File name:

Arcana Loader.exe

Full analysis: https://app.any.run/tasks/597d4b39-bb00-4e09-9707-3c34955438f1
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: January 11, 2025, 21:25:49
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 7 sections
MD5:

6806F60AA4CFBF8A8354092550AF96F9

SHA1:

CB81A4302B65E2BAA397FE6870153B35AD220A57

SHA256:

4D42AE0E80197D050AD85C484F7E1EB2AB518E6798A72CA47AEF9731600BAB26

SSDEEP:

98304:+BW2JeJwSqJnWNOrAS1IbxuegpzOOps8TmltIC+AUhg+6cP64oJm/Y983ARbJlqV:gjQ8UGGNUkA0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the BIOS version

      • Arcana Loader.exe (PID: 3608)
    • Connects to unusual port

      • Arcana Loader.exe (PID: 3608)
    • Creates file in the systems drive root

      • Arcana Loader.exe (PID: 3608)
    • Process requests binary or script from the Internet

      • Arcana Loader.exe (PID: 3608)
    • Executes application which crashes

      • Arcana Loader.exe (PID: 3608)
  • INFO

    • Process checks whether UAC notifications are on

      • Arcana Loader.exe (PID: 3608)
    • Checks supported languages

      • Arcana Loader.exe (PID: 3608)
    • Reads the computer name

      • Arcana Loader.exe (PID: 3608)
    • Reads the machine GUID from the registry

      • Arcana Loader.exe (PID: 3608)
    • Disables trace logs

      • Arcana Loader.exe (PID: 3608)
    • Checks proxy server information

      • Arcana Loader.exe (PID: 3608)
      • WerFault.exe (PID: 3420)
    • Sends debugging messages

      • Arcana Loader.exe (PID: 3608)
    • Reads the software policy settings

      • WerFault.exe (PID: 3420)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 3420)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2074:06:18 19:21:42+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 3996672
InitializedDataSize: 246784
UninitializedDataSize: -
EntryPoint: 0x9ca058
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.1
ProductVersionNumber: 1.0.0.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Лучший лоудер читов майнкрафт
CompanyName: MGA Team's
FileDescription: Arcana Loader
FileVersion: 1.0.0.1
InternalName: Arcana Loader.exe
LegalCopyright: MGA Team's© 2024
LegalTrademarks: MGA
OriginalFileName: Arcana Loader.exe
ProductName: Arcana
ProductVersion: 1.0.0.1
AssemblyVersion: 1.0.0.1
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
126
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start arcana loader.exe werfault.exe arcana loader.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3420C:\WINDOWS\SysWOW64\WerFault.exe -u -p 3608 -s 1756C:\Windows\SysWOW64\WerFault.exe
Arcana Loader.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
3508"C:\Users\admin\Desktop\Arcana Loader.exe" C:\Users\admin\Desktop\Arcana Loader.exeexplorer.exe
User:
admin
Company:
MGA Team's
Integrity Level:
MEDIUM
Description:
Arcana Loader
Exit code:
3221226540
Version:
1.0.0.1
Modules
Images
c:\users\admin\desktop\arcana loader.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
3608"C:\Users\admin\Desktop\Arcana Loader.exe" C:\Users\admin\Desktop\Arcana Loader.exe
explorer.exe
User:
admin
Company:
MGA Team's
Integrity Level:
HIGH
Description:
Arcana Loader
Exit code:
2148734499
Version:
1.0.0.1
Modules
Images
c:\users\admin\desktop\arcana loader.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\mscoree.dll
Total events
3 481
Read events
3 458
Write events
20
Delete events
3

Modification events

(PID) Process:(3608) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3608) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(3608) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3608) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(3608) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(3608) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(3608) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(3608) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3608) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(3608) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
0
Suspicious files
5
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
3420WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Arcana Loader.ex_62b056f43d754a14fd98629f725695ead5978ad_133a4b22_236f9dac-bb56-4161-915b-4546a48d4c00\Report.wer
MD5:
SHA256:
3420WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\Arcana Loader.exe.3608.dmp
MD5:
SHA256:
3420WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\21253908F3CB05D51B1C2DA8B681A785der
MD5:F6F53CD09A41E968C363419B279D3112
SHA256:6D2BB01CC7A9BADE2113B219CAC1BDA86B2733196B7E1BD0C807CE1E396B1892
3420WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\21253908F3CB05D51B1C2DA8B681A785binary
MD5:2F811B3E90660054C6EDE24EBF1FADD8
SHA256:DAABEABCE40712DBC2AD4352F5100F98BB090394E938F3AAC155BC36638A91F2
3420WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER6CD6.tmp.dmpbinary
MD5:2F59C68E8AE1EC166752DD9A1D279BBB
SHA256:46AF79916A184CE9F610690E688355C214AEE7A218045A5BD8F78C704ECB9F56
3420WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FEbinary
MD5:BB52E654250234228C54C00DA0B169B7
SHA256:C948C9FACFFC01053FAF281824DA76671EF4EB814A1CAB5426D4082609892EE6
3420WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER6EFB.tmp.xmlxml
MD5:60921CAAA38A8C7C46098ECAB6C07873
SHA256:DE77D31C6CA30E058532E73BD4392847895CE939ECAF95288FD3364014AFA06A
3608Arcana Loader.exeC:\Active.txttext
MD5:CEAC57C52EC2D76A3CCDC3DF4DFDAB6F
SHA256:122F7176502656BE29238539A0AB2EC556D57FB4FE533EBC3BFEA292520A407D
3420WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37C951188967C8EB88D99893D9D191FEbinary
MD5:FA84E4BCC92AA5DB735AB50711040CDE
SHA256:6D7205E794FDE4219A62D9692ECDDF612663A5CF20399E79BE87B851FCA4CA33
3420WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER6ECB.tmp.WERInternalMetadata.xmlxml
MD5:B7CA15CFBD068EBDA55833B1C054E9B7
SHA256:65DEA3FAB40B3FBC64C1DA9CB378CACDFF83541F6474FDBB8F25648CEE360F88
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
18
DNS requests
6
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.10.249.17:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.10.249.17:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3608
Arcana Loader.exe
GET
200
138.124.117.2:8080
http://138.124.117.2:8080/CheatClients/Check.txt
unknown
unknown
3420
WerFault.exe
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3608
Arcana Loader.exe
GET
404
89.23.100.233:801
http://89.23.100.233:801/Imba.exe
unknown
unknown
3420
WerFault.exe
GET
200
23.10.249.17:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.37.237.227:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
23.10.249.17:80
crl.microsoft.com
Akamai International B.V.
CH
whitelisted
23.10.249.17:80
crl.microsoft.com
Akamai International B.V.
CH
whitelisted
4712
MoUsoCoreWorker.exe
23.37.237.227:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
23.37.237.227:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4712
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5448
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
3608
Arcana Loader.exe
138.124.117.2:8080
CH
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.10.249.17
whitelisted
google.com
  • 142.250.75.14
whitelisted
www.microsoft.com
  • 23.37.237.227
whitelisted
watson.events.data.microsoft.com
  • 20.42.73.29
whitelisted

Threats

PID
Process
Class
Message
3608
Arcana Loader.exe
Potentially Bad Traffic
ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile
3608
Arcana Loader.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
1 ETPRO signatures available at the full report
Process
Message
Arcana Loader.exe
CLR: Managed code called FailFast without specifying a reason.