Skip navigation.
Home

\stub\stub1.4_newmod\WinSrv.vbp

I found a VB malware inside WinRar sfx. This malware retrieve a dropper from a website
that drop on hard disk a trojan (TR/Buzus.ztk for AVIRA).

The WinRar sfx extract on user TEMP folder two files, start.exe and the original Sfx archive,
executing start.exe (the malware) and the sfx.

The malware get dropper from an URL (hxxp://67.159.57.83/setup.exe) using wininet.InternetOpenUrlA.

The dropper create on folder an exe file (Setup_ver1.1585.2.exe) with trojan.

start.exe
089e63cfe70aebc52fe5b087cc5dd2a4

setup.exe
799b4296dd74a2adaaf30b903759db82

Setup_ver1.1585.2
f42e34cedc6e5ff0957ec60d58b5f8da