SYMBOLCOMMON_NAMEaka. SYNONYMS
win.btcware (Back to overview)

BTCWare

VTCollection    

According to PCRisk, BTCWare is an updated version of a ransomware-type virus called Crptxxx. This ransomware is distributed via a malicious application called "Rogers Hi-Speed Internet". Once infiltrated, BTCWare encrypts files and appends filenames with the ".btcware" extension. Newer variants of this ransomware append .shadow, .payday, .wyvern, .nuclear, .aleta, .gryphon, .nopasaran, .blocking, .xfile, .master, .onyon, .theva, .cryptobyte or .cryptowin extensions to encrypted files. BTCWare then creates an HTM file ("#_HOW_TO_FIX_!.hta.htm"), placing it on the desktop. Other variants of this ransomware use !#_RESTORE_FILES_#!.inf file to store their ransom demanding message.

References
2017-08-28 ⋅ Bleeping Computer ⋅ Lawrence Abrams
New Nuclear BTCWare Ransomware Released (Updated)
BTCWare
Yara Rules
[TLP:WHITE] win_btcware_auto (20260917 | Detects win.btcware.)
rule win_btcware_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.btcware."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.btcware"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 6890d58101 8d4c2418 e8???????? 8d44240c }
            // n = 4, score = 100
            //   6890d58101           | push                0x181d590
            //   8d4c2418             | lea                 ecx, [esp + 0x18]
            //   e8????????           |                     
            //   8d44240c             | lea                 eax, [esp + 0xc]

        $sequence_1 = { 83c002 50 6880d28101 8d842490010000 50 }
            // n = 5, score = 100
            //   83c002               | add                 eax, 2
            //   50                   | push                eax
            //   6880d28101           | push                0x181d280
            //   8d842490010000       | lea                 eax, [esp + 0x190]
            //   50                   | push                eax

        $sequence_2 = { 50 56 ff75e4 ff15???????? 8d45ec 50 }
            // n = 6, score = 100
            //   50                   | push                eax
            //   56                   | push                esi
            //   ff75e4               | push                dword ptr [ebp - 0x1c]
            //   ff15????????         |                     
            //   8d45ec               | lea                 eax, [ebp - 0x14]
            //   50                   | push                eax

        $sequence_3 = { 0f84af000000 85ff 752c 68???????? }
            // n = 4, score = 100
            //   0f84af000000         | je                  0xb5
            //   85ff                 | test                edi, edi
            //   752c                 | jne                 0x2e
            //   68????????           |                     

        $sequence_4 = { 8d4db0 e8???????? ff75e0 8bd0 }
            // n = 4, score = 100
            //   8d4db0               | lea                 ecx, [ebp - 0x50]
            //   e8????????           |                     
            //   ff75e0               | push                dword ptr [ebp - 0x20]
            //   8bd0                 | mov                 edx, eax

        $sequence_5 = { 83f81d 7cf1 eb07 8b0cc5ec494100 894de4 }
            // n = 5, score = 100
            //   83f81d               | cmp                 eax, 0x1d
            //   7cf1                 | jl                  0xfffffff3
            //   eb07                 | jmp                 9
            //   8b0cc5ec494100       | mov                 ecx, dword ptr [eax*8 + 0x4149ec]
            //   894de4               | mov                 dword ptr [ebp - 0x1c], ecx

        $sequence_6 = { 668b74240c 33c0 85ff 7e18 0fb78c4490020000 }
            // n = 5, score = 100
            //   668b74240c           | mov                 si, word ptr [esp + 0xc]
            //   33c0                 | xor                 eax, eax
            //   85ff                 | test                edi, edi
            //   7e18                 | jle                 0x1a
            //   0fb78c4490020000     | movzx               ecx, word ptr [esp + eax*2 + 0x290]

        $sequence_7 = { 47 8a5dee 8a4dec 8a7ded 8955e0 }
            // n = 5, score = 100
            //   47                   | inc                 edi
            //   8a5dee               | mov                 bl, byte ptr [ebp - 0x12]
            //   8a4dec               | mov                 cl, byte ptr [ebp - 0x14]
            //   8a7ded               | mov                 bh, byte ptr [ebp - 0x13]
            //   8955e0               | mov                 dword ptr [ebp - 0x20], edx

        $sequence_8 = { 8b45e0 8d4e0c 6a06 8d904cc54100 5f 668b02 8d5202 }
            // n = 7, score = 100
            //   8b45e0               | mov                 eax, dword ptr [ebp - 0x20]
            //   8d4e0c               | lea                 ecx, [esi + 0xc]
            //   6a06                 | push                6
            //   8d904cc54100         | lea                 edx, [eax + 0x41c54c]
            //   5f                   | pop                 edi
            //   668b02               | mov                 ax, word ptr [edx]
            //   8d5202               | lea                 edx, [edx + 2]

        $sequence_9 = { 0f82a070ffff 83f923 0f879770ffff 8bc8 51 e8???????? 83c404 }
            // n = 7, score = 100
            //   0f82a070ffff         | jb                  0xffff70a6
            //   83f923               | cmp                 ecx, 0x23
            //   0f879770ffff         | ja                  0xffff709d
            //   8bc8                 | mov                 ecx, eax
            //   51                   | push                ecx
            //   e8????????           |                     
            //   83c404               | add                 esp, 4

    condition:
        7 of them and filesize < 458752
}
Download all Yara Rules