| File name: | Xeno-v1.1.95.zip |
| Full analysis: | https://app.any.run/tasks/38b81979-8b09-47c1-9828-e238baca0e08 |
| Verdict: | Malicious activity |
| Analysis date: | May 16, 2025, 12:52:35 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract, compression method=store |
| MD5: | 80C1FA6C43472AF00763F67A1476FD6C |
| SHA1: | B4C2ECB2AB9FCB2BC88206090FF33457BFB3F25B |
| SHA256: | 14EF0E1602C97030AC84D3EC70DA1C6F41C2CC6300D1BECD7B5B19FA4C5CC20C |
| SSDEEP: | 98304:nhz3k/s7a0d8jgdFb2gEiEmZEyf5Ynfooj+eObMoGQhrD/Fn9HJE4BIBKPSkYvlo:dGMoOF1Zj64y6t/5 |
| .zip | | | ZIP compressed archive (36.3) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2025:05:08 22:30:10 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | Xeno-v1.1.95/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 372 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Downloads\Xeno-v1.1.95.zip | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| (PID) Process: | (372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\omni_23_10_2024_.zip | |||
| (PID) Process: | (372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Downloads\Xeno-v1.1.95.zip | |||
| (PID) Process: | (372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (372) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 372 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa372.28336\Xeno-v1.1.95\api-ms-win-crt-filesystem-l1-1-0.dll | executable | |
MD5:42A2A95F1BB940D01F55EB1674A81FE2 | SHA256:51541EC6684B43157A85EA46A42EBED4555BE06BED0D0D07FF3EA6377301318D | |||
| 372 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa372.28336\Xeno-v1.1.95\api-ms-win-crt-locale-l1-1-0.dll | executable | |
MD5:FF48B107B2449A647C64BAABD49408A1 | SHA256:7BB8644E565AD4BCFD890F9044BCCB4D99953A740E9A500B1F820B2FDC3FC240 | |||
| 372 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa372.28336\Xeno-v1.1.95\api-ms-win-crt-heap-l1-1-0.dll | executable | |
MD5:98DA186FD7D7873C164A51C5D7B77F1A | SHA256:80139E4CAA379D87B1D1DAFC23ACE71D2B330368115F6314140D4AE59C2A78E8 | |||
| 372 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa372.28336\Xeno-v1.1.95\api-ms-win-crt-convert-l1-1-0.dll | executable | |
MD5:C8DBF0CA88FACFE87899168A7F7DB52C | SHA256:94B6E91B93C2202DABD659BFF294BEE87C22897A30A6B4930B49051C2FB502DC | |||
| 372 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa372.28336\Xeno-v1.1.95\api-ms-win-crt-math-l1-1-0.dll | executable | |
MD5:E10E077BB06209AEDD0D0D378C758F73 | SHA256:8A7BFF1C918539A75C25568DB25933D653C003E016FD7791A37186B42BBB7C20 | |||
| 372 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa372.28336\Xeno-v1.1.95\api-ms-win-crt-string-l1-1-0.dll | executable | |
MD5:0F593E50BE4715AA8E1F6EB39434EDD5 | SHA256:BF4EA10BE1B64C442AC0CCF4BDF69F6703467176A27E9E14A488D26448A6E179 | |||
| 372 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa372.28336\Xeno-v1.1.95\api-ms-win-crt-stdio-l1-1-0.dll | executable | |
MD5:429C26ED27A026442F89C95FF16CE8C2 | SHA256:2A466648AFFD3D51B944F563BB65046A3DA91006A0D90FB2C0B123487A1FC1B3 | |||
| 372 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa372.28336\Xeno-v1.1.95\bin\Monaco\vs\basic-languages\lua\lua.js | binary | |
MD5:EEBDA1FDD970433750C115EAE2F03865 | SHA256:AC729EFB3164F48D6B08F74D4B15060C126A30D40FB4CD4FC9CC94F2E19BD7C7 | |||
| 372 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa372.28336\Xeno-v1.1.95\bin\Monaco\index.html | html | |
MD5:001DCBB8F41CDCBF9B4D1E3A0ED4B2D2 | SHA256:F1D2C52F2803C29585B81D2EFF74C56242D27E9619EE6D38081D5604C5BB1951 | |||
| 372 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$DRa372.28336\Xeno-v1.1.95\bin\Monaco\vs\base\worker\workerMain.js | binary | |
MD5:D0AC5294C58E523CDDF25BC6D785FA48 | SHA256:E90D1A8F116FA74431117A3AD78DDE16DDE060A4BF7528DFE3D5A3AD6156504B | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |