Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Arechclient2

79
Global rank
158 infographic chevron month
Month rank
170 infographic chevron week
Week rank
0
IOCs

The Arechclient2 malware is a sophisticated .NET-based Remote Access Trojan (RAT) that collects sensitive information, such as browser credentials, from infected computers. It employs various stealth techniques, including Base64 encoding to obscure its code and the ability to pause activities to evade automated security tools. The malware also can adjust Windows Defender settings and uses code injection to manipulate legitimate processes.

RAT
Type
Unknown
Origin
1 November, 2019
First seen
17 August, 2026
Last seen
Also known as
SectopRAT

How to analyze Arechclient2 with ANY.RUN

RAT
Type
Unknown
Origin
1 November, 2019
First seen
17 August, 2026
Last seen

IOCs

IP addresses
23.59.18.102
188.114.97.3
104.21.37.38
192.178.183.138
48.209.138.168
150.171.28.10
104.21.81.37
20.190.160.64
23.194.190.156
104.21.18.241
2.16.204.143
2.21.239.135
23.52.181.141
172.217.112.4
135.232.92.137
172.217.117.4
142.251.13.94
142.251.127.84
150.171.27.11
150.171.109.34
Hashes
14f92b911f9fe774720461eec5bb4761ae6bfc9445c67e30bf624a8694b4b1da
a2ca52e34b6138624ac2dd20349cde28482143b837db40a7f0fbda023077c26a
f096bc366a931fba656bdcd77b24af15a5f29fc53281a727c79f82c608ecfab8
a0c9abae18599f0a65fc654ad36251f6330794bea66b718a09d8b297f3e38e87
41c91a9c93d76295746a149dce7ebb3b9ee2cb551d84365fff108e59a61cc304
fc525b684be2945a43ca04de402d74a1ea1901c48bf2eafe5fa814bfccfb4378
329b20f56d6438f20aef784d9bd7b686dd16550dc84967bb5be3dc0a1c29ce18
16ce95d9bc2ba6a7e62fb16f19208ffe3f73f81cf2993f86dc5d6fa88443a43f
6f0f4073a60a2497ef460238a6888a4e4534c59d97f412558e293d1c1ce42a60
474d668707f1cb929fef1e3798b71b632e50675bd1a9dceaab90c9587f72f680
498e3205bf85da0a8f8b57e292d4bd12b31d691e04039c04bedcde75d1ea7459
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
fb077c966296d02d50ccbf7f761d2a3311a206a784a7496f331c2b0d6ad205c8
eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
f7b24f2eb3d5eb0550527490395d2f61c3d2fe74bb9cb345197dad81b58b5fed
3615498fbef408a96bf30e01c318dac2d5451b054998119080e7faac5995f590
48d535bb330519c00d150578734c6cecb056c4b5cdd2a45c70590bc896d27d9f
fbcfe23a2ecb82b7100c50811691dde0a33aa3da8d176be9882a9db485dc0f2d
0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
Domains
ocsp.r2m01.amazontrust.com
accounts.google.com
r.msftstatic.com
fe3cr.delivery.mp.microsoft.com
copilot.microsoft.com
slscr.update.microsoft.com
ntp.msn.com
pop.betterplatform.cc
www.bing.com
client.wns.windows.com
c.pki.goog
edge.microsoft.com
crl.microsoft.com
www.microsoft.com
r.bing.com
clients2.google.com
otp.vagrancyvirus.cc
sb.scorecardresearch.com
ocsp.digicert.com
google.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://pop.betterplatform.cc/
https://pop.betterplatform.cc/cxd~9lj@jme_w
https://pop.betterplatform.cc/f7.dq_cd~e6i~u@_p_
http://clients2.google.com/time/1/current?cup2key=8:uxbjwfwpeqnnipo_oaj8tl1_yczjhp8qzej5p_8om9c&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&json=standard
Last Seen at
Last Seen at

Recent blog posts

post image
6 Months on Alert: Get H1 2026 Cyber Risk Rep...
watchers 438
comments 0
post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 5189
comments 0
post image
15 Minutes Saved Per Alert: How a Lean German...
watchers 10301
comments 0

What is Arechclient2 malware?

Arechclient2 is a .NET Remote Access Trojan (RAT) that was first observed in 2019. It is also widely known under the name SectopRAT. This malware is designed to steal sensitive data from browsers and cryptocurrency wallets, posing a significant threat to users' personal and financial information.

The distribution of Arechclient2 is typically carried out through malicious links, executable file uploads, and fake application updates. In some cases, it may be distributed as an LNK file or as an ISO file containing a malicious executable, making it difficult for users to detect and avoid infection.

Arechclient2 analyzed inside ANY.RUN sandbox Arechclient2 analyzed inside ANY.RUN sandbox

Analysis in ANY.RUN’s interactive malware sandbox shows that ArechClient2 makes considerable use of scripts and process injection to facilitate infection.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Arechclient2 malware technical details

Some of the primary capabilities of the Arechclient2 malware include:

  • Collection of sensitive information, including browser credentials.
  • Use of Base64 encoding for code obfuscation.
  • Temporary pausing of activities for evasion of automated security tools.
  • Adjustment of Windows Defender settings for detection evasion.
  • Employment of code injection for manipulation of legitimate processes.
  • Maintenance of persistence through script execution on startup.
  • Exchange of encrypted and plain text data with its command and control (C2) server.

Arechclient2 execution process

Let’s take a closer look at the stages of Arechclient2 infection by analyzing its sample inside ANY.RUN’s cloud sandbox for malware analysis.

Arechclient2 malicious process inside ANY.RUN sandbox ANY.RUN identifies malicious processes and lists all the actions performed by the malware

The process starts with the delivery of a malicious first-stage payload, which can vary between campaigns. It may be distributed as an LNK file or as an ISO file containing a malicious executable. These files are often spread through unknown initial attack vectors, likely involving social engineering or phishing tactics that trick users into executing them.

When the LNK file is double-clicked, it starts the system utility forfiles.exe to achieve indirect command execution by running PowerShell. An ISO file is mounted like a CD, and the executable may run automatically, initiating the infection process. Upon execution, the payload may extract files into a newly created directory within the victim’s temporary files. This extraction process also initiates multiple child processes crucial to the RAT’s functionality. The execution chain often uses AutoIT, further complicating detection efforts.

Arechclient2 Suricata analysis inside ANY.RUN sandbox ANY.RUN uses Suricata IDS to spot malicious network activities

The malware injects its payload into legitimate processes (e.g., InstallUtil.exe) using a function that facilitates injection while avoiding antivirus hooks by copying necessary files from system directories. This step is critical for maintaining stealth and ensuring continued control over the infected machine. Arechclient2 connects to its command and control (C2) server on port 15647 to receive commands. The communication includes encrypted data, which can switch to plaintext if encryption is disabled during interception. This allows attackers to issue commands remotely, manipulate settings, or extract sensitive information from the victim’s system.

Arechclient2 IOCs inside ANY.RUN sandbox After analysis in ANY.RUN, you can collect a detailed threat report and IOCs

The RAT can extensively profile victim systems, stealing sensitive information such as browser data and cryptocurrency wallet details. It can also launch hidden sessions to monitor user activity without detection.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Arechclient2 distribution methods

ArechClient2 uses various methods to trick users into clicking on harmful links that look legitimate.

Phishing techniques are employed to convince users to open files containing malicious content, which starts the infection process.

One common distribution method is to disguise the malware as updates for popular applications like Brave Browser, TOR, Signal, and Telegram.

By appearing as genuine updates, the malware takes advantage of users' trust in these applications to increase the chances of infection.

Gathering Threat Intelligence on Arechclient2 Malware

To obtain up-to-date intelligence on ArechClient2, utilize Threat Intelligence Lookup from ANY.RUN. This service grants access to a vast database containing Indicators of Compromise (IOCs), Indicators of Attack (IOAs), and Indicators of Behavior (IOBs) from millions of malware analysis sessions performed within the ANY.RUN sandbox. With over 40 customizable search parameters, users can retrieve data on threats, including IPs, domains, file names, and process artifacts associated with ArechClient2.

Arechclient2 results inside ANY.RUN's TI Lookup TI Lookup helps you enrich your investigations with additional threat context

For instance, to gather information on ArechClient2, you can search using its threat name or related artifacts. Inputting a query like threatName:"arechclient2" AND domainName:"" will produce a list of files, events, domain names, and other data extracted from malware samples, along with sandbox sessions that can be examined in detail to gain in-depth understanding of this malware’s behavior.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Arechclient2, also known as SectopRAT, is a sophisticated malware able to evade detection and circumvent security systems. Its activity may lead to direct financial losses.

Whether you would like to research Arechclient2 in detail, or just check some suspicious link or file, use ANY.RUN’s Interactive Sandbox. It knows how to withstand VM-detection techniques and is integrated with Threat Intelligence Lookup to provide you with the data for proactive protection measures.

Sign up for a free ANY.RUN account to analyze cyber threats with no limit →

HAVE A LOOK AT

AsyncRAT screenshot
AsyncRAT
asyncrat
AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.
Read More
HijackLoader screenshot
HijackLoader
hijackloader
HijackLoader is a modular malware acting as a vehicle for distributing different types of malicious software on compromised systems. It gained prominence during the summer of 2023 and has since been used in multiple attacks against organizations from various sectors, including hospitality businesses.
Read More
RondoDox screenshot
RondoDox
rondodox
RondoDox is an emerging Linux-based botnet malware that exploits dozens of known vulnerabilities in internet-facing devices like routers, DVRs, and web servers to build massive networks for DDoS attacks, cryptomining, and data exfiltration. First spotted in mid-2025, its "exploit shotgun" tactic (firing multiple payloads at once) has made it a rapid escalator in the IoT threat landscape, compromising unpatched edge devices worldwide.
Read More
WannaCry screenshot
WannaCry
wannacry ransomware
WannaCry is a famous Ransomware that utilizes the EternalBlue exploit. This malware is known for infecting at least 200,000 computers worldwide and it continues to be an active and dangerous threat.
Read More
Pulsar RAT screenshot
Pulsar RAT
pulsar
Pulsar RAT is a derivative of Quasar RAT with extensive functionality including keylogging, cryptocurrency wallet clipping, credential theft, file management, remote shell execution, and data exfiltration capabilities. As a modular, open-source remote administration tool designed for Windows systems, Pulsar introduces significant enhancements over its predecessor.
Read More
Socelars screenshot
Socelars
socelars
Socelars is an information-stealing Trojan (often categorized as spyware/stealer) that focuses on collecting sensitive data from Windows systems, with standout reporting around Facebook Ads Manager and session cookie theft. Unlike “noisy” malware that immediately breaks something, Socelars quietly converts a single infected machine into access: logged-in sessions, business account data, and pathways to monetization.
Read More