Is Xeno-v1.3.60 (1).zip safe?
Four high-trust engines identify unwanted-software traits, while observed DLL execution and process-injection indicators make this Xeno archive unsuitable for routine use.
The archive drew 11 detections among 75 engines, including four high-trust PUA or adware findings led by Microsoft’s Vigua label. One sandbox did not issue a malware finding, but temporary-directory DLL execution and T1055, T1560, and T1562.001 activity create material risk.
42755d7735ab3eabc7…e4af4b1b39f913Recommended next actions
Before opening or extracting
Do not open or extract it until the source can be verified independently.
If you already opened or extracted it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the original trusted source and verify its exact hash when possible.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The archive drew 11 detections among 75 engines, including four high-trust PUA or adware findings led by Microsoft’s Vigua label. One sandbox did not issue a malware finding, but temporary-directory DLL execution and T1055, T1560, and T1562.001 activity create material risk.
Microsoft, DrWeb, Ikarus, and Sophos independently flag the archive as Vigua, downware, or another potentially unwanted application. Their labels do not form strong agreement on one family, but four high-trust detections cannot be dismissed as a low-quality false-positive pattern. Runtime observation recorded rundll32 loading multiple DLLs from a temporary Xeno directory and mapped activity to process injection, archive collection, and defense impairment techniques. The completed sandbox did not issue a malware finding, the fully covered observed domain had no cached risk hit, and no inspected child was identified as malicious. Those counter-signals lower confidence in a conventional trojan diagnosis, but they do not sufficiently offset the high-trust PUA findings and offensive runtime indicators.
What We Detected
Eleven of 75 antivirus engines flagged the archive. Four high-trust engines participated: Microsoft reported PUA:Win32/Vigua.A, DrWeb reported Adware.Downware.20251, Ikarus reported PUA.Win32.Packunwan, and Sophos reported Generic Reputation PUA. The labels primarily describe potentially unwanted software or adware rather than a consistently named conventional trojan.
Threat Behavior
One completed runtime observation recorded multiple rundll32 launches loading DLLs from a temporary Xeno directory. The saved evidence maps activity to T1055 process injection, T1560 archive collection, and T1562.001 defense impairment. The sandbox itself returned a clean assessment, and the observed domain x3no.pages.dev received no malicious or suspicious result from the complete host-cache check. Ten children were inspected, but only two had conclusive benign results and eight remained unknown.
What To Do Now
Do not run or extract this archive on a production system. Keep endpoint protection enabled, remove the file unless it came from a verified official release channel, and use an isolated analysis environment if examination is necessary.
Where this verdict could be wrong4 caveats
- The single completed sandbox returned a clean verdict, so runtime evidence did not independently identify malware.
- Thirteen of 17 tier-1 engines did not flag the sample, and engines.tier1FamilyConsensus.strong=false.
- MalwareBazaar returned no hit and YARAify returned 0 rules; these absences may reflect intelligence-coverage gaps.
- The archive has medium prevalence with 3,680 submitters and 10,144 submissions, which is less consistent with a narrowly distributed payload.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- One completed sandbox issued no malware finding
- No inspected child was identified as malicious
- The observed domain received no malicious or suspicious host-cache hit
- YARAify returned 0 matching rules
- Medium prevalence across 3,680 submitters
- 11/75 antivirus detections
- Four high-trust engine detections
- Microsoft Vigua PUA identification
- T1055 process-injection mapping
- T1562.001 defense-impairment mapping
- rundll32 loaded DLLs from a temporary directory
Quarantine or delete the archive unless its origin and release integrity can be independently verified. Keep security protection enabled and avoid executing its contents outside an isolated test environment.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete11 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 of 2 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 21MITRE ATT&CK techniques
- 15spawned processes
- 2network contacts
- 40filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Attempted to impair or bypass security controls.
High concern: Manipulated how the operating system loads code, which can redirect execution.
Moderate concern: Runs hidden system commands (script or shell).
Moderate concern: Removed execution artefacts or logs, which can conceal activity.
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Scans through your files and folders.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
Xeno-v1.3.60 (1).zip
42755d7735ab3eabc7fac074eb5e631212f4df02c6de60ec8de4af4b1b39f913
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\Xeno-v1.3.60/api-ms-win-crt-convert-l1-1-0.dll",#1
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\Xeno-v1.3.60/api-ms-win-crt-environment-l1-1-0.dll",#1
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
Temp
C:\ProgramData\Microsoft\Windows\WER\Temp
04Isolated runtime analysis - Written fileObserved
73f20179-bcc0-4d13-a599-ea77feb61462
C:\ProgramData\Microsoft\Windows\WER\Temp\73f20179-bcc0-4d13-a599-ea77feb61462
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
x3no.pages.dev
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostObserved
172.66.47.131
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- x3no.pages.dev
- 172.66.47.131
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Script\Settings\Telemetry\wscript.exe\JScriptSetScriptStateStarted
- C:\ProgramData\Microsoft\Windows\WER\Temp
- C:\ProgramData\Microsoft\Windows\WER\Temp\73f20179-bcc0-4d13-a599-ea77feb61462
- C:\ProgramData\Microsoft\Windows\WER\ReportQueue
- C:\ProgramData\Microsoft\Windows\WER\Temp\b6ae1403-aa70-4566-af1f-406f8cc1c444
- C:\ProgramData\Microsoft\Windows\WER\ReportArchive
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERE38A.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERE9B5.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WEREB9A.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERE38A.tmp.dmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WERE9B5.tmp.WERInternalMetadata.xml
- Local\WERReportingForProcess3408
- Global\c9a4f8ae-17f4-4cc4-8552-41f9fad10f8a
- Local\WERReportingForProcess5612
- Global\f8b11a15-d28e-4b5d-ad62-6c68965ff32a
- Local\WERReportingForProcess6416
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- f7c6c7ea22edd2f8bd07…f91dc1Never scannednever seen before
- 9d16d62878486d6caad6…4b3a3dClean0/75 enginestrust 84from our cache
- 2a466648affd3d51b944…1fc1b3Never scannednever seen before
- 7d3b114326103db72409…acdccfClean0/74 enginestrust 94from our cache
- 465a7ddfb3a0da4c3965…ea0a6fNever scannednever seen before
- 4fe2c4420294758883e1…62653cNever scannednever seen before
- 43e332faef4019a95d3b…55dad2Never scannednever seen before
- 615824c59ed1e07f5924…839451Never scannednever seen before
- 84425efa675012d33433…6803d3Never scannednever seen before
- 51541ec6684b43157a85…01318dNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 11 / 75engines flagged
- 3,680sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
11 of 75 antivirus engines flagged the file, including DrWeb and Google.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has been submitted 10,144 times from 3,680 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: Xeno-v1.3.60 (1).zip — 42755d7735ab3eabc7fac074eb5e631212f4df02c6de60ec8de4af4b1b39f913
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\Xeno-v1.3.60/api-ms-win-crt-convert-l1-1-0.dll",#1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\Xeno-v1.3.60/api-ms-win-crt-environment-l1-1-0.dll",#1
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: Temp — C:\ProgramData\Microsoft\Windows\WER\Temp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: 73f20179-bcc0-4d13-a599-ea77feb61462 — C:\ProgramData\Microsoft\Windows\WER\Temp\73f20179-bcc0-4d13-a599-ea77feb61462
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: x3no.pages.dev — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: 172.66.47.131 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
Category: pua
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
Evidence"C:\Windows\system32\rundll32.exe" "C:\Users\<USER>\AppData\Local\Temp\Xeno-v1.3.60/api-ms-win-crt-convert-l1-1-0.dll",#1
11 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- Xeno-v1.3.60 (1).zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 6.8 MB
- Last analyzed
- Oct 7, 2026, 9:55 AM UTC
42755d7735ab3eabc7fac074eb5e631212f4df02c6de60ec8de4af4b1b39f913Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
- Recovery step 01
Don't open or extract it unless you're certain it came from a source you trust.
- Recovery step 02
Check where you got it — an unexpected attachment or a random download link is a red flag.
- Recovery step 03
If its origin cannot be confirmed, delete this archive and use a fresh copy from a trusted source. Get a fresh copy from the original trusted source and verify its exact hash when possible.
- Recovery step 04
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Xeno-v1.3.60 (1).zip safe, or is it malware?
What is Xeno-v1.3.60 (1).zip?
How many antivirus engines detected Xeno-v1.3.60 (1).zip?
What should I do if I already opened or extracted Xeno-v1.3.60 (1).zip?
How do I remove Xeno-v1.3.60 (1).zip?
What kind of malware is Xeno-v1.3.60 (1).zip?
What is the SHA-256 hash of Xeno-v1.3.60 (1).zip?
How up to date is this analysis of Xeno-v1.3.60 (1).zip?
Community
Member reviews and reports for this exact file hash.