Published 11/30/2022
Arechclient2 is a .NET remote access trojan (RAT) that has numerous capabilities. The RAT can profile victim systems, steal information such as browser and crypto wallet data, and launch a hidden secondary desktop to control browser sessions.
Update 12/8/2022:Cyber Florida identified additional content in the analysis that was not previously reported. This information pertains to network connections. Within utilizing the InstallUtil.exe binary to execute code, the InstallUtil.exe process was observed reaching out to a pastebin.]com page. This page contained the CnC IP address. Additionally, the victim IP address (observed in the UIP parameter) appears to be ascertained from the InstallUtil.exe process from hxxp://eth0[.]me (which appears to be a site that identifies the visiting host's IP address)
Original Post: Cyber Florida has observed network payload data obfuscated via Base64 encoding and sent to what appears to be a command-and-control server. The command-and-control server appears to be using Google Cloud Services (googleusercontent.com). Within the Base64 data, exfiltrated usernames and passwords were observed. Based on observations, the exfiltrated data appears to be from cached browser credentials (Google Chrome profiles, Firefox profiles, Microsoft Edge profiles, etc.) In reviewing logs and network traffic, there were parameters of interest within the data payload that would aid in identifying this activity. The following payload parameters were observed in the network traffic: ConnectionType, Client, SessionID, BotName, Computer, BuildID, BotOS, URLData, UIP
Based on observing network traffic for command-and-control communication, there may be similarities to the Redline Stealer malware. See CERT Italy article. https://cert-agid.gov.it/news/scoperto-il-malware-redline-stealer-veicolato-come-lastpass/
Screenshot samples of log and network traffic have been provided in the appendix of this report.
Some of the interesting evasion tactics Cyber Florida observed included the use of "sleep" functions and the .NET Framework's InstallUtil.exe to communicate with the command-and-control server. The "sleep" functionality appeared to delay the usage of InstallUtil.exe. During testing, Installutil.exe appeared to run indefinitely and regularly communicated with the command-and-control server. In reviewing a few of the automated sandboxes, the Installutil.exe activity was not identified. This may be due to the "sleep" activity being utilized.
Another evasion tactic appears to involve modifying Windows Defender settings via the second observed PowerShell instance. The Set-MpPreference cmdlet, with the –ExclusionPath 'C:' option, was used. This command appears to create a malware scan exclusion, which would prevent Windows Defender from scanning the entire C: volume.
The following links provide examples and context for the use and abuse of InstallUtil.exe malware.
https://gbhackers.com/hiding-malware-legitimate-tool/ (not directly related to observed activity
https://www.ired.team/offensive-security/code-execution/t1118-installutil (not directly related to observed activity)
https://attack.mitre.org/techniques/T1218/004/
During the initial execution of the malicious binary, a persistence mechanism was observed via the common HKCU\Software\Microsoft\Windows\CurrentVersion\Run location.
Blackpoint Cyber discovered an ISO file containing a malicious Windows executable that was downloaded to a victim's computer and not detected by an antivirus program. A malicious executable named Setup.exe was observed employing various defense-evasion techniques, including obfuscation, injection, and uncommon automation tools. These tools were used to drop a RAT named Arechclient2 (Blackpoint Cyber). The size of Setup.exe is over 300 megabytes (Blackpoint Cyber).
The initial attack vector used to deliver Setup.exe to the victim is unknown. This is the execution step. When Setup.iso is double-clicked, the ISO file can be mounted like a CD, and the contents are often automatically executed (Blackpoint Cyber). Running Setup.exe will start the extraction of three files and execute multiple child processes (Blackpoint Cyber). A new folder, IXP000.TMP is made in the victim's AppDataLocalTemp directory, and three files are created in the newly created directory: Funding.mpeg, Mali.mpeg, and Dns.mpeg (Blackpoint Cyber).
The Dns.mpeg script is heavily obfuscated. The script searches for AvastUI.exe and AVGUI.exe running on the victim's computer. The two executables are found in the Avast antivirus product line (Blackpoint Cyber). If those two executables are not found, Dns.mpeg sets Hole.exe.pif to the name AutoIT3.exe. In the script .au3 (or d.au3), there are over 3,000 references to a function named Xspci(). This function takes a string as its first argument and a number as its second argument. The function is responsible for decoding strings (Blackpoint Cyber).
The .au3 script accomplishes three things through injection: 1. Establishing persistence using a URL file in the victim's startup folder. 2. Copying the ntdll.dll file from the C:WindowsSysWOW64 folder to avoid antivirus hooks. 3. Injecting the embedded payload into jsc.exe (Blackpoint Cyber). The function responsible for the above tasks is KXsObHGILZNaOurxqSUainCYU(), which takes a pointer to the binary to be injected, a string argument, and a string argument containing the path to the binary to be executed and injected (Blackpoint Cyber). The script establishes persistence by adding a URL file to the victim's startup folder that will execute a Microsoft Visual Basic Script (VBS) on every login (Blackpoint Cyber).
Arechclient2 has a decompilation phase. Test.exe, a C# binary, can be loaded by tools that analyze code statically and dynamically. One such tool is DnSpy (Blackpoint Cyber). The class names in Test.exe were reduced to single- and double-character names to add an additional layer of confusion for reverse engineers (Blackpoint Cyber). The actual name of Test.exe is 2qbarx12tqm.exe (Blackpoint Cyber). Arechclient2 also includes a command-and-control (C2) phase. When Arechclient2 is executed, it connects to https[:]//pastebin.com/raw/nJqnWX3u to collect C2 information (Blackpoint Cyber). The requested file, nJqnWX3u, contains the IP address 34[.]141[.]198[.]105 as a string. It also connects to http[:]//eth0.me to get its public IP address (Blackpoint Cyber). Arechclient2 connects to its C2 server on port 15647 to receive commands. The server responds with information to control the encryption status ("On" or "Off") in JSON format (Blackpoint Cyber). If communications are intercepted and encryption is set to "Off," subsequent communications will be in plaintext (Blackpoint Cyber).
This screenshot shows the payload sent to a victim, as seen by Cyber Florida. A portion of the Base64 and UIP fields has been redacted.
The following screenshot is similar to the log above but was acquired via network packet capture.
Blackpoint Cyber. "Ratting out arechclient2 – Blackpoint Whitepaper." Blackpoint Cyber. Accessed November 15, 2022. https://blackpointcyber.com/lp/ratting-out-arechclient2/?utm_campaign=ratting_out_arechclient2_whitepaper&utm_source=resource_library.
Contributing Security Analysts: Dorian Pope, Sreten Dedic, EJ Bulut, Uday Bilakhiya.