s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-cb5e0d435fbad026262192e4ded328eba2952f35433412cba4d494a2d8661ca5 high

📛 Threat Title

XenoRAT: AU88.exe

Category: XenoRAT Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 46592 bytes. Tags: c2, dcrat, exe, rat, windows, XenoRAT. Reporter: anonymous. First seen: 2026-05-14 20:52:38.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain au88.exe VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/au88.exe

IOC database

Type
domain
Value
au88.exe
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Extracted from Threat MB-cb5e0d435fbad026262192e4ded328eba2952f35433412cba4d494a2d8661ca5

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/au88.exe

hash_imphash f34d5f2d4577ed6d9ceec516c1f5a744

IOC database

Type
hash_imphash
Value
f34d5f2d4577ed6d9ceec516c1f5a744
First seen
Last seen
Attached to this threat
Appears in
648 threats
Description
imphash of URLhaus payload 61d424c2e3c5d8db…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 cb5e0d435fbad026262192e4ded328eba2952f35433412cba4d494a2d8661ca5 VT 57 / 75 1 feed

IOC database

Type
hash_sha256
Value
cb5e0d435fbad026262192e4ded328eba2952f35433412cba4d494a2d8661ca5
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
XenoRAT

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 57 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.XenoRAT.C5586957
Alibaba malicious Backdoor:MSIL/Dothetuk.af82f8d6
alibabacloud malicious Rat:Win/Xenorat
ALYac malicious Gen:Variant.Ransom.Chaos.96
Antiy-AVL malicious Trojan/Win32.VBKrypt
APEX malicious Malicious
Arcabit malicious Trojan.Ransom.Chaos.96
Avast malicious Win32:MalwareX-gen [Bd]
AVG malicious Win32:MalwareX-gen [Bd]
Avira malicious BDS/W32.MalwareX
BitDefender malicious Gen:Variant.Ransom.Chaos.96
Bkav malicious W32.Malware.10A6A1A1
CAT-QuickHeal malicious Trojan.YakbeexMSIL.ZZ4
ClamAV malicious Win.Malware.Msilzilla-10023780-0
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.trojan.msil
Cylance malicious Unsafe
DeepInstinct malicious MALICIOUS
DrWeb malicious BackDoor.XenoRat.20
Elastic malicious Windows.Trojan.Xeno
Emsisoft malicious Gen:Variant.Ransom.Chaos.96 (B)
ESET-NOD32 malicious MSIL/Agent.WNX trojan
F-Secure malicious Backdoor.BDS/W32.MalwareX
Fortinet malicious MSIL/Agent.WNX!tr
GData malicious MSIL.Trojan.PSE.1MDQVCF
Google malicious Detected
Gridinsoft malicious Trojan.Win32.Agent.dd!ni
huorong malicious Trojan/MSIL.Agent.dj
K7AntiVirus malicious Trojan ( 005b11ae1 )
K7GW malicious Trojan ( 005acc631 )
Kaspersky malicious HEUR:Backdoor.MSIL.Agent.gen
Kingsoft malicious malware.kb.c.993
Lionic malicious Trojan.Win32.XenoRAT.m!c
Malwarebytes malicious Backdoor.XenoRAT
MaxSecure malicious Trojan.Malware.121218.susgen
McAfeeD malicious Real Protect-LS!8F967A1D8F35
Microsoft malicious Trojan:MSIL/Dothetuk!atmn
MicroWorld-eScan malicious Gen:Variant.Ransom.Chaos.96
Paloalto malicious generic.ml
Panda malicious Trj/CI.A
Rising malicious Backdoor.XenoRAT!1.134EF (CLASSIC)
Sangfor malicious Trojan.Win32.Save.a
SentinelOne malicious Static AI - Malicious PE
Skyhigh malicious XenoRAT!8F967A1D8F35
Sophos malicious Mal/RAT-C
Symantec malicious ML.Attribute.HighConfidence
Tencent malicious Backdoor.Msil.Agent.16001498
TrellixENS malicious XenoRat!8F967A1D8F35
TrendMicro malicious Backdoor.MSIL.XENORAT.SMTPTMA
TrendMicro-HouseCall malicious Backdoor.MSIL.XENORAT.SMTPTMA
Varist malicious W32/MSIL_Agent.HBX.gen!Eldorado
VBA32 malicious Backdoor.MSIL.Xeno.Heur
VIPRE malicious Gen:Variant.Ransom.Chaos.96
VirIT malicious Trojan.Win32.MSIL_Heur.A
ViRobot malicious Trojan.Win.Z.Agent.46592.DGU
Webroot malicious W32.Trojan.Gen
ZoneAlarm malicious Mal/RAT-C

Details From VirusTotal

Basic Properties
MD58f967a1d8f355d4a2c7bb64d04291ed8
SHA-1f336e25759c34dd29dd975466c099877411c8c15
SHA-256cb5e0d435fbad026262192e4ded328eba2952f35433412cba4d494a2d8661ca5
VHash24403655151130b524b2083a
SSDEEP768:IkthM/poiioOlJInyCrIMx9Xqk5nWEZ5SbTDawjI7CPW5p:b2+rgnZ0E9XqcnW85SbTtjIx
TLSHT1B923F84C5BAC8927E6AF1ABD9832425387B3F3669532E38F08CCD4E9379339554053A7
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size45.5 KB
History
Creation date2104-06-27 07:24 UTC
First seen on VirusTotal2026-05-14 20:50 UTC
Last submission2026-05-14 21:16 UTC
Last analysis2026-06-27 06:01 UTC
Last modified on VirusTotal2026-06-27 08:06 UTC
Known Names
  • Xeno_manager.exe
  • xeno rat client.exe
  • cb5e0d435fbad026262192e4ded328eba2952f35433412cba4d494a2d8661ca5.exe
  • au88.exe
  • _cb5e0d435fbad026262192e4ded328eba2952f35433412cba4d494a2d8661ca5.exe
  • 1h6bv.exe
hash_sha1 f336e25759c34dd29dd975466c099877411c8c15 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/f336e25759c34dd29dd975466c099877411c8c15
1 feed

IOC database

Type
hash_sha1
Value
f336e25759c34dd29dd975466c099877411c8c15
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/f336e25759c34dd29dd975466c099877411c8c15

hash_md5 8f967a1d8f355d4a2c7bb64d04291ed8 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/8f967a1d8f355d4a2c7bb64d04291ed8
1 feed

IOC database

Type
hash_md5
Value
8f967a1d8f355d4a2c7bb64d04291ed8
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/8f967a1d8f355d4a2c7bb64d04291ed8

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 46592 bytes. Tags: c2, dcrat, exe, rat, windows, XenoRAT. Reporter: anonymous. First seen: 2026-05-14 20:52:38.

Remediations (10)

  • web:any.run

    Xeno RAT is an open-source malware mainly distributed through drive-by downloads. The core capabilities of this threat include remote control, keystroke logging, webcam and microphone access. Equipped with advanced utilities, such as Hidden Virtual Network Computing and Socks5 reverse proxy, Xeno RAT is most frequently used in attacks against individual users.

  • web:authenticone.com

    Learn about the Xenorat malware campaign, its infection chain, technical analysis, and its indicators of compromises.

  • web:cert.by

    XenoRat features and functionality expansion mechanism During the analysis of the XenoRat malware, it was found that by default the tool has a wide range of remote administration functions, including:

  • web:community.emergingthreats.net

    Hi, I found traffic from XenoRAT and propose to detect it based on the content of the first 117 byte packet plus 21 bytes packet in stream. alert tcp any any -> any any (msg: "ET MALWARE [ANY.RUN] Xeno-RAT TCP Check-In…

  • web:hunt.io

    XenoRAT is an open-source remote access trojan (RAT) developed in C#. It provides advanced capabilities such as remote control, keystroke logging, and webcam or microphone access. Initially distributed on GitHub, XenoRAT has been used both by ethical security researchers and malicious actors. Recent campaigns have seen the malware distributed through Excel XLL files, improving its ability to ...

  • web:medium.com

    Xeno Rat — Basic Malware Analysis In this post I'll be providing a really quick and basic malware analysis of Xeno Rat. If you don't recognize the name, that's fine, Xeno Rat is like the ...

  • web:thehackernews.com

    Xeno RAT, a new player in the malware scene, boasts alarming features for remote system exploitation. Learn more about its impact on Windows systems.

  • web:threatfox.abuse.ch

    ThreatFox Database Indicators of Compromise (IOCs) on ThreatFox are associated with a certain malware fas. A malware sample can be associated with only one malware family. The page below gives you an overview on indicators of compromise associated with win. xenorat . You can also get this data through the ThreatFox API. Database Entry

  • web:www.activecountermeasures.com

    What is Malware of the Day? Lab Setup Malware: XenoRAT MITRE Tactics: TA0011 Command and Control , T1571 Non-Standard Port Traffic Type: TCP Connection Type: Reverse TCP C2 Platform: XenoRAT Origin of Sample: Active Countermeasures Lab Host Payload Delivery Method: EXE binary (C2 implant) Target Host/Victim: 192.168.2.77 (Windows 10 Pro x64) C2 Server: 172.208.51.75 Beacon Timing: none Jitter ...

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.