Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Arechclient2

72
Global rank
92 infographic chevron month
Month rank
126 infographic chevron week
Week rank
0
IOCs

The Arechclient2 malware is a sophisticated .NET-based Remote Access Trojan (RAT) that collects sensitive information, such as browser credentials, from infected computers. It employs various stealth techniques, including Base64 encoding to obscure its code and the ability to pause activities to evade automated security tools. The malware also can adjust Windows Defender settings and uses code injection to manipulate legitimate processes.

RAT
Type
Unknown
Origin
1 November, 2019
First seen
26 August, 2026
Last seen
Also known as
SectopRAT

How to analyze Arechclient2 with ANY.RUN

RAT
Type
Unknown
Origin
1 November, 2019
First seen
26 August, 2026
Last seen

IOCs

IP addresses
145.63.138.138
95.100.102.101
48.209.138.189
150.171.27.11
52.123.243.90
2.16.241.223
2.16.241.7
199.232.210.172
92.223.97.79
48.209.6.48
74.178.76.54
150.171.28.11
2.16.241.219
2.16.241.201
104.102.63.189
74.178.240.61
48.209.133.15
74.179.77.204
20.190.160.20
48.192.1.65
Hashes
1d20603f695dc73a621d36c41c346d16a328a5e5eeb27033764226719f170883
25fb23868ebf48348f9e438e00cb9b9d9b3a054f32482a781c762cc4f9cc6393
568a0f6eed5a5674316e0cb6f35ef38bdd9947cfa02efc286bae793aff6ca231
ee810a451aea499c3d6f89edb840ed025df0937874485a211a3bb39f915f4ea0
1b2fefbe93afd3f42a9e37f6afd123dc71919313b8ebb20c4990f0f67d7365d5
1b3d6e1878afbd806dc16b15bf36ea113429b64c7597236f81c91406cf727b1c
90e734b891a5cf67004cd19fb56718b84d70fc0b758d207bc2c2e6b520e2f19a
77935955686798514e6a8e45c83bc395b266d5974582e1e1ad38fd26bdbb6183
6dfbd1239bf08e1797f2f4d6dfd52cc5081b09806849f507b821e4a732a5669d
663441dc2c7ae66f6ea1bd5f9787831b7cbb39a76988d74d079499398c84f051
14f92b911f9fe774720461eec5bb4761ae6bfc9445c67e30bf624a8694b4b1da
a2ca52e34b6138624ac2dd20349cde28482143b837db40a7f0fbda023077c26a
f096bc366a931fba656bdcd77b24af15a5f29fc53281a727c79f82c608ecfab8
a0c9abae18599f0a65fc654ad36251f6330794bea66b718a09d8b297f3e38e87
41c91a9c93d76295746a149dce7ebb3b9ee2cb551d84365fff108e59a61cc304
fc525b684be2945a43ca04de402d74a1ea1901c48bf2eafe5fa814bfccfb4378
329b20f56d6438f20aef784d9bd7b686dd16550dc84967bb5be3dc0a1c29ce18
16ce95d9bc2ba6a7e62fb16f19208ffe3f73f81cf2993f86dc5d6fa88443a43f
6f0f4073a60a2497ef460238a6888a4e4534c59d97f412558e293d1c1ce42a60
474d668707f1cb929fef1e3798b71b632e50675bd1a9dceaab90c9587f72f680
Domains
crl.microsoft.com
edge.microsoft.com
settings-win.data.microsoft.com
www.bing.com
fs.microsoft.com
fe3cr.delivery.mp.microsoft.com
slscr.update.microsoft.com
msedge.b.tlu.dl.delivery.mp.microsoft.com
google.com
config.edge.skype.com
www.microsoft.com
activation-v2.sls.microsoft.com
login.live.com
ocsp.digicert.com
ocsp.r2m01.amazontrust.com
accounts.google.com
r.msftstatic.com
copilot.microsoft.com
ntp.msn.com
pop.betterplatform.cc
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3593&flightids=&updateoffereddays=344&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%206%20model%2014%20stepping%203&sku=48&activationchannel=retail&attrdataver=188&ismdmenrolled=0&processorcores=4&processormodel=intel%28r%29%20core%28tm%29%20i5-6400%20cpu%20%40%202.70ghz&totalphysicalram=4096&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260246&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
http://145.63.138.138/wbinjget?q=a3bd7fa9898315eae64d91e682143454
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/e1447940-5090-4f3b-9c07-17966e50ad9c?p1=1780046820&p2=404&p3=2&p4=physy89aqwkwxskn2%2ffjf3gqstp6pbc2r3wm3h3abpgglmomzkexp2leqnuohsz%2brpcicq2piiz6mhg35zztmq%3d%3d
https://fs.microsoft.com/fs/windows/config.json
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=188&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%206%20model%2014%20stepping%203&oemmodel=dell&updateoffereddays=344&processormanufacturer=authenticamd&installdate=1662378835&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&isflightingenabled=0&osskuid=48&processorclockspeed=3593&totalphysicalram=4096&securebootcapable=0&app=waasassessment&processorcores=4&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=188&processormodel=intel%28r%29%20core%28tm%29%20i5-6400%20cpu%20%40%202.70ghz&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3593&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=188&processorcores=4&branchreadinesslevelraw=16&totalphysicalram=4096&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260246&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&activehoursstart=8&securebootcapable=0&activehoursend=17&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%206%20model%2014%20stepping%203&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1662378835&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&isflightingenabled=0&osskuid=48&processorclockspeed=3593&totalphysicalram=4096&securebootcapable=0&app=sedimentpack&processorcores=4&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=188&processormodel=intel%28r%29%20core%28tm%29%20i5-6400%20cpu%20%40%202.70ghz&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://settings-win.data.microsoft.com/settings/v3.0/wsd/qualityremediation?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%206%20model%2014%20stepping%203&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1662378835&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&isflightingenabled=0&osskuid=48&processorclockspeed=3593&totalphysicalram=4096&securebootcapable=0&app=sedimentpack&processorcores=4&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=188&processormodel=intel%28r%29%20core%28tm%29%20i5-6400%20cpu%20%40%202.70ghz&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/63c258d6-4ed4-4080-a99f-b692b9844f58?p1=1780046821&p2=404&p3=2&p4=bjmvvdydj3kxm1%2fljlub5itxlg8orfkk%2b%2f3bp6l%2fcijax5gs5wpmrbebj1ea1l98ru2isepykpfmayfvb4viiq%3d%3d
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3138ce11-89ae-4e1a-93a3-b17e30c5f0b6?p1=1780131450&p2=404&p3=2&p4=edvluavv8lomm1uszlclvhzpocyirewcf%2fr143vzq8o8idr4%2fpibbbyfq235en7jlocbbvboipdf6ipj6vqcxw%3d%3d
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/a39794f2-c084-4aea-b52a-bd39d8783175?p1=1780387638&p2=404&p3=2&p4=ftvmcl%2fit9wslqldg2cn8jzagpgb12kmapifr%2bjymbepp59yfkikkonc49begzgtdn4kobwppbumf4jfbeewaa%3d%3d
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/cdca748d-949b-4e5b-ba90-e721ceb58566?p1=1780046821&p2=404&p3=2&p4=gue1h7qd0zeuyol8esdzvdvckhwrf8xdrqg4w%2bnnxp8smjnhp4csqizz7r7wdybwpqxpxs371e2p%2bf1ah7luwa%3d%3d
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/1159c5f4-512b-4855-918f-92aa88aa927b?p1=1780046820&p2=404&p3=2&p4=dnasovmiptcbjopgrpivdiiifinvzygwem118kmy2wm3rfh199ekcuhsdtnx6e40gxyq4qeliydctsiodncjea%3d%3d
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20update%20signing%20ca%202.3.crl
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 4792
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 11109
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 13464
comments 0

What is Arechclient2 malware?

Arechclient2 is a .NET Remote Access Trojan (RAT) that was first observed in 2019. It is also widely known under the name SectopRAT. This malware is designed to steal sensitive data from browsers and cryptocurrency wallets, posing a significant threat to users' personal and financial information.

The distribution of Arechclient2 is typically carried out through malicious links, executable file uploads, and fake application updates. In some cases, it may be distributed as an LNK file or as an ISO file containing a malicious executable, making it difficult for users to detect and avoid infection.

Arechclient2 analyzed inside ANY.RUN sandbox Arechclient2 analyzed inside ANY.RUN sandbox

Analysis in ANY.RUN’s interactive malware sandbox shows that ArechClient2 makes considerable use of scripts and process injection to facilitate infection.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Arechclient2 malware technical details

Some of the primary capabilities of the Arechclient2 malware include:

  • Collection of sensitive information, including browser credentials.
  • Use of Base64 encoding for code obfuscation.
  • Temporary pausing of activities for evasion of automated security tools.
  • Adjustment of Windows Defender settings for detection evasion.
  • Employment of code injection for manipulation of legitimate processes.
  • Maintenance of persistence through script execution on startup.
  • Exchange of encrypted and plain text data with its command and control (C2) server.

Arechclient2 execution process

Let’s take a closer look at the stages of Arechclient2 infection by analyzing its sample inside ANY.RUN’s cloud sandbox for malware analysis.

Arechclient2 malicious process inside ANY.RUN sandbox ANY.RUN identifies malicious processes and lists all the actions performed by the malware

The process starts with the delivery of a malicious first-stage payload, which can vary between campaigns. It may be distributed as an LNK file or as an ISO file containing a malicious executable. These files are often spread through unknown initial attack vectors, likely involving social engineering or phishing tactics that trick users into executing them.

When the LNK file is double-clicked, it starts the system utility forfiles.exe to achieve indirect command execution by running PowerShell. An ISO file is mounted like a CD, and the executable may run automatically, initiating the infection process. Upon execution, the payload may extract files into a newly created directory within the victim’s temporary files. This extraction process also initiates multiple child processes crucial to the RAT’s functionality. The execution chain often uses AutoIT, further complicating detection efforts.

Arechclient2 Suricata analysis inside ANY.RUN sandbox ANY.RUN uses Suricata IDS to spot malicious network activities

The malware injects its payload into legitimate processes (e.g., InstallUtil.exe) using a function that facilitates injection while avoiding antivirus hooks by copying necessary files from system directories. This step is critical for maintaining stealth and ensuring continued control over the infected machine. Arechclient2 connects to its command and control (C2) server on port 15647 to receive commands. The communication includes encrypted data, which can switch to plaintext if encryption is disabled during interception. This allows attackers to issue commands remotely, manipulate settings, or extract sensitive information from the victim’s system.

Arechclient2 IOCs inside ANY.RUN sandbox After analysis in ANY.RUN, you can collect a detailed threat report and IOCs

The RAT can extensively profile victim systems, stealing sensitive information such as browser data and cryptocurrency wallet details. It can also launch hidden sessions to monitor user activity without detection.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Arechclient2 distribution methods

ArechClient2 uses various methods to trick users into clicking on harmful links that look legitimate.

Phishing techniques are employed to convince users to open files containing malicious content, which starts the infection process.

One common distribution method is to disguise the malware as updates for popular applications like Brave Browser, TOR, Signal, and Telegram.

By appearing as genuine updates, the malware takes advantage of users' trust in these applications to increase the chances of infection.

Gathering Threat Intelligence on Arechclient2 Malware

To obtain up-to-date intelligence on ArechClient2, utilize Threat Intelligence Lookup from ANY.RUN. This service grants access to a vast database containing Indicators of Compromise (IOCs), Indicators of Attack (IOAs), and Indicators of Behavior (IOBs) from millions of malware analysis sessions performed within the ANY.RUN sandbox. With over 40 customizable search parameters, users can retrieve data on threats, including IPs, domains, file names, and process artifacts associated with ArechClient2.

Arechclient2 results inside ANY.RUN's TI Lookup TI Lookup helps you enrich your investigations with additional threat context

For instance, to gather information on ArechClient2, you can search using its threat name or related artifacts. Inputting a query like threatName:"arechclient2" AND domainName:"" will produce a list of files, events, domain names, and other data extracted from malware samples, along with sandbox sessions that can be examined in detail to gain in-depth understanding of this malware’s behavior.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Arechclient2, also known as SectopRAT, is a sophisticated malware able to evade detection and circumvent security systems. Its activity may lead to direct financial losses.

Whether you would like to research Arechclient2 in detail, or just check some suspicious link or file, use ANY.RUN’s Interactive Sandbox. It knows how to withstand VM-detection techniques and is integrated with Threat Intelligence Lookup to provide you with the data for proactive protection measures.

Sign up for a free ANY.RUN account to analyze cyber threats with no limit →

HAVE A LOOK AT

RondoDox screenshot
RondoDox
rondodox
RondoDox is an emerging Linux-based botnet malware that exploits dozens of known vulnerabilities in internet-facing devices like routers, DVRs, and web servers to build massive networks for DDoS attacks, cryptomining, and data exfiltration. First spotted in mid-2025, its "exploit shotgun" tactic (firing multiple payloads at once) has made it a rapid escalator in the IoT threat landscape, compromising unpatched edge devices worldwide.
Read More
Emmenhtal screenshot
Emmenhtal
emmenhtal
First identified in 2024, Emmenhtal operates by embedding itself within modified legitimate Windows binaries, often using HTA (HTML Application) files to execute malicious scripts. It has been linked to the distribution of malware such as CryptBot and Lumma Stealer. Emmenhtal is typically disseminated through phishing campaigns, including fake video downloads and deceptive email attachments.
Read More
Jigsaw screenshot
Jigsaw
jigsaw
The Jigsaw ransomware, initially detected in 2016, encrypts files on compromised systems and requires a ransom payment in Bitcoin. If the ransom is not paid, the malware starts deleting files, increasing the pressure on victims to comply. Its source code is publicly accessible, allowing various threat actors to customize and repurpose the malware for different objectives.
Read More
Havoc screenshot
Havoc
havoc
Havoc is an advanced post-exploitation framework used by hackers to take control of a system once they've breached it. With Havoc, attackers can run commands remotely, inject malicious processes, and access sensitive data. It's often used in targeted attacks, allowing cybercriminals to stay hidden in a network while stealing information or launching further attacks. Its flexibility and ability to bypass detection make it a serious threat, especially in environments that rely on traditional security tools.
Read More
CryptoWall screenshot
CryptoWall
cryptowall
CryptoWall is a notorious ransomware family that emerged in early 2014 and rapidly became one of the most destructive cyber threats of its time. This malware encrypts victims' files using strong AES encryption, demands ransom payments in Bitcoin, and has generated hundreds of millions of dollars for cybercriminals.
Read More
LockBit screenshot
LockBit
lockbit
LockBit, a ransomware variant, encrypts data on infected machines, demanding a ransom payment for decryption. Used in targeted attacks, It's a significant risk to organizations.
Read More