Win32.Generic!BT |
| Sangfor | Suspicious.Win32.Save.a |
| K7AntiVirus | Trojan ( 005565491 ) |
| BitDefender | Gen:Heur.RI.1 |
| K7GW | Trojan ( 005565491 ) |
| CrowdStrike | win/malicious_confidence_90% (D) |
| Symantec | ML.Attribute.HighConfidence |
| ESET-NOD32 | a variant of Win32/Injector.EGZV |
| APEX | Malicious |
| ClamAV | Win.Trojan.Farfli-9755023-0 |
| Kaspersky | Backdoor.Win64.Winnti.wd |
| NANO-Antivirus | Trojan.Win32.RI.hmkkqx |
| MicroWorld-eScan | Gen:Heur.RI.1 |
| Rising | Backdoor.Winnti!8.1C3B (C64:YzY0Op4ISXvSP2K/) |
| Ad-Aware | Gen:Heur.RI.1 |
| Sophos | ML/PE-A |
| DrWeb | Trojan.DownLoader33.59527 |
| McAfee-GW-Edition | GenericRXKR-ZE!6DB6EC5BAE14 |
| FireEye | Generic.mg.6db6ec5bae1438fa |
| Emsisoft | Gen:Heur.RI.1 (B) |
| SentinelOne | Static AI - Malicious PE |
| Jiangmin | Heur:Backdoor/Huigezi |
| Avira | HEUR/AGEN.1234370 |
| Antiy-AVL | Trojan/Generic.ASMalwS.305A526 |
| Microsoft | Trojan:Win32/Fareit.EGZV!MTB |
| Arcabit | Trojan.RI.1 |
| GData | Gen:Heur.RI.1 |
| AhnLab-V3 | Malware/Win32.RL_Generic.R356011 |
| Acronis | suspicious |
| McAfee | GenericRXKR-ZE!6DB6EC5BAE14 |
| MAX | malware (ai score=80) |
| VBA32 | BScope.Backdoor.Win64.Winnti |
| Cylance | Unsafe |
| Panda | Trj/Genetic.gen |
| Tencent | Malware.Win32.Gencirc.10ce4153 |
| Yandex | Trojan.Injector!hRcvA6CFe40 |
| Ikarus | Trojan.Win32.Injector |
| eGambit | Generic.Malware |
| BitDefenderTheta | Gen:NN.ZexaF.34212.eqW@aK6ty4pb |
| AVG | Win32:BackdoorX-gen [Trj] |
| Cybereason | malicious.bae143 |
| Avast | Win32:BackdoorX-gen [Trj] |
| MaxSecure | Trojan.Malware.102770177.susgen |