SYMBOLCOMMON_NAMEaka. SYNONYMS
win.betabot (Back to overview)

BetaBot

aka: Neurevt
VTCollection     URLhaus      

Cybereason concludes that Betabot is a sophisticated infostealer malware that’s evolved significantly since it first appeared in late 2012. The malware began as a banking Trojan and is now packed with features that allow its operators to practically take over a victim’s machine and steal sensitive information.

References
2022-08-08 ⋅ Medium CSIS Techblog ⋅ Benoît Ancel
An inside view of domain anonymization as-a-service — the BraZZZerSFF infrastructure
Riltok magecart Anubis Azorult BetaBot Buer CoalaBot CryptBot DiamondFox DreamBot GCleaner ISFB Loki Password Stealer (PWS) MedusaLocker MeguminTrojan Nemty PsiX RedLine Stealer SmokeLoader STOP TinyNuke Vidar Zloader
2022-03-28 ⋅ KrabsOnSecurity ⋅ Mr. Krabs
Betabot in the Rearview Mirror
BetaBot
2021-03-31 ⋅ Kaspersky SAS ⋅ Kaspersky
Financial Cyberthreats in 2020
BetaBot DanaBot Emotet Gozi Ramnit RTM SpyEye TrickBot Zeus
2020-07-14 ⋅ SophosLabs Uncut ⋅ Markel Picado, Sean Gallagher
RATicate upgrades “RATs as a Service” attacks with commercial “crypter”
LokiBot BetaBot CloudEyE NetWire RC
2020-05-14 ⋅ SophosLabs ⋅ Markel Picado
RATicate: an attacker’s waves of information-stealing malware
Agent Tesla BetaBot BlackRemote Formbook Loki Password Stealer (PWS) NetWire RC NjRAT Remcos
2018-11-04 ⋅ CCN-CERT ⋅ CCN-CERT
BetaBot y Fleercivet, dos nuevos informes de código dañino del CCN-CERT
BetaBot
2018-10-03 ⋅ Cybereason ⋅ Assaf Dahan
New Betabot campaign under the microscope
BetaBot
2018-06-15 ⋅ Medium woj_ciech ⋅ Wojciech
Betabot still alive with multi-stage packing
BetaBot
2017-02-27 ⋅ Sophos ⋅ Ted Heppner
Betabot: Configuration Data Extraction
BetaBot
2015-04-15 ⋅ XyliBox ⋅ Xylitol
Betabot retrospective
BetaBot
2013-09-24 ⋅ Hanan Natan
How to extract BetaBot config info
BetaBot
Yara Rules
[TLP:WHITE] win_betabot_auto (20260917 | Detects win.betabot.)
rule win_betabot_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.betabot."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.betabot"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { e8???????? 8325????????00 6a05 58 c3 68???????? e8???????? }
            // n = 7, score = 400
            //   e8????????           |                     
            //   8325????????00       |                     
            //   6a05                 | push                5
            //   58                   | pop                 eax
            //   c3                   | ret                 
            //   68????????           |                     
            //   e8????????           |                     

        $sequence_1 = { bf???????? e8???????? a3???????? 833d????????00 7409 833d????????00 7507 }
            // n = 7, score = 400
            //   bf????????           |                     
            //   e8????????           |                     
            //   a3????????           |                     
            //   833d????????00       |                     
            //   7409                 | je                  0xb
            //   833d????????00       |                     
            //   7507                 | jne                 9

        $sequence_2 = { c20c00 55 8bec 33c0 837d0801 721e 39450c }
            // n = 7, score = 400
            //   c20c00               | ret                 0xc
            //   55                   | push                ebp
            //   8bec                 | mov                 ebp, esp
            //   33c0                 | xor                 eax, eax
            //   837d0801             | cmp                 dword ptr [ebp + 8], 1
            //   721e                 | jb                  0x20
            //   39450c               | cmp                 dword ptr [ebp + 0xc], eax

        $sequence_3 = { eb48 a1???????? 53 57 054effffff 50 6a0c }
            // n = 7, score = 400
            //   eb48                 | jmp                 0x4a
            //   a1????????           |                     
            //   53                   | push                ebx
            //   57                   | push                edi
            //   054effffff           | add                 eax, 0xffffff4e
            //   50                   | push                eax
            //   6a0c                 | push                0xc

        $sequence_4 = { b88bff0000 663906 7504 8bc6 eb02 33c0 5f }
            // n = 7, score = 400
            //   b88bff0000           | mov                 eax, 0xff8b
            //   663906               | cmp                 word ptr [esi], ax
            //   7504                 | jne                 6
            //   8bc6                 | mov                 eax, esi
            //   eb02                 | jmp                 4
            //   33c0                 | xor                 eax, eax
            //   5f                   | pop                 edi

        $sequence_5 = { 56 53 8d85d8fdffff 50 e8???????? 8d45e0 50 }
            // n = 7, score = 400
            //   56                   | push                esi
            //   53                   | push                ebx
            //   8d85d8fdffff         | lea                 eax, [ebp - 0x228]
            //   50                   | push                eax
            //   e8????????           |                     
            //   8d45e0               | lea                 eax, [ebp - 0x20]
            //   50                   | push                eax

        $sequence_6 = { 56 8d8588feffff 50 e8???????? 397508 745d 8b4d08 }
            // n = 7, score = 400
            //   56                   | push                esi
            //   8d8588feffff         | lea                 eax, [ebp - 0x178]
            //   50                   | push                eax
            //   e8????????           |                     
            //   397508               | cmp                 dword ptr [ebp + 8], esi
            //   745d                 | je                  0x5f
            //   8b4d08               | mov                 ecx, dword ptr [ebp + 8]

        $sequence_7 = { ff35???????? ff15???????? 85c0 7502 eb05 e9???????? ff75fc }
            // n = 7, score = 400
            //   ff35????????         |                     
            //   ff15????????         |                     
            //   85c0                 | test                eax, eax
            //   7502                 | jne                 4
            //   eb05                 | jmp                 7
            //   e9????????           |                     
            //   ff75fc               | push                dword ptr [ebp - 4]

        $sequence_8 = { e9???????? 837d0800 7426 837d0c00 7413 8b450c 0fb700 }
            // n = 7, score = 400
            //   e9????????           |                     
            //   837d0800             | cmp                 dword ptr [ebp + 8], 0
            //   7426                 | je                  0x28
            //   837d0c00             | cmp                 dword ptr [ebp + 0xc], 0
            //   7413                 | je                  0x15
            //   8b450c               | mov                 eax, dword ptr [ebp + 0xc]
            //   0fb700               | movzx               eax, word ptr [eax]

        $sequence_9 = { 33f6 e8???????? 33d2 b978ff0000 f7f1 b9ff030000 83c237 }
            // n = 7, score = 400
            //   33f6                 | xor                 esi, esi
            //   e8????????           |                     
            //   33d2                 | xor                 edx, edx
            //   b978ff0000           | mov                 ecx, 0xff78
            //   f7f1                 | div                 ecx
            //   b9ff030000           | mov                 ecx, 0x3ff
            //   83c237               | add                 edx, 0x37

    condition:
        7 of them and filesize < 835584
}
[TLP:WHITE] win_betabot_w0   (20170517 | Neurevt Malware Sig)
rule win_betabot_w0 {
    meta:
        author = "Venom23"
        date = "2013-06-21"
        description = "Neurevt Malware Sig"
        hash = "db9a816d58899f1ba92bc338e89f856a"
        hash = "d7b427ce3175fa7704da6b19a464938e"
        hash = "13027beb8aa5e891e8e641c05ccffde3"
        hash = "d1004b63d6d3cb90e6012c68e19ab453"
        hash = "a1286fd94984fd2de857f7b846062b5e"
        yaragenerator = "https://github.com/Xen0ph0n/YaraGenerator"
        source = "https://github.com/mattulm/sfiles_yara/blob/master/malware/Neurevt.yar"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.betabot"
        malpedia_version = "20170517"
        malpedia_license = "CC BY-NC-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    strings:
        $string0 = "BullGuard" wide
        $string1 = "cmd.exe" wide
        $string4 = "eUSERPROFILE" wide
        $string5 = "%c:\\%s.lnk" wide
        $string6 = "services.exe" wide
        $string9 = "Multiples archivos corruptos han sido encontrados en la carpeta \"Mis Documentos\". Para evitar perder" wide
        $string10 = "F-PROT Antivirus Tray application" wide
        $string12 = "-k NetworkService" wide
        $string13 = "firefox.exe"
        $string14 = "uWinMgr.exe" wide
        $string15 = "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.13) Gecko/20060410 Firefox/1.0.8"
        $string16 = "Mozilla/5.0 (Windows; U; Windows NT 6.0; en-GB; rv:1.8.1.11) Gecko/20071127 Firefox/2.0.0.11"
        $string18 = "Data Path" wide

    condition:
        10 of them
}
Download all Yara Rules