🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8f8239a8b0e30eca06fce80fbf744a596d3a74bbe53f3a14d26e090bd4541397. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Arechclient2


Vendor detections: 10


Intelligence 10 IOCs YARA 7 File information Comments

SHA256 hash: 8f8239a8b0e30eca06fce80fbf744a596d3a74bbe53f3a14d26e090bd4541397
SHA3-384 hash: 16be784cfc828663fd2fb293360723cbf70932639711df75f9c587b5a6d2ea38b20706d9970c44737b2f691703ede00e
SHA1 hash: 95cef82171b638074cf4bd0e8a3f875e55db9841
MD5 hash: 4160223ab42e6c414c2387ff33173a30
humanhash: asparagus-sierra-juliet-robert
File name:d-56364130-1079Ef-f.ps1
Download: download sample
Signature Arechclient2
File size:68'265 bytes
First seen:2026-09-25 23:20:41 UTC
Last seen:Never
File type:PowerShell (PS) ps1
MIME type:text/plain
ssdeep 1536:4X/eqvLNNXT+H5HOYlR6jzjFH/JCHsd1XQrbGvz1f:4X26LNxG4YlR6jzNYHk1gryLt
TLSH T1A56354533AA442E9328DCEB20E40546DDEE6F033D29EA55C76CD68C8B7B37A452E4C35
Magika powershell
Reporter aachum
Tags:178-104-144-200 Arechclient2 AsgardProtector dropped-by-ACRStealer ps1 SectopRAT


Avatar
iamaachum
https://except.stood.work/78d4-1-1f7237

Arechclient2/SectopRAT C2: 178.104.144.200

Intelligence


File Origin
# of uploads :
1
# of downloads :
106
Origin country :
ES ES
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
anti-debug anti-vm autoit base64 encrypted evasive fingerprint fingerprint keylogger obfuscated reconnaissance
Verdict:
Malicious
File Type:
ps1
First seen:
2026-09-25T21:15:00Z UTC
Last seen:
2026-09-26T22:12:00Z UTC
Hits:
~100
Result
Threat name:
Arechclient2
Detection:
malicious
Classification:
troj.spyw.expl.evad
Score:
100 / 100
Signature
Creates a thread in another existing process (thread injection)
Creates processes via WMI
Found direct / indirect Syscall (likely to bypass EDR)
Found malware configuration
Injects a PE file into a foreign processes
Installs a global keyboard hook
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Modifies the context of a thread in another process (thread injection)
Multi AV Scanner detection for submitted file
Powershell connects to network
Powershell drops PE file
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sigma detected: Bad Opsec Defaults Sacrificial Processes With Improper Arguments
Sigma detected: Dot net compiler compiles file from suspicious location
Suspicious execution chain found
Tries to harvest and steal browser information (history, passwords, etc)
Writes to foreign memory regions
Yara detected Arechclient2
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1978406 Sample: d-56364130-1079Ef-f.ps1 Startdate: 26/09/2026 Architecture: WINDOWS Score: 100 70 metrics.agoxpathbet.one 2->70 72 nCFHXxdXxlINtTGGOFDfL.nCFHXxdXxlINtTGGOFDfL 2->72 80 Found malware configuration 2->80 82 Malicious sample detected (through community Yara rule) 2->82 84 Multi AV Scanner detection for submitted file 2->84 86 4 other signatures 2->86 11 powershell.exe 15 43 2->11         started        16 AutoIt3.exe 2->16         started        18 AutoIt3.exe 2->18         started        20 svchost.exe 1 1 2->20         started        signatures3 process4 dnsIp5 76 metrics.agoxpathbet.one 104.21.45.199, 443, 49710 CLOUDFLARENET-CloudflareIncUS Canada 11->76 64 C:\Users\user\AppData\Roaming\...\AutoIt3.exe, PE32+ 11->64 dropped 66 C:\Users\user\AppData\Roaming\...\Fabrics.a3x, data 11->66 dropped 68 C:\Users\user\AppData\...\ilm5eswz.cmdline, Unicode 11->68 dropped 106 Suspicious execution chain found 11->106 108 Creates processes via WMI 11->108 110 Powershell connects to network 11->110 112 Powershell drops PE file 11->112 22 AutoIt3.exe 1 11->22         started        26 conhost.exe 11->26         started        28 csc.exe 3 11->28         started        30 csc.exe 3 11->30         started        114 Writes to foreign memory regions 16->114 116 Modifies the context of a thread in another process (thread injection) 16->116 118 Injects a PE file into a foreign processes 16->118 120 Found direct / indirect Syscall (likely to bypass EDR) 16->120 32 RegAsm.exe 16->32         started        34 RegAsm.exe 18->34         started        78 127.0.0.1 unknown unknown 20->78 file6 signatures7 process8 file9 58 C:\Users\user\AppData\Roaming\...\RegAsm.exe, PE32+ 22->58 dropped 96 Writes to foreign memory regions 22->96 98 Modifies the context of a thread in another process (thread injection) 22->98 100 Injects a PE file into a foreign processes 22->100 102 Found direct / indirect Syscall (likely to bypass EDR) 22->102 36 RegAsm.exe 22->36         started        104 Installs a global keyboard hook 26->104 60 C:\Users\user\AppData\Local\...\ilm5eswz.dll, PE32 28->60 dropped 40 cvtres.exe 1 28->40         started        62 C:\Users\user\AppData\Local\...\ttrlvxph.dll, PE32 30->62 dropped 42 cvtres.exe 1 30->42         started        signatures10 process11 dnsIp12 74 178.104.144.200, 443, 49714 HETZNER-ASDE Germany 36->74 88 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 36->88 90 Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines) 36->90 92 Tries to harvest and steal browser information (history, passwords, etc) 36->92 94 4 other signatures 36->94 44 chrome.exe 36->44         started        46 chrome.exe 36->46         started        signatures13 process14 process15 48 chrome.exe 44->48 injected 50 WerFault.exe 44->50         started        52 chrome.exe 46->52 injected 54 chrome.exe 46->54         started        process16 56 WerFault.exe 48->56         started       
Verdict:
Malware
YARA:
1 match(es)
Tags:
Base64 Block Contains Base64 Block DeObfuscated PowerShell T1027 T1059.001 T1105
Result
Malware family:
sectoprat
Score:
  10/10
Tags:
family:sectoprat discovery execution persistence rat trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of FindShellTrayWindow
Suspicious use of SendNotifyMessage
Suspicious use of WriteProcessMemory
Command and Scripting Interpreter: PowerShell
Reads the TCP/IP host and domain name from the registry
Suspicious use of SetThreadContext
Adds Run key to start application
Enumerates connected drives
Executes dropped EXE
Badlisted process makes network request
Detects SectopRAT aka Arechclient2
Family: SectopRAT
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ClamAV_Emotet_String_Aggregate
Rule name:detect_powershell
Author:daniyyell
Description:Detects suspicious PowerShell activity related to malware execution
Rule name:Detect_PowerShell_Obfuscation
Author:daniyyell
Description:Detects obfuscated PowerShell commands commonly used in malicious scripts.
Rule name:OBFUS_PowerShell_Common_Replace
Author:SECUINFRA Falcon Team
Description:Detects the common usage of replace for obfuscation
Rule name:Suspicious_PS_Strings
Author:Lucas Acha (http://www.lukeacha.com)
Description:observed set of strings which are likely malicious, observed with Jupyter malware.
Reference:http://security5magics.blogspot.com/2020/12/tracking-jupyter-malware.html
Rule name:SUSP_PowerShell_Base64_Decode
Author:SECUINFRA Falcon Team
Description:Detects PowerShell code to decode Base64 data. This can yield many FP
Rule name:Sus_CMD_Powershell_Usage
Author:XiAnzheng
Description:May Contain(Obfuscated or no) Powershell or CMD Command that can be abused by threat actor(can create FP)

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Arechclient2

PowerShell (PS) ps1 8f8239a8b0e30eca06fce80fbf744a596d3a74bbe53f3a14d26e090bd4541397

(this sample)

  
Dropped by
ACRStealer
  
Delivery method
Distributed via web download

Comments