s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1811989 high

📛 Threat Title

SectopRAT: SHA256 hash of a malware sample (payload) 3acf0c5484f7b9a08fee20f36d76566c53423b6612ec20bb5194fbb5beecb939

Category: SectopRAT Published: Source updated: First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: SectopRAT (aliases: 1xxbot,ArechClient). Confidence: 100. First seen: 2026-05-13 20:54:03 UTC. Reporter: la_cyber. Tags: SectopRAT.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 3acf0c5484f7b9a08fee20f36d76566c53423b6612ec20bb5194fbb5beecb939

IOC database

Type
hash_sha256
Value
3acf0c5484f7b9a08fee20f36d76566c53423b6612ec20bb5194fbb5beecb939
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
SHA256 hash of a malware sample (payload) attributed to SectopRAT

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: SectopRAT (aliases: 1xxbot,ArechClient). Confidence: 100. First seen: 2026-05-13 20:54:03 UTC. Reporter: la_cyber. Tags: SectopRAT.

Remediations (10)

  • web:bazaar.abuse.ch

    Using the form below, you can search for malware samples by a hash (MD5, SHA256 , SHA1), imphash, tlsh hash , ClamAV signature, tag or malware family. Browse Database

  • web:cybersecuritynews.com

    The emergence of a highly obfuscated .NET-based Remote Access Trojan (RAT) known as sectopRAT , disguised as a legitimate Google Chrome extension has been revealed in a recent analysis. This malicious software, also identified as Arechclient2, demonstrates advanced obfuscation techniques and sophisticated functionalities aimed at data theft. SectopRAT is written in .NET and employs the calli ...

  • web:cybersecuritynews.com

    A new malware strain dubbed SectopRAT has emerged, leveraging Cloudflare's Turnstile challenge system as part of its attack methodology.

  • web:github.com

    infected - password for all archives. 🔑 SHA256 - is hash of file in archive. ⌗ Virus/ Malware - software to infect, damage, or erase file/s, network, wireless network, server/s. (?) ️

  • web:malpedia.caad.fkie.fraunhofer.de

    SectopRAT , aka ArechClient2, is a .NET RAT with numerous capabilities including multiple stealth functions. Arechclient2 can profile victim systems, steal information such as browser and crypto-wallet data, and launch a hidden secondary desktop to control browser sessions. Additionally, it has several anti-VM and anti-emulator capabilities.

  • web:malwr-analysis.com

    Arechclient2, also known as sectopRAT , is a Remote Access Trojan (RAT) written in .NET. This malware is highly obfuscated using the calli obfuscator, making its analysis challenging. Despite attempting deobfuscation using calliFixer, the code remained obfuscated but was still somewhat readable using dnSpy. The sample analyzed has the following characteristics: File Hash ...

  • web:www.broadcom.com

    A multi-stage malware campaign has been uncovered where users searching for cracked games are tricked into downloading installers that first deploy Lumma Stealer and then install SectopRAT .

  • web:www.malwarebytes.com

    The final redirect eventually downloads a large executable disguised as Google Chrome which does install the aforementioned but also surreptitiously drops a malware payload known as SecTopRAT . We have reported this incident to Google, but at the time of writing the fake Google Sites page is still up and running.

  • web:www.microsoft.com

    Following the mitigation steps below can help prevent malware attacks: Harden internet-facing assets and ensure they have the latest security updates. Use threat and vulnerability management to audit these assets regularly for vulnerabilities, misconfigurations, and suspicious activity.

  • web:www.securitytalent.net

    SecurityTalent is a public malware database by MD Mehedi Hasan, enabling security professionals to search, submit, and download malware samples , hashes, and IOCs.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.