A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #28220  by EP_X0FF
 Wed Apr 06, 2016 6:55 am
It is BTC Stealer from idiot with username "Santa Claus"

dropper -> dotnet RunPE with primitive antiVM -> fake messagebox -> 2nd stage dotnet dropper -> dotnet Payload (https://www.virustotal.com/en/file/22e6 ... /analysis/)
C:\Users\Santa Claus\Desktop\Download\The FILE\BTC-Stealer (No MSG)\BitcoinStealer\obj\Release\AU-Run-Immediately.pdb
All stages in attach, but I really doubt someone whats to looks inside this dotnet shit.
Attachments
pass: malware
(799.68 KiB) Downloaded 56 times
 #28222  by kminfo
 Wed Apr 06, 2016 2:05 pm
Well thank you for the analysis.

I do not have BTC , but I ran the file on my pc. How to remove it ? if the malware stays hidden.

What tools did you use for analysis ?
 #28224  by rootjacker
 Wed Apr 06, 2016 2:25 pm
kminfo wrote:Well thank you for the analysis.

I do not have BTC , but I ran the file on my pc. How to remove it ? if the malware stays hidden.
Delete the file in your home directory (Adobe\\Updater\\AdobeHelper.exe), remove the key in the registry(SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run), and reboot.
 #28225  by kminfo
 Wed Apr 06, 2016 2:58 pm
Maybe this guy created or someone used code from here -
Code: Select all
https://tech9tutorialz.wordpress.com/tag/preferably-on-onion-websites-because-thats-where-all-the-good-stuff-is-here-is-the-code-i-used-using-system-using-system-collections-g/