s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

OTX-6ab688467ce23517fb31e378 info

📛 Threat Title

Uncovering a SectopRAT Variant Embedded in Legitimate Software

Category: sectoprat Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

SectopRAT (also known as ArechClient2) is a .NET-based remote access trojan (RAT) that provides a range of functions through multiple control commands. These include collecting sensitive data from the victim’s device, capturing screens, remotely managing processes and files, controlling bots, and other forms of remote device management. Pulse contains 23 indicator(s) (IOCs). View on OTX to inspect.

Indicators of Compromise (23)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain bsc-dataseed1.ninicoin.io VT 0 / 91 UrlVoid 0 / 36

IOC database

Type
domain
Value
bsc-dataseed1.ninicoin.io
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
RegistrarGoDaddy.com, LLC
TLDio
History
Creation date2019-04-12 04:00 UTC
Last analysis2026-09-25 15:10 UTC
Last modified on VirusTotal2026-09-25 21:12 UTC
Last WHOIS update2026-08-11 20:27 UTC
domain bsc-dataseed4.ninicoin.io VT 0 / 91 UrlVoid 0 / 36

IOC database

Type
domain
Value
bsc-dataseed4.ninicoin.io
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
RegistrarGoDaddy.com, LLC
TLDio
History
Creation date2019-04-12 04:00 UTC
Last analysis2026-09-25 15:10 UTC
Last modified on VirusTotal2026-09-25 19:56 UTC
Last WHOIS update2026-08-11 20:27 UTC
domain bsc-dataseed3.defibit.io VT 0 / 91 UrlVoid 0 / 36

IOC database

Type
domain
Value
bsc-dataseed3.defibit.io
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
RegistrarGoDaddy.com, LLC
TLDio
History
Creation date2019-04-12 04:00 UTC
Last analysis2026-09-25 15:10 UTC
Last modified on VirusTotal2026-09-25 19:02 UTC
Last WHOIS update2026-08-11 21:08 UTC
domain bsc-dataseed4.defibit.io VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/bsc-dataseed4.defibit.io

IOC database

Type
domain
Value
bsc-dataseed4.defibit.io
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/bsc-dataseed4.defibit.io

domain bsc-dataseed3.ninicoin.io VT 0 / 91 UrlVoid 0 / 36

IOC database

Type
domain
Value
bsc-dataseed3.ninicoin.io
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
RegistrarGoDaddy.com, LLC
TLDio
History
Creation date2019-04-12 04:00 UTC
Last analysis2026-09-25 15:10 UTC
Last modified on VirusTotal2026-09-25 18:32 UTC
Last WHOIS update2026-08-11 20:27 UTC
domain bsc-dataseed2.ninicoin.io VT 0 / 91 UrlVoid 0 / 36

IOC database

Type
domain
Value
bsc-dataseed2.ninicoin.io
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
RegistrarGoDaddy.com, LLC
TLDio
History
Creation date2019-04-12 04:00 UTC
Last analysis2026-09-25 17:53 UTC
Last modified on VirusTotal2026-09-25 23:32 UTC
Last WHOIS update2026-08-11 20:27 UTC
domain bsc-dataseed2.defibit.io VT 0 / 91 UrlVoid 0 / 36

IOC database

Type
domain
Value
bsc-dataseed2.defibit.io
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
RegistrarGoDaddy.com, LLC
TLDio
History
Creation date2019-04-12 04:00 UTC
Last analysis2026-09-25 15:10 UTC
Last modified on VirusTotal2026-09-25 21:32 UTC
Last WHOIS update2026-08-11 21:08 UTC
domain bsc-dataseed1.defibit.io VT 0 / 91 UrlVoid 0 / 36

IOC database

Type
domain
Value
bsc-dataseed1.defibit.io
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
RegistrarGoDaddy.com, LLC
TLDio
History
Creation date2019-04-12 04:00 UTC
Last analysis2026-09-25 15:10 UTC
Last modified on VirusTotal2026-09-25 18:41 UTC
Last WHOIS update2026-08-11 21:08 UTC
hash_md5 a12ba3a3dcd70e02f89253c9ec78b11f VT: not in VT

IOC database

Type
hash_md5
Value
a12ba3a3dcd70e02f89253c9ec78b11f
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: not in VT

hash_sha256 37fcbcb21d16866784050682c58424c91d3a736f6fd599271fa6e53cf5ca8a92 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/37fcbcb21d16866784050682c58424c91d3a736f6fd599271fa6e53cf5ca8a92

IOC database

Type
hash_sha256
Value
37fcbcb21d16866784050682c58424c91d3a736f6fd599271fa6e53cf5ca8a92
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/37fcbcb21d16866784050682c58424c91d3a736f6fd599271fa6e53cf5ca8a92

hash_sha256 48d3ecbb9e0b6babe6e53e2082a076bad07ef61ccd98dcc8b9e4f390b937788b VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/48d3ecbb9e0b6babe6e53e2082a076bad07ef61ccd98dcc8b9e4f390b937788b

IOC database

Type
hash_sha256
Value
48d3ecbb9e0b6babe6e53e2082a076bad07ef61ccd98dcc8b9e4f390b937788b
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/48d3ecbb9e0b6babe6e53e2082a076bad07ef61ccd98dcc8b9e4f390b937788b

hash_sha256 95f6abd3c43ef4b33cd61d054527233dd2ce705804d44a04be96cfb73bb52e3a VT: not in VT

IOC database

Type
hash_sha256
Value
95f6abd3c43ef4b33cd61d054527233dd2ce705804d44a04be96cfb73bb52e3a
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: not in VT

hash_sha256 efa07701570983909ef923ea79bb032f19fd9dac0b819fa0e4f6b1161a4cc221 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/efa07701570983909ef923ea79bb032f19fd9dac0b819fa0e4f6b1161a4cc221

IOC database

Type
hash_sha256
Value
efa07701570983909ef923ea79bb032f19fd9dac0b819fa0e4f6b1161a4cc221
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/efa07701570983909ef923ea79bb032f19fd9dac0b819fa0e4f6b1161a4cc221

url http://98.142.252.140:15847 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cDovLzk4LjE0Mi4yNTIuMTQwOjE1ODQ3

IOC database

Type
url
Value
http://98.142.252.140:15847
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cDovLzk4LjE0Mi4yNTIuMTQwOjE1ODQ3

url http://98.142.252.140:9000/wmglb VT 11 / 91

IOC database

Type
url
Value
http://98.142.252.140:9000/wmglb
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 11 of 91 VirusTotal vendors

VendorVerdictDetection
ADMINUSLabs malicious malicious
alphaMountain.ai malicious malicious
BitDefender malicious malware
Forcepoint ThreatSeeker malicious malicious
Fortinet malicious malware
G-Data malicious malware
Lionic malicious malicious
SOCRadar malicious phishing
Sophos malicious malware
VIPRE malicious malware
Gridinsoft suspicious suspicious

Details From VirusTotal

Basic Properties
Final URLhttp://98.142.252.140:9000/wmglb
Last HTTP status200
History
First seen on VirusTotal2026-09-24 13:45 UTC
Last submission2026-09-24 13:45 UTC
Last analysis2026-09-24 13:45 UTC
Last modified on VirusTotal2026-09-25 18:45 UTC
url https://bsc-dataseed1.defibit.io/ VT 1 / 93 UrlVoid 0 / 36

IOC database

Type
url
Value
https://bsc-dataseed1.defibit.io/
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 1 of 93 VirusTotal vendors

VendorVerdictDetection
Cluster25 malicious malicious

Details From VirusTotal

Basic Properties
TLDio
Final URLhttps://bsc-dataseed1.defibit.io/
Last HTTP status404
History
First seen on VirusTotal2020-10-31 03:39 UTC
Last submission2026-09-25 15:10 UTC
Last analysis2026-09-25 15:10 UTC
Last modified on VirusTotal2026-09-25 19:14 UTC
url https://bsc-dataseed1.ninicoin.io/ VT 1 / 93 UrlVoid 0 / 36

IOC database

Type
url
Value
https://bsc-dataseed1.ninicoin.io/
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 1 of 93 VirusTotal vendors

VendorVerdictDetection
Cluster25 malicious malicious

Details From VirusTotal

Basic Properties
TLDio
Final URLhttps://bsc-dataseed1.ninicoin.io/
Last HTTP status404
History
First seen on VirusTotal2021-01-06 09:20 UTC
Last submission2026-09-25 15:10 UTC
Last analysis2026-09-25 15:10 UTC
Last modified on VirusTotal2026-09-25 19:02 UTC
url https://bsc-dataseed2.defibit.io/ VT 1 / 93 UrlVoid 0 / 36

IOC database

Type
url
Value
https://bsc-dataseed2.defibit.io/
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 1 of 93 VirusTotal vendors

VendorVerdictDetection
Cluster25 malicious malicious

Details From VirusTotal

Basic Properties
TLDio
Final URLhttps://bsc-dataseed2.defibit.io/
Last HTTP status404
History
First seen on VirusTotal2021-04-27 16:47 UTC
Last submission2026-09-25 15:10 UTC
Last analysis2026-09-25 15:10 UTC
Last modified on VirusTotal2026-09-25 18:20 UTC
url https://bsc-dataseed2.ninicoin.io/ VT 1 / 93 UrlVoid 0 / 36

IOC database

Type
url
Value
https://bsc-dataseed2.ninicoin.io/
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 1 of 93 VirusTotal vendors

VendorVerdictDetection
Cluster25 malicious malicious

Details From VirusTotal

Basic Properties
TLDio
Final URLhttps://bsc-dataseed2.ninicoin.io/
Last HTTP status404
History
First seen on VirusTotal2023-08-15 05:40 UTC
Last submission2026-09-25 15:10 UTC
Last analysis2026-09-25 15:10 UTC
Last modified on VirusTotal2026-09-25 19:11 UTC
url https://bsc-dataseed3.defibit.io/ VT 1 / 93 UrlVoid 0 / 36

IOC database

Type
url
Value
https://bsc-dataseed3.defibit.io/
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 1 of 93 VirusTotal vendors

VendorVerdictDetection
Cluster25 malicious malicious

Details From VirusTotal

Basic Properties
TLDio
Final URLhttps://bsc-dataseed3.defibit.io/
Last HTTP status404
History
First seen on VirusTotal2020-10-31 03:38 UTC
Last submission2026-09-25 15:10 UTC
Last analysis2026-09-25 15:10 UTC
Last modified on VirusTotal2026-09-25 18:18 UTC
url https://bsc-dataseed3.ninicoin.io/ VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cHM6Ly9ic2MtZGF0YXNlZWQzLm5pbmljb2luLmlvLw
UrlVoid 0 / 36

IOC database

Type
url
Value
https://bsc-dataseed3.ninicoin.io/
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cHM6Ly9ic2MtZGF0YXNlZWQzLm5pbmljb2luLmlvLw

url https://bsc-dataseed4.defibit.io/ VT 1 / 93

IOC database

Type
url
Value
https://bsc-dataseed4.defibit.io/
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 1 of 93 VirusTotal vendors

VendorVerdictDetection
Cluster25 malicious malicious

Details From VirusTotal

Basic Properties
TLDio
Final URLhttps://bsc-dataseed4.defibit.io/
Last HTTP status404
History
First seen on VirusTotal2021-04-27 20:52 UTC
Last submission2026-09-25 15:10 UTC
Last analysis2026-09-25 15:10 UTC
Last modified on VirusTotal2026-09-25 18:23 UTC
url https://bsc-dataseed4.ninicoin.io/ VT 1 / 93 UrlVoid 0 / 36

IOC database

Type
url
Value
https://bsc-dataseed4.ninicoin.io/
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 1 of 93 VirusTotal vendors

VendorVerdictDetection
Cluster25 malicious malicious

Details From VirusTotal

Basic Properties
TLDio
Final URLhttps://bsc-dataseed4.ninicoin.io/
Last HTTP status404
History
First seen on VirusTotal2021-12-04 07:32 UTC
Last submission2026-09-25 15:10 UTC
Last analysis2026-09-25 15:10 UTC
Last modified on VirusTotal2026-09-25 19:11 UTC

References (2)

  • OTX pulse AlienVaulkt OTX

    SectopRAT (also known as ArechClient2) is a .NET-based remote access trojan (RAT) that provides a range of functions through multiple control commands. These include collecting sensitive data from the victim’s device, capturing screens, remotely managing processes and files, controlling bots, and other forms of remote device management.

  • reference AlienVaulkt OTX

Remediations (8)

  • web:daily.dev

    Fortinet's incident response team dissects a SectopRAT (ArechClient2) variant found hidden inside a tampered installation of a legitimate Italian digital audio workstation. The malware uses a multi-stage loader chain — a scheduled task, a tampered DLL with a modified Import Address Table, encrypted ASM code executed via an EnumSystemCodePagesW () API abuse trick, and API hash resolution ...

  • web:expertinsights.com

    FortiGuard Incident Response has detailed an intrusion in which SectopRAT , a .NET Remote Access Trojan (RAT) also known as ArechClient2, was hidden inside a tampered copy of legitimate audio software from an Italian company.

  • web:feed.craftedsignal.io

    Threat actors are distributing a variant of SectopRAT by embedding the malware into legitimate software installers, enabling remote control and credential theft upon execution.

  • web:gurucul.com

    Researchers uncovered a SectopRAT (ArechClient2) variant hidden inside a legitimate Italian audio workstation application. Attackers tampered with FrameworkBase.dll to sideload sdkcra.dll, while the encrypted SectopRAT payload was embedded in legitimate -looking database files and launched through a scheduled task. The malware decrypts and executes its payload in memory, enabling remote device ...

  • web:hackread.com

    Attackers concealed a SectopRAT variant inside tampered components belonging to legitimate digital audio software , creating a multi-stage infection chain that gave them remote control of a Windows system. FortiGuard Incident Response found the files while investigating an intrusion and shared its ...

  • web:www.darkreading.com

    Researchers discovered a variant of the SectopRAT post-compromise backdoor and infostealer hidden inside legitimate software from an Italian digital-audio company. The operators appear to have ...

  • web:www.fortinet.com

    Analysis of a SectopRAT variant hidden in tampered legitimate software that steals credentials and enables remote system control…

  • web:www.techfinitive.com

    The latest SectopRAT variant comes hidden within "tampered legitimate software that steals credentials and enables remote system control".

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.