| File name: | Christmas Tree.exe |
| Full analysis: | https://app.any.run/tasks/9deb1588-2acb-4371-9a12-55a0855e3875 |
| Verdict: | Malicious activity |
| Threats: | The Arechclient2 malware is a sophisticated .NET-based Remote Access Trojan (RAT) that collects sensitive information, such as browser credentials, from infected computers. It employs various stealth techniques, including Base64 encoding to obscure its code and the ability to pause activities to evade automated security tools. The malware also can adjust Windows Defender settings and uses code injection to manipulate legitimate processes. |
| Analysis date: | April 19, 2025, 00:49:00 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections |
| MD5: | A239A27C2169AF388D4F5BE6B52F272C |
| SHA1: | 0FEB9A0CD8C25F01D071E9B2CFC2AE7BD430318C |
| SHA256: | 98E895F711226A32BFAB152E224279D859799243845C46E550C2D32153C619FC |
| SSDEEP: | 48:YqYHO2f7Frk70zDJZZJOfTHH/rPmckulbfSqXSfbNtm:27Jlm/6ypf6zNt |
| .exe | | | Generic CIL Executable (.NET, Mono, etc.) (82.9) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (7.4) |
| .exe | | | Win32 Executable (generic) (5.1) |
| .exe | | | Generic Win/DOS Executable (2.2) |
| .exe | | | DOS Executable Generic (2.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:09:30 16:32:57+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 11 |
| CodeSize: | 2048 |
| InitializedDataSize: | 2048 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x268e |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows command line |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| FileDescription: | |
| FileVersion: | 0.0.0.0 |
| InternalName: | New Text Document.exe |
| LegalCopyright: | |
| OriginalFileName: | New Text Document.exe |
| ProductVersion: | 0.0.0.0 |
| AssemblyVersion: | 0.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 516 | C:\WINDOWS\System32\schtasks.exe /create /f /ru "System" /tn "GoogleUpdateTaskMachineQC" /xml "C:\Users\ADMINI~1\AppData\Local\Temp\flaevwjwirpw.xml" | C:\Windows\System32\schtasks.exe | explorer.exe | ||||||||||||
User: Administrator Company: Microsoft Corporation Integrity Level: HIGH Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 668 | "C:\Windows\System32\a\Quas13k.exe" | C:\Windows\System32\a\Quas13k.exe | Christmas Tree.exe | ||||||||||||
User: Administrator Integrity Level: HIGH Description: Quasar Client Exit code: 3 Version: 1.4.1 Modules
| |||||||||||||||
| 732 | "C:\Windows\System32\a\hkcmd.exe" | C:\Windows\System32\a\hkcmd.exe | Christmas Tree.exe | ||||||||||||
User: Administrator Integrity Level: HIGH Exit code: 3221225477 Modules
| |||||||||||||||
| 872 | "schtasks" /create /tn "MicrosoftQuasUpdate" /sc ONLOGON /tr "C:\WINDOWS\system32\explorer\explorer.exe" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | Quas13k.exe | |||||||||||
User: Administrator Company: Microsoft Corporation Integrity Level: HIGH Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 924 | "C:\Windows\System32\a\CZXCVTD.exe" | C:\Windows\System32\a\CZXCVTD.exe | — | Christmas Tree.exe | |||||||||||
User: Administrator Integrity Level: HIGH Description: CZXCVTD Exit code: 2148734720 Version: 1.0.0.0 Modules
| |||||||||||||||
| 1004 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass Add-MpPreference -ExclusionPath 'C:\Windows\System32\a\XClient.exe' | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | XClient.exe | |||||||||||
User: Administrator Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1004 | powercfg /x -hibernate-timeout-dc 0 | C:\Windows\System32\powercfg.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Power Settings Command-Line Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1096 | "C:\Windows\System32\a\s.exe" | C:\Windows\System32\a\s.exe | Christmas Tree.exe | ||||||||||||
User: Administrator Integrity Level: HIGH Description: Version: 1.0.0.0 Modules
| |||||||||||||||
| 1188 | "C:\Users\admin\Desktop\Guard-Endpoint\HeimdallGuard.exe" | C:\Users\admin\Desktop\Guard-Endpoint\HeimdallGuard.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: HeimdallGuard Exit code: 3221225786 Version: 1.0.0.0 Modules
| |||||||||||||||
| 1328 | "C:\Windows\System32\a\S123.exe" | C:\Windows\System32\a\S123.exe | Christmas Tree.exe | ||||||||||||
User: Administrator Integrity Level: HIGH Description: Quasar Client Version: 1.4.1 Modules
Quasar(PID) Process(1328) S123.exe Version1.4.1 C2 (2)118.195.162.44:443 Sub_DirSubDir Install_NameClient.exe Mutex68d5e2b3-4339-4659-a181-0c8f9f98a553 StartupQuasar Client Startup Tagtest2 LogDirLogs SignatureItx+iqkvtAHU0ddWUZIBXYd/SsF44lLiuVg1y9tF8zG+oaV0ZDHZcgLmFdV/L0i3nytWBcfDlhsfvA49gHjtjane29uAbGgiSgWwJ08RoiSbs0Bb8AAPrJsSZPa5R+ru0D/B5MDH83s0wasVTOLhYqpZIhB5jIgxoWa6Rg/D6NpggEQB7ZiV44BLR686HNCq+HcTovLPnmdmndhogjg+Gn3KSlvctkBAB3k4R8Z9K26W9QfxgHMomQvI7VVIWQzvcndtrUEtKoKB3xht5B0/e0u4PvRrYkEW6wTgcbhQOIEB... CertificateMIIE9DCCAtygAwIBAgIQAJ3N+Lg26iiv+teE8eSluTANBgkqhkiG9w0BAQ0FADAbMRkwFwYDVQQDDBBRdWFzYXIgU2VydmVyIENBMCAXDTI1MDQxNjA5NDIwOFoYDzk5OTkxMjMxMjM1OTU5WjAbMRkwFwYDVQQDDBBRdWFzYXIgU2VydmVyIENBMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAlKRXqa4ec5vGBeQC55RFDLVLGjIX7bzKxlR1/NiZ088j9UE85fqpmuewJsRJwH40vpDJ6VqG... | |||||||||||||||
| (PID) Process: | (5544) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (5544) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (5544) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (5544) WinRAR.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (2772) HeimdallGuard.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HeimdallGuard_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (2772) HeimdallGuard.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HeimdallGuard_RASAPI32 |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (2772) HeimdallGuard.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HeimdallGuard_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (2772) HeimdallGuard.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HeimdallGuard_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (2772) HeimdallGuard.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HeimdallGuard_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (2772) HeimdallGuard.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\HeimdallGuard_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6324 | Christmas Tree.exe | C:\Windows\System32\a\FoxmailSetup_7.2.25.375.exe | — | |
MD5:— | SHA256:— | |||
| 2772 | HeimdallGuard.exe | C:\Users\admin\Desktop\Guard-Endpoint\debug.log | text | |
MD5:A06BAA8FDA73BA75BEAAEAADCCA01243 | SHA256:5BA8B66C73F9F6CC5522D5CEF5BCBF6A1C0C549D2EACFC348D3F0E256F3A0369 | |||
| 5544 | WinRAR.exe | C:\Users\admin\Desktop\Guard-Endpoint\Newtonsoft.Json.dll | executable | |
MD5:195FFB7167DB3219B217C4FD439EEDD6 | SHA256:E1E27AF7B07EEEDF5CE71A9255F0422816A6FC5849A483C6714E1B472044FA9D | |||
| 5544 | WinRAR.exe | C:\Users\admin\Desktop\Guard-Endpoint\HeimdallGuard.exe | executable | |
MD5:EB82D42A6C6CE9794AEB165FE857C7CF | SHA256:A9FD7CAC0FF0B2FE0C4DCA174049DF06C0CC697770365CFE4507EF0453F8B220 | |||
| 6324 | Christmas Tree.exe | C:\Windows\System32\a\CZXCVTD.exe | executable | |
MD5:F1FB7323684401E2A5E3E5BAE1E97B72 | SHA256:22B68E443FCBDEB3CB7810A1EEEBFC876B7D3BE1ADB7DBCD8217E953EA5B36CC | |||
| 6324 | Christmas Tree.exe | C:\Windows\System32\a\S123.exe | executable | |
MD5:233A781D28BD3B3A86178C48AF135297 | SHA256:8C4EDF15B2E0BFAAF67D12A3E17E0D6D314EA1DF16965C8C1D7D2B83F3BC1C36 | |||
| 6324 | Christmas Tree.exe | C:\Windows\System32\a\CONVERTER.exe | executable | |
MD5:E856AE17BD77A4AC8FFE5291BA02C4A1 | SHA256:4202DDD7AF049132F98A9A28DF3B6B1B34567B78E1DCE8B5D380C8974D697199 | |||
| 6324 | Christmas Tree.exe | C:\Windows\System32\a\Quas13k.exe | executable | |
MD5:283557E6108671AF76718BF8BDC84508 | SHA256:8FD804D664127A9FE36DAE01487103DEAA045859A0D8C4D801DD476CCBC238E3 | |||
| 6324 | Christmas Tree.exe | C:\Windows\System32\a\snd16061.exe | executable | |
MD5:E24D2CDF95E080F2B6A1DB32352D8A3C | SHA256:D2F9DC8E7278A2EC0AA634536AC8D23DB209ABA8CA0E109CE80469C27517AB33 | |||
| 6324 | Christmas Tree.exe | C:\Windows\System32\a\brbotnet.exe | executable | |
MD5:4C753F7A2AF14B8DC43F2D169EA61752 | SHA256:A951BB26B99601F732F9333D11DFA5028E78D90EF80287DC7E82A2C37DE61993 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6324 | Christmas Tree.exe | GET | 200 | 45.136.15.39:80 | http://45.136.15.39/02.08.2022.exe | unknown | — | — | malicious |
6324 | Christmas Tree.exe | GET | 301 | 140.82.121.3:80 | http://github.com/nkminash/my-codd/raw/896d806a9b4569c9c3a275f200ebe7d2ecec5702/snd16061.exe | unknown | — | — | whitelisted |
6324 | Christmas Tree.exe | GET | — | 196.251.71.139:80 | http://196.251.71.139/vnc/nvnc.exe | unknown | — | — | unknown |
6324 | Christmas Tree.exe | GET | 200 | 176.65.134.79:80 | http://176.65.134.79/hosting/CONVERTER.exe | unknown | — | — | malicious |
6324 | Christmas Tree.exe | GET | 200 | 192.3.26.143:80 | http://192.3.26.143/460/csrss.exe | unknown | — | — | unknown |
6324 | Christmas Tree.exe | GET | 301 | 140.82.121.3:80 | http://github.com/naruto3213213/111/raw/refs/heads/main/Host.exe | unknown | — | — | whitelisted |
6324 | Christmas Tree.exe | GET | 200 | 192.3.26.143:80 | http://192.3.26.143/440/hkcmd.exe | unknown | — | — | unknown |
6324 | Christmas Tree.exe | GET | 301 | 140.82.121.3:80 | http://github.com/cybr543809/lua/releases/download/SD/ULauncher.exe | unknown | — | — | whitelisted |
4628 | XClient.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/line/?fields=hosting | unknown | — | — | whitelisted |
1096 | s.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/line/?fields=hosting | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 23.216.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3216 | svchost.exe | 172.211.123.249:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6544 | svchost.exe | 40.126.32.68:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
2104 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2772 | HeimdallGuard.exe | 172.67.194.159:443 | countervector.pro | CLOUDFLARENET | US | unknown |
6488 | SIHClient.exe | 4.175.87.197:443 | slscr.update.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
countervector.pro |
| unknown |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6324 | Christmas Tree.exe | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |
6324 | Christmas Tree.exe | Potential Corporate Privacy Violation | ET INFO PE EXE or DLL Windows file download HTTP |
6324 | Christmas Tree.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
6324 | Christmas Tree.exe | Potentially Bad Traffic | ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response |
6324 | Christmas Tree.exe | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |
6324 | Christmas Tree.exe | Potential Corporate Privacy Violation | ET INFO PE EXE or DLL Windows file download HTTP |
6324 | Christmas Tree.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
6324 | Christmas Tree.exe | Potentially Bad Traffic | ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response |
1328 | S123.exe | Domain Observed Used for C2 Detected | ET MALWARE Generic AsyncRAT/zgRAT Style SSL Cert |
1328 | S123.exe | Domain Observed Used for C2 Detected | ET MALWARE Observed Malicious SSL Cert (Quasar CnC) |