File name:

Arcana Loader.exe

Full analysis: https://app.any.run/tasks/b45b3f10-d0fe-40b8-a222-1e3cb05b39a0
Verdict: Malicious activity
Analysis date: January 11, 2025, 21:25:11
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 7 sections
MD5:

6806F60AA4CFBF8A8354092550AF96F9

SHA1:

CB81A4302B65E2BAA397FE6870153B35AD220A57

SHA256:

4D42AE0E80197D050AD85C484F7E1EB2AB518E6798A72CA47AEF9731600BAB26

SSDEEP:

98304:+BW2JeJwSqJnWNOrAS1IbxuegpzOOps8TmltIC+AUhg+6cP64oJm/Y983ARbJlqV:gjQ8UGGNUkA0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Creates file in the systems drive root

      • Arcana Loader.exe (PID: 4640)
    • Reads the BIOS version

      • Arcana Loader.exe (PID: 4640)
    • Executes application which crashes

      • Arcana Loader.exe (PID: 4640)
    • Reads security settings of Internet Explorer

      • ShellExperienceHost.exe (PID: 3848)
  • INFO

    • Process checks whether UAC notifications are on

      • Arcana Loader.exe (PID: 4640)
    • Checks supported languages

      • Arcana Loader.exe (PID: 4640)
      • ShellExperienceHost.exe (PID: 3848)
    • Disables trace logs

      • Arcana Loader.exe (PID: 4640)
    • Checks proxy server information

      • WerFault.exe (PID: 3416)
      • Arcana Loader.exe (PID: 4640)
    • Reads the computer name

      • Arcana Loader.exe (PID: 4640)
      • ShellExperienceHost.exe (PID: 3848)
    • Sends debugging messages

      • Arcana Loader.exe (PID: 4640)
    • Reads the machine GUID from the registry

      • Arcana Loader.exe (PID: 4640)
    • Reads the software policy settings

      • WerFault.exe (PID: 3416)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 3416)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2074:06:18 19:21:42+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 3996672
InitializedDataSize: 246784
UninitializedDataSize: -
EntryPoint: 0x9ca058
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.1
ProductVersionNumber: 1.0.0.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Лучший лоудер читов майнкрафт
CompanyName: MGA Team's
FileDescription: Arcana Loader
FileVersion: 1.0.0.1
InternalName: Arcana Loader.exe
LegalCopyright: MGA Team's© 2024
LegalTrademarks: MGA
OriginalFileName: Arcana Loader.exe
ProductName: Arcana
ProductVersion: 1.0.0.1
AssemblyVersion: 1.0.0.1
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
120
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start arcana loader.exe werfault.exe shellexperiencehost.exe no specs arcana loader.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2612"C:\Users\admin\Desktop\Arcana Loader.exe" C:\Users\admin\Desktop\Arcana Loader.exeexplorer.exe
User:
admin
Company:
MGA Team's
Integrity Level:
MEDIUM
Description:
Arcana Loader
Exit code:
3221226540
Version:
1.0.0.1
Modules
Images
c:\users\admin\desktop\arcana loader.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
3416C:\WINDOWS\SysWOW64\WerFault.exe -u -p 4640 -s 1760C:\Windows\SysWOW64\WerFault.exe
Arcana Loader.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
3848"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mcaC:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Shell Experience Host
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\systemapps\shellexperiencehost_cw5n1h2txyewy\shellexperiencehost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\wincorlib.dll
4640"C:\Users\admin\Desktop\Arcana Loader.exe" C:\Users\admin\Desktop\Arcana Loader.exe
explorer.exe
User:
admin
Company:
MGA Team's
Integrity Level:
HIGH
Description:
Arcana Loader
Exit code:
2148734499
Version:
1.0.0.1
Modules
Images
c:\users\admin\desktop\arcana loader.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\mscoree.dll
Total events
7 489
Read events
7 466
Write events
20
Delete events
3

Modification events

(PID) Process:(4640) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(4640) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(4640) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(4640) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(4640) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(4640) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(4640) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(4640) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(4640) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(4640) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
0
Suspicious files
2
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
3416WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Arcana Loader.ex_62b056f43d754a14fd98629f725695ead5978ad_133a4b22_f90e2760-594f-428c-86bf-5530f1c2236c\Report.wer
MD5:
SHA256:
3416WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\Arcana Loader.exe.4640.dmp
MD5:
SHA256:
3416WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER62C4.tmp.dmpbinary
MD5:16521A21DCA0B040972E7CA66CDD3AD3
SHA256:E4E54DC98FA1E8B77EC87FF4CD9B0E3FF7526F305E6D51C6DD3E944DC699C5B4
4640Arcana Loader.exeC:\Active.txttext
MD5:CEAC57C52EC2D76A3CCDC3DF4DFDAB6F
SHA256:122F7176502656BE29238539A0AB2EC556D57FB4FE533EBC3BFEA292520A407D
3416WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER63FF.tmp.xmlxml
MD5:7ADA033B8F2FC5B9869D337D8D51835B
SHA256:9644FE238A1D167BCE6C2EC72D36DE251EFAAE3C032D8F8A66BF47E91C2F782C
3416WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER63DF.tmp.WERInternalMetadata.xmlxml
MD5:5D137E9F1151377F5915B6C82F01CCFF
SHA256:2DFCDD454919675D8ACEAF37EFB26A55BC27FFE57CCED10E3F13A14744F2EE10
3416WerFault.exeC:\Windows\appcompat\Programs\Amcache.hvebinary
MD5:C9CDA705827538B6645D6EBC60E86F6F
SHA256:7546794132C30DC3E1B15461A2EA241BAB416C08A85CDE0460ABE10EBD26E785
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
26
DNS requests
8
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
132
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4640
Arcana Loader.exe
138.124.117.2:8080
CH
unknown
3416
WerFault.exe
20.42.73.29:443
watson.events.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
www.bing.com
whitelisted
google.com
  • 142.250.186.46
whitelisted
watson.events.data.microsoft.com
  • 20.42.73.29
whitelisted

Threats

No threats detected
Process
Message
Arcana Loader.exe
CLR: Managed code called FailFast without specifying a reason.