OTX-6ab688467ce23517fb31e378
info
📛 Threat Title
Uncovering a SectopRAT Variant Embedded in Legitimate Software
Description
SectopRAT (also known as ArechClient2) is a .NET-based remote access trojan (RAT) that provides a range of functions through multiple control commands. These include collecting sensitive data from the victim’s device, capturing screens, remotely managing processes and files, controlling bots, and other forms of remote device management. Pulse contains 23 indicator(s) (IOCs). View on OTX to inspect.
Indicators of Compromise (23)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
bsc-dataseed1.ninicoin.io
VT 0 / 91
UrlVoid 0 / 36
IOC database
- Type
- domain
- Value
bsc-dataseed1.ninicoin.io- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| Registrar | GoDaddy.com, LLC |
| TLD | io |
History
| Creation date | 2019-04-12 04:00 UTC |
| Last analysis | 2026-09-25 15:10 UTC |
| Last modified on VirusTotal | 2026-09-25 21:12 UTC |
| Last WHOIS update | 2026-08-11 20:27 UTC |
domain
bsc-dataseed4.ninicoin.io
VT 0 / 91
UrlVoid 0 / 36
IOC database
- Type
- domain
- Value
bsc-dataseed4.ninicoin.io- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| Registrar | GoDaddy.com, LLC |
| TLD | io |
History
| Creation date | 2019-04-12 04:00 UTC |
| Last analysis | 2026-09-25 15:10 UTC |
| Last modified on VirusTotal | 2026-09-25 19:56 UTC |
| Last WHOIS update | 2026-08-11 20:27 UTC |
domain
bsc-dataseed3.defibit.io
VT 0 / 91
UrlVoid 0 / 36
IOC database
- Type
- domain
- Value
bsc-dataseed3.defibit.io- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| Registrar | GoDaddy.com, LLC |
| TLD | io |
History
| Creation date | 2019-04-12 04:00 UTC |
| Last analysis | 2026-09-25 15:10 UTC |
| Last modified on VirusTotal | 2026-09-25 19:02 UTC |
| Last WHOIS update | 2026-08-11 21:08 UTC |
domain
bsc-dataseed4.defibit.io
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/bsc-dataseed4.defibit.io
IOC database
- Type
- domain
- Value
bsc-dataseed4.defibit.io- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/bsc-dataseed4.defibit.io
domain
bsc-dataseed3.ninicoin.io
VT 0 / 91
UrlVoid 0 / 36
IOC database
- Type
- domain
- Value
bsc-dataseed3.ninicoin.io- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| Registrar | GoDaddy.com, LLC |
| TLD | io |
History
| Creation date | 2019-04-12 04:00 UTC |
| Last analysis | 2026-09-25 15:10 UTC |
| Last modified on VirusTotal | 2026-09-25 18:32 UTC |
| Last WHOIS update | 2026-08-11 20:27 UTC |
domain
bsc-dataseed2.ninicoin.io
VT 0 / 91
UrlVoid 0 / 36
IOC database
- Type
- domain
- Value
bsc-dataseed2.ninicoin.io- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| Registrar | GoDaddy.com, LLC |
| TLD | io |
History
| Creation date | 2019-04-12 04:00 UTC |
| Last analysis | 2026-09-25 17:53 UTC |
| Last modified on VirusTotal | 2026-09-25 23:32 UTC |
| Last WHOIS update | 2026-08-11 20:27 UTC |
domain
bsc-dataseed2.defibit.io
VT 0 / 91
UrlVoid 0 / 36
IOC database
- Type
- domain
- Value
bsc-dataseed2.defibit.io- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| Registrar | GoDaddy.com, LLC |
| TLD | io |
History
| Creation date | 2019-04-12 04:00 UTC |
| Last analysis | 2026-09-25 15:10 UTC |
| Last modified on VirusTotal | 2026-09-25 21:32 UTC |
| Last WHOIS update | 2026-08-11 21:08 UTC |
domain
bsc-dataseed1.defibit.io
VT 0 / 91
UrlVoid 0 / 36
IOC database
- Type
- domain
- Value
bsc-dataseed1.defibit.io- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| Registrar | GoDaddy.com, LLC |
| TLD | io |
History
| Creation date | 2019-04-12 04:00 UTC |
| Last analysis | 2026-09-25 15:10 UTC |
| Last modified on VirusTotal | 2026-09-25 18:41 UTC |
| Last WHOIS update | 2026-08-11 21:08 UTC |
hash_md5
a12ba3a3dcd70e02f89253c9ec78b11f
VT: not in VT
IOC database
- Type
- hash_md5
- Value
a12ba3a3dcd70e02f89253c9ec78b11f- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: not in VT
hash_sha256
37fcbcb21d16866784050682c58424c91d3a736f6fd599271fa6e53cf5ca8a92
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/37fcbcb21d16866784050682c58424c91d3a736f6fd599271fa6e53cf5ca8a92
IOC database
- Type
- hash_sha256
- Value
37fcbcb21d16866784050682c58424c91d3a736f6fd599271fa6e53cf5ca8a92- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/37fcbcb21d16866784050682c58424c91d3a736f6fd599271fa6e53cf5ca8a92
hash_sha256
48d3ecbb9e0b6babe6e53e2082a076bad07ef61ccd98dcc8b9e4f390b937788b
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/48d3ecbb9e0b6babe6e53e2082a076bad07ef61ccd98dcc8b9e4f390b937788b
IOC database
- Type
- hash_sha256
- Value
48d3ecbb9e0b6babe6e53e2082a076bad07ef61ccd98dcc8b9e4f390b937788b- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/48d3ecbb9e0b6babe6e53e2082a076bad07ef61ccd98dcc8b9e4f390b937788b
hash_sha256
95f6abd3c43ef4b33cd61d054527233dd2ce705804d44a04be96cfb73bb52e3a
VT: not in VT
IOC database
- Type
- hash_sha256
- Value
95f6abd3c43ef4b33cd61d054527233dd2ce705804d44a04be96cfb73bb52e3a- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: not in VT
hash_sha256
efa07701570983909ef923ea79bb032f19fd9dac0b819fa0e4f6b1161a4cc221
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/efa07701570983909ef923ea79bb032f19fd9dac0b819fa0e4f6b1161a4cc221
IOC database
- Type
- hash_sha256
- Value
efa07701570983909ef923ea79bb032f19fd9dac0b819fa0e4f6b1161a4cc221- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/efa07701570983909ef923ea79bb032f19fd9dac0b819fa0e4f6b1161a4cc221
url
http://98.142.252.140:15847
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cDovLzk4LjE0Mi4yNTIuMTQwOjE1ODQ3
IOC database
- Type
- url
- Value
http://98.142.252.140:15847- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cDovLzk4LjE0Mi4yNTIuMTQwOjE1ODQ3
url
http://98.142.252.140:9000/wmglb
VT 11 / 91
IOC database
- Type
- url
- Value
http://98.142.252.140:9000/wmglb- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 11 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| alphaMountain.ai | malicious | malicious |
| BitDefender | malicious | malware |
| Forcepoint ThreatSeeker | malicious | malicious |
| Fortinet | malicious | malware |
| G-Data | malicious | malware |
| Lionic | malicious | malicious |
| SOCRadar | malicious | phishing |
| Sophos | malicious | malware |
| VIPRE | malicious | malware |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Final URL | http://98.142.252.140:9000/wmglb |
| Last HTTP status | 200 |
History
| First seen on VirusTotal | 2026-09-24 13:45 UTC |
| Last submission | 2026-09-24 13:45 UTC |
| Last analysis | 2026-09-24 13:45 UTC |
| Last modified on VirusTotal | 2026-09-25 18:45 UTC |
url
https://bsc-dataseed1.defibit.io/
VT 1 / 93
UrlVoid 0 / 36
IOC database
- Type
- url
- Value
https://bsc-dataseed1.defibit.io/- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 1 of 93 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Cluster25 | malicious | malicious |
Details From VirusTotal
Basic Properties
| TLD | io |
| Final URL | https://bsc-dataseed1.defibit.io/ |
| Last HTTP status | 404 |
History
| First seen on VirusTotal | 2020-10-31 03:39 UTC |
| Last submission | 2026-09-25 15:10 UTC |
| Last analysis | 2026-09-25 15:10 UTC |
| Last modified on VirusTotal | 2026-09-25 19:14 UTC |
url
https://bsc-dataseed1.ninicoin.io/
VT 1 / 93
UrlVoid 0 / 36
IOC database
- Type
- url
- Value
https://bsc-dataseed1.ninicoin.io/- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 1 of 93 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Cluster25 | malicious | malicious |
Details From VirusTotal
Basic Properties
| TLD | io |
| Final URL | https://bsc-dataseed1.ninicoin.io/ |
| Last HTTP status | 404 |
History
| First seen on VirusTotal | 2021-01-06 09:20 UTC |
| Last submission | 2026-09-25 15:10 UTC |
| Last analysis | 2026-09-25 15:10 UTC |
| Last modified on VirusTotal | 2026-09-25 19:02 UTC |
url
https://bsc-dataseed2.defibit.io/
VT 1 / 93
UrlVoid 0 / 36
IOC database
- Type
- url
- Value
https://bsc-dataseed2.defibit.io/- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 1 of 93 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Cluster25 | malicious | malicious |
Details From VirusTotal
Basic Properties
| TLD | io |
| Final URL | https://bsc-dataseed2.defibit.io/ |
| Last HTTP status | 404 |
History
| First seen on VirusTotal | 2021-04-27 16:47 UTC |
| Last submission | 2026-09-25 15:10 UTC |
| Last analysis | 2026-09-25 15:10 UTC |
| Last modified on VirusTotal | 2026-09-25 18:20 UTC |
url
https://bsc-dataseed2.ninicoin.io/
VT 1 / 93
UrlVoid 0 / 36
IOC database
- Type
- url
- Value
https://bsc-dataseed2.ninicoin.io/- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 1 of 93 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Cluster25 | malicious | malicious |
Details From VirusTotal
Basic Properties
| TLD | io |
| Final URL | https://bsc-dataseed2.ninicoin.io/ |
| Last HTTP status | 404 |
History
| First seen on VirusTotal | 2023-08-15 05:40 UTC |
| Last submission | 2026-09-25 15:10 UTC |
| Last analysis | 2026-09-25 15:10 UTC |
| Last modified on VirusTotal | 2026-09-25 19:11 UTC |
url
https://bsc-dataseed3.defibit.io/
VT 1 / 93
UrlVoid 0 / 36
IOC database
- Type
- url
- Value
https://bsc-dataseed3.defibit.io/- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 1 of 93 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Cluster25 | malicious | malicious |
Details From VirusTotal
Basic Properties
| TLD | io |
| Final URL | https://bsc-dataseed3.defibit.io/ |
| Last HTTP status | 404 |
History
| First seen on VirusTotal | 2020-10-31 03:38 UTC |
| Last submission | 2026-09-25 15:10 UTC |
| Last analysis | 2026-09-25 15:10 UTC |
| Last modified on VirusTotal | 2026-09-25 18:18 UTC |
url
https://bsc-dataseed3.ninicoin.io/
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cHM6Ly9ic2MtZGF0YXNlZWQzLm5pbmljb2luLmlvLw
UrlVoid 0 / 36
IOC database
- Type
- url
- Value
https://bsc-dataseed3.ninicoin.io/- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cHM6Ly9ic2MtZGF0YXNlZWQzLm5pbmljb2luLmlvLw
url
https://bsc-dataseed4.defibit.io/
VT 1 / 93
IOC database
- Type
- url
- Value
https://bsc-dataseed4.defibit.io/- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 1 of 93 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Cluster25 | malicious | malicious |
Details From VirusTotal
Basic Properties
| TLD | io |
| Final URL | https://bsc-dataseed4.defibit.io/ |
| Last HTTP status | 404 |
History
| First seen on VirusTotal | 2021-04-27 20:52 UTC |
| Last submission | 2026-09-25 15:10 UTC |
| Last analysis | 2026-09-25 15:10 UTC |
| Last modified on VirusTotal | 2026-09-25 18:23 UTC |
url
https://bsc-dataseed4.ninicoin.io/
VT 1 / 93
UrlVoid 0 / 36
IOC database
- Type
- url
- Value
https://bsc-dataseed4.ninicoin.io/- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 1 of 93 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Cluster25 | malicious | malicious |
Details From VirusTotal
Basic Properties
| TLD | io |
| Final URL | https://bsc-dataseed4.ninicoin.io/ |
| Last HTTP status | 404 |
History
| First seen on VirusTotal | 2021-12-04 07:32 UTC |
| Last submission | 2026-09-25 15:10 UTC |
| Last analysis | 2026-09-25 15:10 UTC |
| Last modified on VirusTotal | 2026-09-25 19:11 UTC |
References (2)
-
OTX pulse
AlienVaulkt OTX
SectopRAT (also known as ArechClient2) is a .NET-based remote access trojan (RAT) that provides a range of functions through multiple control commands. These include collecting sensitive data from the victim’s device, capturing screens, remotely managing processes and files, controlling bots, and other forms of remote device management.
- reference AlienVaulkt OTX
Remediations (8)
-
web:daily.dev
Fortinet's incident response team dissects a SectopRAT (ArechClient2) variant found hidden inside a tampered installation of a legitimate Italian digital audio workstation. The malware uses a multi-stage loader chain — a scheduled task, a tampered DLL with a modified Import Address Table, encrypted ASM code executed via an EnumSystemCodePagesW () API abuse trick, and API hash resolution ...
-
web:expertinsights.com
FortiGuard Incident Response has detailed an intrusion in which SectopRAT , a .NET Remote Access Trojan (RAT) also known as ArechClient2, was hidden inside a tampered copy of legitimate audio software from an Italian company.
-
web:feed.craftedsignal.io
Threat actors are distributing a variant of SectopRAT by embedding the malware into legitimate software installers, enabling remote control and credential theft upon execution.
-
web:gurucul.com
Researchers uncovered a SectopRAT (ArechClient2) variant hidden inside a legitimate Italian audio workstation application. Attackers tampered with FrameworkBase.dll to sideload sdkcra.dll, while the encrypted SectopRAT payload was embedded in legitimate -looking database files and launched through a scheduled task. The malware decrypts and executes its payload in memory, enabling remote device ...
-
web:hackread.com
Attackers concealed a SectopRAT variant inside tampered components belonging to legitimate digital audio software , creating a multi-stage infection chain that gave them remote control of a Windows system. FortiGuard Incident Response found the files while investigating an intrusion and shared its ...
-
web:www.darkreading.com
Researchers discovered a variant of the SectopRAT post-compromise backdoor and infostealer hidden inside legitimate software from an Italian digital-audio company. The operators appear to have ...
-
web:www.fortinet.com
Analysis of a SectopRAT variant hidden in tampered legitimate software that steals credentials and enables remote system control…
-
web:www.techfinitive.com
The latest SectopRAT variant comes hidden within "tampered legitimate software that steals credentials and enables remote system control".
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.