Suspicious
Suspect

9cf073fefffea51d7e6780b3b886f00c

PE Executable
MD5: 9cf073fefffea51d7e6780b3b886f00c
Size: 46.59 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Low
MD5 9cf073fefffea51d7e6780b3b886f00c
Sha1 923ae59f2983bf854f2a6222083b55f5ac886cb7
Sha256 45f245b964952e7ab59f50597ba1458ea8a3dfe42f0bc9a12696af02a810fbac
Sha384 eb7f5c601b7a664d665e09e726b269fa2695395d3d28c6f18693503dbfbcd0d2869d0caae19f6d6821fad3ae1b38a64e
Sha512 5fb7983e02e928312085d1e2ce26fa9d23b2b0f2eb4d202416b307d50d0581bee6e7eb843508588e10ffd40234c6de15e9f0f9e8db80cabab3c57b66cd4288b6
SSDeep 768:VdhO/poiiUcjlJInBSH9Xqk5nWEZ5SbTDaluI7CPW5Q:rw+jjgn8H9XqcnW85SbT4uI4
TLSH 6923F84C57AC8923E6AF5ABD98324263C7B3E3669532E38F08CCD4E9379338554053A7
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
xeno rat client.exe
Full Name
xeno rat client.exe
EntryPoint
System.Void xeno_rat_client.Program::<Main>(System.String[])
Scope Name
xeno rat client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xeno rat client
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
64
Main Method
System.Void xeno_rat_client.Program::<Main>(System.String[])
Main IL Instruction Count
7
Main IL
ldarg.0 <null>
call System.Threading.Tasks.Task xeno_rat_client.Program::Main(System.String[])
callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter()
stloc.0 <null>
ldloca.s V_0
call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult()
ret <null>
Module Name
xeno rat client.exe
Full Name
xeno rat client.exe
EntryPoint
System.Void xeno_rat_client.Program::<Main>(System.String[])
Scope Name
xeno rat client.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
xeno rat client
Assembly Version
1.0.0.0
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
64
Main Method
System.Void xeno_rat_client.Program::<Main>(System.String[])
Main IL Instruction Count
7
Main IL
ldarg.0 <null>
call System.Threading.Tasks.Task xeno_rat_client.Program::Main(System.String[])
callvirt System.Runtime.CompilerServices.TaskAwaiter System.Threading.Tasks.Task::GetAwaiter()
stloc.0 <null>
ldloca.s V_0
call System.Void System.Runtime.CompilerServices.TaskAwaiter::GetResult()
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙