File name:

MetaSkins.exe

Full analysis: https://app.any.run/tasks/0b9b52a1-f255-4993-962c-7a209c791012
Verdict: Malicious activity
Analysis date: April 14, 2025, 06:38:23
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

60503419745150AA85FF9382E3674547

SHA1:

0570DFE0BC7C7CDAB792E5CC46A348C8EACFE098

SHA256:

51E0A1413546BBB9C9087F83432B289AFC34643DAAC298EDA2E63301F4874F3E

SSDEEP:

98304:xO+lCLDDfppLDOisBZoGg7Pz0jSnPug5DZ2BrB/Jn8tJI2tWxp8nre1jCiFQ/+vr:2PMt8g

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • MetaSkins.exe (PID: 2320)
    • Executable content was dropped or overwritten

      • MetaSkins.exe (PID: 2320)
    • Reads the BIOS version

      • MetaSkins.exe (PID: 2320)
    • Reads security settings of Internet Explorer

      • MetaSkins.exe (PID: 2320)
  • INFO

    • The sample compiled with english language support

      • MetaSkins.exe (PID: 2320)
    • Reads the computer name

      • MetaSkins.exe (PID: 2320)
    • Process checks whether UAC notifications are on

      • MetaSkins.exe (PID: 2320)
    • Checks supported languages

      • MetaSkins.exe (PID: 2320)
    • Reads the software policy settings

      • slui.exe (PID: 5408)
      • slui.exe (PID: 864)
    • Checks proxy server information

      • slui.exe (PID: 5408)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:04:08 22:15:21+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.44
CodeSize: 2159616
InitializedDataSize: 1353216
UninitializedDataSize: -
EntryPoint: 0x1cdaf0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
6
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start metaskins.exe sppextcomobj.exe no specs slui.exe slui.exe openwith.exe no specs metaskins.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
864"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2092C:\WINDOWS\system32\OpenWith.exe -EmbeddingC:\Windows\System32\OpenWith.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Pick an app
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\openwith.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2140"C:\Users\admin\AppData\Local\Temp\MetaSkins.exe" C:\Users\admin\AppData\Local\Temp\MetaSkins.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\metaskins.exe
c:\windows\system32\ntdll.dll
2320"C:\Users\admin\AppData\Local\Temp\MetaSkins.exe" C:\Users\admin\AppData\Local\Temp\MetaSkins.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
4294967295
Modules
Images
c:\users\admin\appdata\local\temp\metaskins.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
5244C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
5408C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
1 788
Read events
1 753
Write events
35
Delete events
0

Modification events

(PID) Process:(2320) MetaSkins.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2320) MetaSkins.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2320) MetaSkins.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2320) MetaSkins.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(2320) MetaSkins.exeKey:HKEY_CURRENT_USER\SOFTWARE\MetaSkins
Operation:writeName:WindowData
Value:
6666B83E8887873D2003000058020000
Executable files
3
Suspicious files
4
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2320MetaSkins.exeC:\Users\admin\Documents\MetaSkins\dota_files\MetaSkinsLowPolyMap.zip
MD5:
SHA256:
2320MetaSkins.exeC:\Users\admin\Documents\MetaSkins\kernel.dllexecutable
MD5:976002D5E43AB54BA33009537376ED1F
SHA256:9704AC5F492FDB9E591866CF797ABC50ED4DEB6A81204F62FDA8082214958869
2320MetaSkins.exeC:\Users\admin\Documents\MetaSkins\userdata.jsonbinary
MD5:7D6BB50D5E3CB472130B741E055AF157
SHA256:E0775BA0CB6B3417A732A6C2D3A2DBA1A7E49FD702A993F0A91E686142E64414
2320MetaSkins.exeC:\Users\admin\Documents\MetaSkins\msdia140.dllexecutable
MD5:DA3F8AC9AEEA2931C655CA33D0B4A7C4
SHA256:26295CDC39EC335323A74EE2C5D3DF238926CD4E4A53AA39CFC15232165262F2
2320MetaSkins.exeC:\Users\admin\Documents\MetaSkins\config_Dota2.jsonbinary
MD5:955B2E7C9240CB840D1F9C1EBEA3E8A1
SHA256:6EC96F94DA5CCF229647BA62C4C2B3AD93DCAFFBB6A4DEA7200FB97EA1D5DE40
2320MetaSkins.exeC:\Users\admin\Documents\MetaSkins\symsrv.dllexecutable
MD5:CAE67C24308AA631784B44096727F5C5
SHA256:51DA071BAB34ABC9DB349B471F24E06697CFA65F6F74E4CD995E09CF9E96BC35
2320MetaSkins.exeC:\Users\admin\Documents\MetaSkins\launcher.jsonbinary
MD5:98667EF98FB22756AEF1D53FA3373B92
SHA256:044E0424A65C5E87F82F282AA4A5AD0BB0C7AECE389DAF8CF7F7F216F27C425E
2320MetaSkins.exeC:\Users\admin\Documents\MetaSkins\config_CS2.jsonbinary
MD5:955B2E7C9240CB840D1F9C1EBEA3E8A1
SHA256:6EC96F94DA5CCF229647BA62C4C2B3AD93DCAFFBB6A4DEA7200FB97EA1D5DE40
2320MetaSkins.exeC:\Users\admin\Documents\MetaSkins\kernel.logtext
MD5:0C39980357938768EEA43A9ECC3FFF39
SHA256:6B4CC7425EDFAF21C5CACF7FA65E2E30B6E40F2AB13B07E058E959FA40812CD1
2320MetaSkins.exeC:\Users\admin\Documents\MetaSkins\log.txttext
MD5:A01551D03A47BFE4D1DE576721AF5888
SHA256:7BD291C422D252A4722FB50E11C3681631C0CDCD2327038FC9140AA3C3E02A57
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
40
DNS requests
26
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.216.77.16:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
756
lsass.exe
GET
200
142.250.186.99:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
756
lsass.exe
GET
200
142.250.186.99:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6388
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6388
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
2924
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.216.77.16:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
2320
MetaSkins.exe
104.21.2.85:443
api.metaskins.gg
CLOUDFLARENET
unknown
756
lsass.exe
142.250.186.99:80
c.pki.goog
GOOGLE
US
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.65:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.216.77.16
  • 23.216.77.41
  • 23.216.77.6
  • 23.216.77.18
  • 23.216.77.13
  • 23.216.77.7
  • 23.216.77.39
  • 23.216.77.15
  • 23.216.77.5
whitelisted
google.com
  • 142.250.185.206
whitelisted
api.metaskins.gg
  • 104.21.2.85
  • 172.67.186.238
unknown
c.pki.goog
  • 142.250.186.99
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.160.65
  • 40.126.32.133
  • 20.190.160.131
  • 20.190.160.2
  • 40.126.32.72
  • 40.126.32.76
  • 20.190.160.4
  • 20.190.160.67
  • 20.190.159.2
  • 40.126.31.1
  • 20.190.159.128
  • 20.190.159.131
  • 40.126.31.67
  • 20.190.159.129
  • 20.190.159.64
  • 40.126.31.2
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
www.microsoft.com
  • 23.52.120.96
whitelisted

Threats

No threats detected
No debug info