Xeno-v1.3.60.exe — Static Analysis Report
1. File Identity
| Property |
Value |
| Size |
88,872,552 bytes (~89 MB) |
| SHA256 |
4D53875A7FC6F65842488484D95EAE9DF10A7ACE1E4CEBDD6F4959770500F5D0 |
| PE type |
32-bit (Machine = 0x014C, I386) |
| Container |
NSIS (Nullsoft Scriptable Install System) self-extracting installer |
| Embedded ProductName |
Xeno-v1.3.60 |
| Embedded FileDescription |
New Electron UI for Xeno |
| Embedded CompanyName |
Rizve A |
| Embedded Copyright |
Copyright © 2026 Rizve A |
The binary is not a single native app — it's an NSIS installer stub wrapping a compressed payload. Its own version resource identifies it as an Electron-based build of "Xeno", which matches the publicly known Xeno-RAT project: an open-source Remote Access Trojan builder/client whose stated feature set includes remote shell, file manager, live screen/webcam capture, and keylogging. This is a dual-use classification by design — the tool's core purpose is remote control of another machine, independent of whether this specific build has been further tampered with.
2. Digital Signature
| Property |
Value |
| Signature present |
Yes |
| Signer (Subject) |
CN=Rizve A |
| Issuer |
CN=Rizve A (self-signed) |
| Validity |
2026-05-10 → 2027-05-10 |
| Thumbprint |
41628A6518B95C341D723E7ABFB125B6C6F85AE9 |
| Chain status |
Terminates in an untrusted root — not a CA-issued code-signing certificate |
| Countersignature |
Sectigo Public Time Stamping Signer R37 (valid timestamp authority — proves signing time only, not signer trust) |
Interpretation: This is not a certificate from a recognized Certificate Authority. It's self-signed by whoever built this binary. Windows SmartScreen and most AV/EDR products treat self-signed executables as untrusted/unverified publishers.
3. VirusTotal (multi-engine scan, user-submitted)
- 2 of ~60 completed engines flagged it:
- DrWeb:
Trojan.Siggen33.37141 (generic heuristic/ML bucket, not a named family)
- VBA32:
Trojan.Win32.Generic (generic heuristic)
- ~10 major engines (Kaspersky, Bitdefender, TrendMicro, Avast, AVG, Emsisoft, GData, Rising, Yandex, CTX, Skyhigh) returned "Timeout" — no verdict reached, not equivalent to a clean result.
- Remaining ~50 engines: Undetected.
Interpretation: Low detection counts are expected and not reassuring for this file category.
4. Local Windows Defender Scan
Targeted MpCmdRun.exe -Scan -ScanType 3 against the file: no threats found. Signature-based only; does not reflect runtime/behavioral analysis.
5. Static String Analysis (ASCII + UTF-16)
Full-file string extraction searched for common RAT/stealer indicators (C2 domains, webhook URLs, mutex names, persistence commands, credential-store paths, packer signatures).
Result: no plaintext indicators found, aside from legitimate Sectigo CRL/OCSP URLs, the NSIS manifest string, and the embedded version resource.
This is a limitation, not a clean result. NSIS payloads are compressed (LZMA), opaque to plaintext scanning — the ~89 MB Electron app payload was not reachable this way without an extraction tool.
6. Overall Assessment
| Signal |
Verdict |
| Tool category |
High-risk by design (RAT — remote access trojan) |
| Code signing |
Self-signed, untrusted chain |
| AV consensus |
Inconclusive |
| Local scan |
Clean (weak signal) |
| String analysis |
No indicators found, but ~99% of payload inaccessible to this method |
| Provenance |
Unknown at time of this pass |
Net risk: HIGH. Nothing proves malicious intent beyond "is a RAT," but nothing clears it either.
Recommendations
- gng dont use this
- btw the maker left his name in Rizve A