# Cryptbot Stealer - Update on Rules

**URL:** <https://community.emergingthreats.net/t/cryptbot-stealer-update-on-rules/790>\
**Category:** Rule Signatures\
**Created:** [July 21, 2023, 6:17pm UTC](https://community.emergingthreats.net/t/cryptbot-stealer-update-on-rules/790 "2023-07-21T18:17:40Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![g0njxa](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/g0njxa/32/364_2.png) [@g0njxa](https://community.emergingthreats.net/u/g0njxa)\
**Post date:** [July 21, 2023, 6:17pm UTC](https://community.emergingthreats.net/t/cryptbot-stealer-update-on-rules/790/1 "2023-07-21T18:17:40Z")

</div>

Cryptbot Stealer has been switching its behavior in the past weeks from uploading logs to C2 on /gate.php to /zip.php. Maybe there are more changes.  
I believe this change has been completed and theres no rule detection for Cryptbot as for now, so old rules must need to be updated.

OLD DETONATION  
([Analysis https://kickasscracks.com Malicious activity - Interactive analysis ANY.RUN](https://app.any.run/tasks/1acacd8b-9ddd-4464-9a32-f190d4660237/))

Rules related to cryptbot fired

- ET MALWARE Win32/Cryptbotv2 CnC Activity (POST) M1
- ET MALWARE Win32/Cryptbot V2 Data Exfiltration Attempt
- ET MALWARE Win32/Cryptbotv2 CnC Activity (POST) M2

NEW DETONATION  
([Analysis https://abbaspc.net Malicious activity - Interactive analysis ANY.RUN](https://app.any.run/tasks/8e3e870c-04a7-41eb-b52d-3a023185a395))

No rules fired, 0 detection on Cryptbot.

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![bingohotdog](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/bingohotdog/32/42_2.png) [@bingohotdog](https://community.emergingthreats.net/u/bingohotdog)\
**Post date:** [July 24, 2023, 8:20pm UTC](https://community.emergingthreats.net/t/cryptbot-stealer-update-on-rules/790/2 "2023-07-24T20:20:23Z")

</div>

Thanks for the share, [g0njxa](https://community.emergingthreats.net/u/g0njxa). I’ve added a new rule to detect these new Cryptbot variants. It should appear in the release today. If you find new variants, please let us know so we can continue to add detection.

🌭

---

<div class="post-metadata">

**Author:** ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Post date:** [July 29, 2023, 9:05pm UTC](https://community.emergingthreats.net/t/cryptbot-stealer-update-on-rules/790/3 "2023-07-29T21:05:45Z")

</div>

Believe this was 2046886, thanks!

---

<div class="post-metadata">

**Author:** ![g0njxa](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/g0njxa/32/364_2.png) [@g0njxa](https://community.emergingthreats.net/u/g0njxa)\
**Post date:** [July 5, 2024, 6:10am UTC](https://community.emergingthreats.net/t/cryptbot-stealer-update-on-rules/790/4 "2024-07-05T06:10:02Z")

</div>

Hello!

New variants have been found in the wild, curently without proper rule detection.

Detonation: [Analysis https://iplogger.com/2lEuz3 Malicious activity - Interactive analysis ANY.RUN](https://app.any.run/tasks/c4a98765-6d7d-41e7-a963-bf4713cfb33d)

C2 - [http://rzninet19ht.top/v1/upload.php](http://rzninet19ht.top/v1/upload.php)

Would be interesting to add detection to these new variants of Cryptbot

---

<div class="post-metadata">

**Author:** ![ishaughnessy](https://sea2.discourse-cdn.com/flex016/user_avatar/community.emergingthreats.net/ishaughnessy/32/491_2.png) [@ishaughnessy](https://community.emergingthreats.net/u/ishaughnessy)\
**Post date:** [July 5, 2024, 9:45pm UTC](https://community.emergingthreats.net/t/cryptbot-stealer-update-on-rules/790/5 "2024-07-05T21:45:31Z")

</div>

hey @g0njxa -

Thanks for the tip! We got the following signatures into today’s release that should cover the gap.

```auto
2054347 - ET MALWARE Cryptbot CnC Domain in DNS Lookup (analforeverlove .top)
2054348 - ET MALWARE Cryptbot CnC Domain in DNS Lookup (rzfift15ht .top)
2054349 - ET MALWARE Cryptbot CnC Domain in DNS Lookup (rzeight18pt .top)
2054350 - ET MALWARE Win32/Cryptbotv2 CnC Activity (POST) M4
2054351 - ET MALWARE Observed Cryptbot Domain (analforeverlove .top in TLS SNI)
2054352 - ET MALWARE Observed Cryptbot Domain (rzfift15ht .top in TLS SNI)
2054353 - ET MALWARE Observed Cryptbot Domain (rzeight18pt .top in TLS SNI)

```

I’m also working on some signatures to detect the DGA pattern that they are using right now and should have that out on Monday,

Thanks and have a great weekend! 🕶  
Isaac
