| URL: | https://extrack.net/dl/ |
| Full analysis: | https://app.any.run/tasks/b7578eb6-8b79-48e4-b4ba-d45c81a6b676 |
| Verdict: | Malicious activity |
| Threats: | The Arechclient2 malware is a sophisticated .NET-based Remote Access Trojan (RAT) that collects sensitive information, such as browser credentials, from infected computers. It employs various stealth techniques, including Base64 encoding to obscure its code and the ability to pause activities to evade automated security tools. The malware also can adjust Windows Defender settings and uses code injection to manipulate legitimate processes. |
| Analysis date: | February 03, 2025, 18:43:03 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MD5: | 9223891A72E2A3F537EC8C9409801422 |
| SHA1: | 2A9EDBBB7A57695B723AF7C88219565CF686BAD8 |
| SHA256: | 50D00EF3FD790983E9E4A66B108B4093C08743AFA1A023064E1FE138BA3C1BDB |
| SSDEEP: | 3:N891oaJK:2W |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 68 | tasklist /FI "IMAGENAME eq sophoshealth.exe" /FO CSV /NH | C:\Windows\SysWOW64\tasklist.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Lists the current running tasks Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 372 | "cmd.exe" /C tasklist /FI "IMAGENAME eq avastui.exe" /FO CSV /NH | find /I "avastui.exe" | C:\Windows\SysWOW64\cmd.exe | — | O27AXWJHCQ7YCX8F4.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 536 | "C:\Users\admin\AppData\Local\Temp\SN9RZEZSKIAU0JE8MZTD7CSRBDB464.exe" | C:\Users\admin\AppData\Local\Temp\SN9RZEZSKIAU0JE8MZTD7CSRBDB464.exe | Setup.exe | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Mingler Assistant Setup Exit code: 1 Version: 1.2.4.0 Modules
| |||||||||||||||
| 768 | "cmd.exe" /C tasklist /FI "IMAGENAME eq avastui.exe" /FO CSV /NH | find /I "avastui.exe" | C:\Windows\SysWOW64\cmd.exe | — | SN9RZEZSKIAU0JE8MZTD7CSRBDB464.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1144 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=1488 --field-trial-handle=2276,i,9369075442105528451,757861143859191676,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1144 | tasklist /FI "IMAGENAME eq wrsa.exe" /FO CSV /NH | C:\Windows\SysWOW64\tasklist.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Lists the current running tasks Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1200 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=33 --mojo-platform-channel-handle=7376 --field-trial-handle=2460,i,5387920300707705051,7325055155373551998,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1220 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5444 --field-trial-handle=2276,i,9369075442105528451,757861143859191676,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1348 | "cmd.exe" /C tasklist /FI "IMAGENAME eq avgui.exe" /FO CSV /NH | find /I "avgui.exe" | C:\Windows\SysWOW64\cmd.exe | — | SN9RZEZSKIAU0JE8MZTD7CSRBDB464.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1596 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5380 --field-trial-handle=2276,i,9369075442105528451,757861143859191676,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| (PID) Process: | (6280) iexplore.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (6280) iexplore.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (6280) iexplore.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (6280) iexplore.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (6280) iexplore.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones |
| Operation: | write | Name: | SecuritySafe |
Value: 1 | |||
| (PID) Process: | (6280) iexplore.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | DisableFirstRunCustomize |
Value: 1 | |||
| (PID) Process: | (6604) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328464 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {9ABC1BA9-C6E5-4924-875A-EEC95D729803} | |||
| (PID) Process: | (6604) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328464 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {91C5B0AE-EF91-442A-B50B-2801C6917E68} | |||
| (PID) Process: | (6604) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\328464 |
| Operation: | write | Name: | WindowTabManagerFileMappingId |
Value: {DC04D2FA-A743-4C75-AF93-ADFE0A89F527} | |||
| (PID) Process: | (6604) msedge.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6604 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF139d2d.TMP | — | |
MD5:— | SHA256:— | |||
| 6604 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6604 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF139d2d.TMP | — | |
MD5:— | SHA256:— | |||
| 6604 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6604 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old~RF139d3d.TMP | — | |
MD5:— | SHA256:— | |||
| 6604 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\discounts_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6604 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF139d3d.TMP | — | |
MD5:— | SHA256:— | |||
| 6604 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF139d3d.TMP | — | |
MD5:— | SHA256:— | |||
| 6604 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 6604 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
7468 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
7468 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
6880 | msedge.exe | GET | 304 | 23.192.153.142:80 | http://x1.i.lencr.org/ | unknown | — | — | unknown |
1176 | svchost.exe | GET | 200 | 104.75.232.13:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6880 | msedge.exe | GET | 304 | 23.192.153.142:80 | http://r3.i.lencr.org/ | unknown | — | — | unknown |
7156 | svchost.exe | HEAD | 200 | 199.232.214.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/b53afe04-3e1c-4ebd-ab0e-f6aaa606637e?P1=1739203881&P2=404&P3=2&P4=FQcU3D6fY6HpOhDrRtTGMiH9tbk6ZgCUu%2b7Xg%2fl9pCTLgmnzGhBgVdUSel6iFb214ln3LVX1yl262vHa6ewN3g%3d%3d | unknown | — | — | whitelisted |
7156 | svchost.exe | GET | 206 | 199.232.214.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/b53afe04-3e1c-4ebd-ab0e-f6aaa606637e?P1=1739203881&P2=404&P3=2&P4=FQcU3D6fY6HpOhDrRtTGMiH9tbk6ZgCUu%2b7Xg%2fl9pCTLgmnzGhBgVdUSel6iFb214ln3LVX1yl262vHa6ewN3g%3d%3d | unknown | — | — | whitelisted |
7156 | svchost.exe | GET | 206 | 199.232.214.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/b53afe04-3e1c-4ebd-ab0e-f6aaa606637e?P1=1739203881&P2=404&P3=2&P4=FQcU3D6fY6HpOhDrRtTGMiH9tbk6ZgCUu%2b7Xg%2fl9pCTLgmnzGhBgVdUSel6iFb214ln3LVX1yl262vHa6ewN3g%3d%3d | unknown | — | — | whitelisted |
6528 | backgroundTaskHost.exe | GET | 200 | 104.75.232.13:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
7156 | svchost.exe | GET | 206 | 199.232.214.172:80 | http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/b53afe04-3e1c-4ebd-ab0e-f6aaa606637e?P1=1739203881&P2=404&P3=2&P4=FQcU3D6fY6HpOhDrRtTGMiH9tbk6ZgCUu%2b7Xg%2fl9pCTLgmnzGhBgVdUSel6iFb214ln3LVX1yl262vHa6ewN3g%3d%3d | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5064 | SearchApp.exe | 104.126.37.160:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
1076 | svchost.exe | 23.213.166.81:443 | go.microsoft.com | AKAMAI-AS | DE | whitelisted |
6880 | msedge.exe | 13.107.21.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6880 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6880 | msedge.exe | 185.216.143.121:443 | extrack.net | FiberXpress BV | GB | unknown |
6880 | msedge.exe | 13.107.246.45:443 | edge-mobile-static.azureedge.net | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6880 | msedge.exe | 13.107.6.158:443 | business.bing.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
extrack.net |
| unknown |
www.bing.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
edge-mobile-static.azureedge.net |
| whitelisted |
business.bing.com |
| whitelisted |
bzib.nelreports.net |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
stats.wp.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6880 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
6880 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
6880 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
6880 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
6880 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
6880 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
6880 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
6880 | msedge.exe | Generic Protocol Command Decode | SURICATA QUIC failed decrypt |
6880 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
6880 | msedge.exe | Not Suspicious Traffic | INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code .jquery .com) |