SYMBOLCOMMON_NAMEaka. SYNONYMS
win.bhunt (Back to overview)

BHunt

VTCollection    

BHunt collects the crypto wallets of its victims. The malware consists of several functions/modules, e.g. a reporting module that reports the presence of crypto wallets on the target computers to the C2 server. It searches for many different cryptocurrencies (e.g. Atomic, Bitcoin, Electrum, Ethereum, Exodus, Jaxx and Litecoin). The Blackjack module is used to steal wallets, Sweet_Bonanza steals victims' browser passwords. There are also modules like the Golden7 or the Chaos_crew module.

References
2022-02-10 ⋅ Blackberry ⋅ The BlackBerry Research & Intelligence Team
Threat Thursday: BHunt Scavenger Harvests Victims’ Crypto Wallets
BHunt
2022-01-19 ⋅ BleepingComputer ⋅ Bill Toulas
New BHUNT malware targets your crypto wallets and passwords
BHunt
2022-01-18 ⋅ Bitdefender ⋅ Janos Gergo Szeles
Poking Holes in Crypto-Wallets: a Short Analysis of BHUNT Stealer
BHunt
Yara Rules
[TLP:WHITE] win_bhunt_auto (20260917 | Detects win.bhunt.)
rule win_bhunt_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.bhunt."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bhunt"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 6685c0 7504 33c0 eb75 0fb7c0 eb13 66837dfc0a }
            // n = 7, score = 100
            //   6685c0               | test                ax, ax
            //   7504                 | jne                 6
            //   33c0                 | xor                 eax, eax
            //   eb75                 | jmp                 0x77
            //   0fb7c0               | movzx               eax, ax
            //   eb13                 | jmp                 0x15
            //   66837dfc0a           | cmp                 word ptr [ebp - 4], 0xa

        $sequence_1 = { 894e04 ff731c 8d570f 68???????? e8???????? 59 59 }
            // n = 7, score = 100
            //   894e04               | mov                 dword ptr [esi + 4], ecx
            //   ff731c               | push                dword ptr [ebx + 0x1c]
            //   8d570f               | lea                 edx, [edi + 0xf]
            //   68????????           |                     
            //   e8????????           |                     
            //   59                   | pop                 ecx
            //   59                   | pop                 ecx

        $sequence_2 = { e8???????? 33c0 68???????? c705????????00040000 c705????????00010000 a3???????? a3???????? }
            // n = 7, score = 100
            //   e8????????           |                     
            //   33c0                 | xor                 eax, eax
            //   68????????           |                     
            //   c705????????00040000     |     
            //   c705????????00010000     |     
            //   a3????????           |                     
            //   a3????????           |                     

        $sequence_3 = { ff37 8b7508 8945e8 8b4734 68???????? 8945f0 e8???????? }
            // n = 7, score = 100
            //   ff37                 | push                dword ptr [edi]
            //   8b7508               | mov                 esi, dword ptr [ebp + 8]
            //   8945e8               | mov                 dword ptr [ebp - 0x18], eax
            //   8b4734               | mov                 eax, dword ptr [edi + 0x34]
            //   68????????           |                     
            //   8945f0               | mov                 dword ptr [ebp - 0x10], eax
            //   e8????????           |                     

        $sequence_4 = { ae 660458 660fabca 660fbaf24a c0e654 32d8 d2ce }
            // n = 7, score = 100
            //   ae                   | scasb               al, byte ptr es:[edi]
            //   660458               | add                 al, 0x58
            //   660fabca             | bts                 dx, cx
            //   660fbaf24a           | btr                 dx, 0x4a
            //   c0e654               | shl                 dh, 0x54
            //   32d8                 | xor                 bl, al
            //   d2ce                 | ror                 dh, cl

        $sequence_5 = { 6685ec f8 f7d2 f9 f6c720 3adb }
            // n = 6, score = 100
            //   6685ec               | test                sp, bp
            //   f8                   | clc                 
            //   f7d2                 | not                 edx
            //   f9                   | stc                 
            //   f6c720               | test                bh, 0x20
            //   3adb                 | cmp                 bl, bl

        $sequence_6 = { 99 8acb 660fabf2 660fbae29f 8af2 d3c0 02f7 }
            // n = 7, score = 100
            //   99                   | cdq                 
            //   8acb                 | mov                 cl, bl
            //   660fabf2             | bts                 dx, si
            //   660fbae29f           | bt                  dx, 0x9f
            //   8af2                 | mov                 dh, dl
            //   d3c0                 | rol                 eax, cl
            //   02f7                 | add                 dh, bh

        $sequence_7 = { ff750c 57 e8???????? 68???????? ff750c 50 e8???????? }
            // n = 7, score = 100
            //   ff750c               | push                dword ptr [ebp + 0xc]
            //   57                   | push                edi
            //   e8????????           |                     
            //   68????????           |                     
            //   ff750c               | push                dword ptr [ebp + 0xc]
            //   50                   | push                eax
            //   e8????????           |                     

        $sequence_8 = { 7614 8d8c244c010000 51 8d742424 e8???????? }
            // n = 5, score = 100
            //   7614                 | jbe                 0x16
            //   8d8c244c010000       | lea                 ecx, [esp + 0x14c]
            //   51                   | push                ecx
            //   8d742424             | lea                 esi, [esp + 0x24]
            //   e8????????           |                     

        $sequence_9 = { c1c305 33742414 33c2 0374245c 33442444 0374241c 3344242c }
            // n = 7, score = 100
            //   c1c305               | rol                 ebx, 5
            //   33742414             | xor                 esi, dword ptr [esp + 0x14]
            //   33c2                 | xor                 eax, edx
            //   0374245c             | add                 esi, dword ptr [esp + 0x5c]
            //   33442444             | xor                 eax, dword ptr [esp + 0x44]
            //   0374241c             | add                 esi, dword ptr [esp + 0x1c]
            //   3344242c             | xor                 eax, dword ptr [esp + 0x2c]

    condition:
        7 of them and filesize < 19161088
}
[TLP:WHITE] win_bhunt_w0   (20220220 | Detects BHunt Malware Infostealer)
import "pe"

rule win_bhunt_w0 {
    meta:
        description = "Detects BHunt Malware Infostealer"
        author = "BlackBerry Research & Intelligence Team"
        date = "Jan 28th 2022"
        license = "This Yara rule is provided under the Apache License 2.0 (https://www.apache.org/licenses/LICENSE-2.0) and open to any user or organization, as long as you use it under this license and ensure originator credit in any derivative to The BlackBerry Research & Intelligence Team"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.bhunt"
        malpedia_version = "20220220"
        malpedia_license = "CC BY-NC-SA 4.0"
        malpedia_sharing = "TLP:WHITE"
        malpedia_rule_date = "20220220"
        malpedia_hash = ""
        
    strings:
        // C2
        $s1 = "http://minecraftsquid.hopto.org/ifo.php" wide
        // Name of assembly in metadata
        $s2 = "BHUNT" wide
        // Outlook misspelled in reg key
        $s3 = "Outllook" wide

    condition:
        // MZ Header
        uint16(0) == 0x5a4d and
        // is a .NET binary
        pe.data_directories[pe.IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR].size != 0 and
        all of ($s*)
}
Download all Yara Rules