MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 952e0e0ade47380a9bddfc173746aafb755a3a5f7739150f73f6f7fab26b2305. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Arechclient2


Vendor detections: 15


Intelligence 15 IOCs YARA File information Comments 1

SHA256 hash: 952e0e0ade47380a9bddfc173746aafb755a3a5f7739150f73f6f7fab26b2305
SHA3-384 hash: 6a01238a3c1371403d71b25b452702a517b259a26a109eae22f2ed273d2118cf1f7979f7dd3cb5a061db0c2e735f4a0d
SHA1 hash: 0f169538d3a469c1f2329d2d606ebc2c3b1ae356
MD5 hash: c9db3bc218f02d26844913714a12bcee
humanhash: berlin-mississippi-california-lemon
File name:c9db3bc218f02d26844913714a12bcee
Download: download sample
Signature Arechclient2
File size:4'477'160 bytes
First seen:2023-12-15 14:07:44 UTC
Last seen:2023-12-15 15:17:12 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash f34d5f2d4577ed6d9ceec516c1f5a744 (48'649 x AgentTesla, 19'452 x Formbook, 12'202 x SnakeKeylogger)
ssdeep 98304:WGxUcDO50Cz0jt76UVXO9sEdigo4cl4429NPldUz:WGxUcDO50CzgtOYXO9BAgo4l429Ntdm
Threatray 257 similar samples on MalwareBazaar
TLSH T155269D137254EF25C2194A378BDF952013F8E5213E21CF2E2B6E337C529671689A39ED
TrID 49.0% (.EXE) Generic CIL Executable (.NET, Mono, etc.) (73123/4/13)
20.9% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
8.7% (.SCR) Windows screen saver (13097/50/3)
7.0% (.EXE) Win64 Executable (generic) (10523/12/4)
4.4% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
File icon (PE):PE icon
dhash icon fce4e4d4c8ccc8d8 (1 x Arechclient2)
Reporter zbetcheckin
Tags:32 Arechclient2 exe

Intelligence


File Origin
# of uploads :
2
# of downloads :
300
Origin country :
FR FR
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a window
Сreating synchronization primitives
Creating a file in the %temp% directory
Launching a process
Creating a file in the %AppData% subdirectories
Creating a file
DNS request
Sending a custom TCP request
Forced shutdown of a system process
Unauthorized injection to a system process
Enabling autorun by creating a file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
cmd lolbin msbuild net_reactor obfuscated overlay packed packed
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Malware family:
Generic Malware
Verdict:
Malicious
Result
Threat name:
RedLine
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
.NET source code contains method to dynamically call methods (often used by packers)
Allocates memory in foreign processes
Connects to a pastebin service (likely for C&C)
Connects to many ports of the same IP (likely port scanning)
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Writes to foreign memory regions
Yara detected AntiVM3
Yara detected RedLine Stealer
Behaviour
Behavior Graph:
Threat name:
Win32.Spyware.RedLine
Status:
Malicious
First seen:
2023-12-15 03:52:26 UTC
AV detection:
14 of 37 (37.84%)
Threat level:
  2/5
Result
Malware family:
sectoprat
Score:
  10/10
Tags:
family:sectoprat rat trojan
Behaviour
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Program crash
Suspicious use of SetThreadContext
Legitimate hosting services abused for malware hosting/C2
Drops startup file
Loads dropped DLL
SectopRAT
SectopRAT payload
Unpacked files
SH256 hash:
3ef6b85ea5ec21e5edf64014b40051a5837294c4e29684a358804d0e2c90c2b3
MD5 hash:
ff60060d1bc257fb3c4e12836e74e6dc
SHA1 hash:
798532ae880ab7391ab18bc5a501940a6f593b65
Detections:
SUSP_XORed_URL_In_EXE MALWARE_Win_Arechclient2
SH256 hash:
952e0e0ade47380a9bddfc173746aafb755a3a5f7739150f73f6f7fab26b2305
MD5 hash:
c9db3bc218f02d26844913714a12bcee
SHA1 hash:
0f169538d3a469c1f2329d2d606ebc2c3b1ae356
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Arechclient2

Executable exe 952e0e0ade47380a9bddfc173746aafb755a3a5f7739150f73f6f7fab26b2305

(this sample)

Comments



Avatar
zbet commented on 2023-12-15 14:07:45 UTC

url : hxxp://185.172.128.160/hv.exe