File name:

Arcana Loader.exe

Full analysis: https://app.any.run/tasks/d59315c4-c665-4e86-bd76-20217d9b4e81
Verdict: Malicious activity
Analysis date: January 11, 2025, 18:40:25
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
themida
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 7 sections
MD5:

6806F60AA4CFBF8A8354092550AF96F9

SHA1:

CB81A4302B65E2BAA397FE6870153B35AD220A57

SHA256:

4D42AE0E80197D050AD85C484F7E1EB2AB518E6798A72CA47AEF9731600BAB26

SSDEEP:

98304:+BW2JeJwSqJnWNOrAS1IbxuegpzOOps8TmltIC+AUhg+6cP64oJm/Y983ARbJlqV:gjQ8UGGNUkA0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the BIOS version

      • Arcana Loader.exe (PID: 6404)
    • Creates file in the systems drive root

      • Arcana Loader.exe (PID: 6404)
    • Potential Corporate Privacy Violation

      • Arcana Loader.exe (PID: 6404)
    • Executes application which crashes

      • Arcana Loader.exe (PID: 6404)
    • Connects to unusual port

      • Arcana Loader.exe (PID: 6404)
  • INFO

    • Process checks whether UAC notifications are on

      • Arcana Loader.exe (PID: 6404)
    • Checks supported languages

      • Arcana Loader.exe (PID: 6404)
    • Reads the machine GUID from the registry

      • Arcana Loader.exe (PID: 6404)
    • Reads the computer name

      • Arcana Loader.exe (PID: 6404)
    • Disables trace logs

      • Arcana Loader.exe (PID: 6404)
    • Sends debugging messages

      • Arcana Loader.exe (PID: 6404)
    • Checks proxy server information

      • Arcana Loader.exe (PID: 6404)
      • WerFault.exe (PID: 6856)
    • Themida protector has been detected

      • Arcana Loader.exe (PID: 6404)
    • Reads the software policy settings

      • WerFault.exe (PID: 6856)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 6856)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2074:06:18 19:21:42+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 3996672
InitializedDataSize: 246784
UninitializedDataSize: -
EntryPoint: 0x9ca058
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.1
ProductVersionNumber: 1.0.0.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Лучший лоудер читов майнкрафт
CompanyName: MGA Team's
FileDescription: Arcana Loader
FileVersion: 1.0.0.1
InternalName: Arcana Loader.exe
LegalCopyright: MGA Team's© 2024
LegalTrademarks: MGA
OriginalFileName: Arcana Loader.exe
ProductName: Arcana
ProductVersion: 1.0.0.1
AssemblyVersion: 1.0.0.1
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
132
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start arcana loader.exe werfault.exe arcana loader.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6208"C:\Users\admin\AppData\Local\Temp\Arcana Loader.exe" C:\Users\admin\AppData\Local\Temp\Arcana Loader.exeexplorer.exe
User:
admin
Company:
MGA Team's
Integrity Level:
MEDIUM
Description:
Arcana Loader
Exit code:
3221226540
Version:
1.0.0.1
Modules
Images
c:\users\admin\appdata\local\temp\arcana loader.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6404"C:\Users\admin\AppData\Local\Temp\Arcana Loader.exe" C:\Users\admin\AppData\Local\Temp\Arcana Loader.exe
explorer.exe
User:
admin
Company:
MGA Team's
Integrity Level:
HIGH
Description:
Arcana Loader
Exit code:
2148734499
Version:
1.0.0.1
Modules
Images
c:\users\admin\appdata\local\temp\arcana loader.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\mscoree.dll
6856C:\WINDOWS\SysWOW64\WerFault.exe -u -p 6404 -s 1740C:\Windows\SysWOW64\WerFault.exe
Arcana Loader.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
Total events
3 481
Read events
3 458
Write events
20
Delete events
3

Modification events

(PID) Process:(6404) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6404) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6404) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6404) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6404) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(6404) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(6404) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(6404) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6404) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6404) Arcana Loader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\Arcana Loader_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
0
Suspicious files
6
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
6856WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Arcana Loader.ex_62b056f43d754a14fd98629f725695ead5978ad_133a4b22_5c7318e8-fef1-4b85-9164-9ccf9b0d9fd9\Report.wer
MD5:
SHA256:
6856WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\Arcana Loader.exe.6404.dmp
MD5:
SHA256:
6856WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER789F.tmp.WERInternalMetadata.xmlxml
MD5:8C48E762EA519A7A87FBA094B231EE5F
SHA256:615E1CE149DE30E330954783C4C4A5E05F3B0629951D141BCCBD1DC742F62B74
6856WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER764C.tmp.dmpbinary
MD5:115B632152830F36DD7F13C79F1C3035
SHA256:F06A4A195C01FEF86BA5BAC34EE46CD73D2234F9BBBC56A90FBB91E19044A566
6856WerFault.exeC:\Windows\appcompat\Programs\Amcache.hvebinary
MD5:F548E0FCD4BDEB810A8ABE5DABD26A83
SHA256:C864E65EF5140F45C6AFBB7719FB254B5A7A6F905F066DDA5D72E8C86A7349EA
6856WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER78CF.tmp.xmlxml
MD5:39A0CC8DF8288138CAB1C2D055B50E29
SHA256:B49C209D75A7B34D8B42DCB083D65EC4C89F38E56A1A58A0286FAD495256B042
6856WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\21253908F3CB05D51B1C2DA8B681A785binary
MD5:A168820A7E172D3B697956BE65394448
SHA256:AE58B816A4FA08309538A71A05BD62D9C91A825E1D0DC92B424D16089150C315
6856WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FEbinary
MD5:2D30E2541665EDBF7A68D30354672741
SHA256:ACE3F8894FF4999869B8A5E593FC8DC5AC2BB3C9022D5F98C51DDC3CE2DD9A7B
6856WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37C951188967C8EB88D99893D9D191FEder
MD5:FA84E4BCC92AA5DB735AB50711040CDE
SHA256:6D7205E794FDE4219A62D9692ECDDF612663A5CF20399E79BE87B851FCA4CA33
6856WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\21253908F3CB05D51B1C2DA8B681A785der
MD5:F6F53CD09A41E968C363419B279D3112
SHA256:6D2BB01CC7A9BADE2113B219CAC1BDA86B2733196B7E1BD0C807CE1E396B1892
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
38
DNS requests
19
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.147:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6404
Arcana Loader.exe
GET
89.23.100.233:801
http://89.23.100.233:801/Imba.exe
unknown
unknown
6404
Arcana Loader.exe
GET
200
138.124.117.2:8080
http://138.124.117.2:8080/CheatClients/Check.txt
unknown
unknown
6856
WerFault.exe
GET
200
23.48.23.194:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6856
WerFault.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3832
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7160
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5496
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
104.126.37.130:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
23.48.23.147:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
20.190.159.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
www.bing.com
  • 104.126.37.130
  • 104.126.37.131
  • 104.126.37.136
  • 104.126.37.153
  • 104.126.37.144
  • 104.126.37.185
  • 104.126.37.123
  • 104.126.37.154
  • 104.126.37.155
whitelisted
google.com
  • 142.250.185.238
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
crl.microsoft.com
  • 23.48.23.147
  • 23.48.23.194
  • 23.48.23.180
  • 23.48.23.156
  • 23.48.23.145
  • 23.48.23.164
  • 23.48.23.176
  • 23.48.23.167
  • 23.48.23.193
  • 23.48.23.173
  • 23.48.23.141
  • 23.48.23.169
  • 23.48.23.177
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
login.live.com
  • 20.190.159.71
  • 40.126.31.67
  • 20.190.159.64
  • 20.190.159.2
  • 20.190.159.75
  • 20.190.159.23
  • 40.126.31.69
  • 40.126.31.73
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
watson.events.data.microsoft.com
  • 20.189.173.20
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted

Threats

PID
Process
Class
Message
6404
Arcana Loader.exe
Potentially Bad Traffic
ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile
6404
Arcana Loader.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
6404
Arcana Loader.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
6404
Arcana Loader.exe
Potentially Bad Traffic
ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response
6404
Arcana Loader.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
1 ETPRO signatures available at the full report
Process
Message
Arcana Loader.exe
CLR: Managed code called FailFast without specifying a reason.