🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f0710dbb4fe2f9062dd1fadd47b4699aebbd19a62abb39e86bb6215fa4ea1c9b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Arechclient2


Vendor detections: 4


Intelligence 4 IOCs YARA 25 File information Comments

SHA256 hash: f0710dbb4fe2f9062dd1fadd47b4699aebbd19a62abb39e86bb6215fa4ea1c9b
SHA3-384 hash: 50e53b2dd30969542438e3950fd6a2c30132710c6224dcde30d7f6687001c28d60a3b6bb22aa6711ed3f3fe42df40c8b
SHA1 hash: 46102edba7d808aabe908d7355bab75c9d336cea
MD5 hash: e29482b84e7c56b229699c016410953a
humanhash: ink-tennessee-oven-jig
File name:eurebu.zip
Download: download sample
Signature Arechclient2
File size:15'959'871 bytes
First seen:2026-09-12 14:08:32 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 196608:1KLWheWj/T3LR7FLOyomFHKnPmWD/fXoAEkZWzSdMeTh8qtXW4DY:1bL5FYEkZWKhx5Y
TLSH T1B2F69D26779E0492D066D179895B4627EBB2BC02073993CB91A2BF5E1F737F2063B710
Magika zip
Reporter aachum
Tags:145-63-128-66 Arechclient2 dropped-by-ACRStealer HIjackLoader IDATLoader SectopRAT zip


Avatar
iamaachum
https://pub-e10d56052d2542d0b2f74abed3691951.r2.dev/eurebu.zip

SectopRAT/Arechclient2 C2: 145.63.128.66

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
ES ES
File Archive Information

This file archive contains 11 file(s), sorted by their relevance:

File name:vcruntime140_1.dll
File size:49'792 bytes
SHA256 hash: e30b3f4979b63b50438d061858c9cde962f4494e585c627a11c98b6c5b7b2592
MD5 hash: 851760a3cc87354e057985e42e69f425
MIME type:application/x-dosexec
Signature Arechclient2
File name:msvcp_win.dll
File size:635'952 bytes
SHA256 hash: 2a7825c2925347e0cb767a0dcb611f3eb80d0f71cbec981069b227bdc7cb871a
MD5 hash: ec9f1cdd909f7c0bae4db21dcd2033de
MIME type:application/x-dosexec
Signature Arechclient2
File name:Microsoft.Data.SqlClient.SNI.dll
File size:503'728 bytes
SHA256 hash: b99da433d42a9ac546868b3b5fca27439a9d99d7981369e74557547be87b7542
MD5 hash: 46a7ca270fdd2cb4744798f3bd5a5d65
MIME type:application/x-dosexec
Signature Arechclient2
File name:SupMesh.exe
File size:5'629'512 bytes
SHA256 hash: d2c9299134e112bae225c56f2c09626da2999a765202b16abb56a8d4376e5848
MD5 hash: 5951fefc798ddc89edc49e94348c7c27
MIME type:application/x-dosexec
Signature Arechclient2
File name:daemon8.sys
File size:1'582'470 bytes
SHA256 hash: ec35193d659766d265ece5ae3167c62b3b937f1a74c5557befb1972b84e72389
MD5 hash: b8753d48a912385df7654c303f77e787
MIME type:application/octet-stream
Signature Arechclient2
File name:vcruntime140.dll
File size:124'520 bytes
SHA256 hash: 60b813f8b87ff4fa344f081c163c1a2234b5e3e41f748721c28fbdecbcfecb8a
MD5 hash: ec0117040bd1e880088753d9b8467234
MIME type:application/x-dosexec
Signature Arechclient2
File name:ucrtbase.dll
File size:1'046'080 bytes
SHA256 hash: 3c60056371f82e4744185b6f2fa0c69042b1e78804685944132974dd13f3b6d9
MD5 hash: 4e326feeb3ebf1e3eb21eeb224345727
MIME type:application/x-dosexec
Signature Arechclient2
File name:msvcp140.dll
File size:557'136 bytes
SHA256 hash: 1e2e2bcb916931f0ee6d0a567212511244e7442da574757c331c1b91087f2a0f
MD5 hash: b08063e2d0bb587538575af2babac0b2
MIME type:application/x-dosexec
Signature Arechclient2
File name:WebView2Loader.dll
File size:148'480 bytes
SHA256 hash: 348a783350d6310bd63ba215b1e065f3d46f80bfd3373219b7c496372b596969
MD5 hash: 2bee9a527354e8b2ba168619f1a2db37
MIME type:application/x-dosexec
Signature Arechclient2
File name:mfc140u.dll
File size:5'666'928 bytes
SHA256 hash: 8d97422cb84fd123deafce190fce6f34d868f7e692593fe1ed7d91ee7161ac27
MD5 hash: b4d93addb6f8cd8baefe3004f94a12a4
MIME type:application/x-dosexec
Signature Arechclient2
File name:system_gate.dat
File size:13'681 bytes
SHA256 hash: b25713a7201b143ab9fe1169cec0a6f72d1dced0f072e6ca14d2c31feb2c2a02
MD5 hash: 00938e570263bd81bb7985586a37bd0c
MIME type:application/octet-stream
Signature Arechclient2
Vendor Threat Intelligence
Gathering data
Verdict:
Unknown
Threat level:
n/a  -.1.0/10
Confidence:
100%
Tags:
anti-debug crypto expired-cert fingerprint microsoft_visual_cc signed
Verdict:
inconclusive
YARA:
3 match(es)
Tags:
Executable PDB Path PE (Portable Executable) PE File Layout Zip Archive
Threat name:
Binary.Trojan.Rugmi
Status:
Malicious
First seen:
2026-09-12 14:09:27 UTC
File Type:
Binary (Archive)
Extracted files:
1435
AV detection:
6 of 38 (15.79%)
Threat level:
  5/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:Check_OutputDebugStringA_iat
Rule name:cobalt_strike_tmp01925d3f
Author:The DFIR Report
Description:files - file ~tmp01925d3f.exe
Reference:https://thedfirreport.com
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DebuggerCheck__API
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DebuggerException__SetConsoleCtrl
Reference:https://github.com/naxonez/yaraRules/blob/master/AntiDebugging.yara
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:Detect_all_IPv6_variants
Author:Bierchermuesli
Description:Generic IPv6 catcher
Rule name:golang_bin_JCorn_CSC846
Author:Justin Cornwell
Description:CSC-846 Golang detection ruleset
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:NET
Author:malware-lu
Rule name:pe_detect_tls_callbacks
Rule name:PE_Digital_Certificate
Author:albertzsigovits
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:telebot_framework
Author:vietdx.mb
Rule name:TH_AntiVM_MassHunt_Win_Malware_2026_CYFARE
Author:CYFARE
Description:Detects Windows malware employing anti-VM / anti-sandbox evasion techniques across VMware, VirtualBox, Hyper-V, QEMU, Xen, and generic sandbox environments
Reference:https://cyfare.net/
Rule name:VECT_Ransomware
Author:Mustafa Bakhit
Description:Detects activity associated with VECT ransomware. This includes registry modifications and deletions, execution of system and defense-evasion commands, suspicious API usage, mutex creation, file and memory manipulation, ransomware note generation, anti-debugging and anti-analysis techniques, and embedded cryptographic constants (SHA256) characteristic of this malware family. Designed for threat intelligence and malware detection environments.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Arechclient2

zip f0710dbb4fe2f9062dd1fadd47b4699aebbd19a62abb39e86bb6215fa4ea1c9b

(this sample)

  
Dropped by
ACRStealer
  
Delivery method
Distributed via web download

Comments