File name:

bootskin_free.exe

Full analysis: https://app.any.run/tasks/049eab75-8024-4d06-a4bd-95e604cd2e35
Verdict: Malicious activity
Analysis date: May 25, 2025, 18:27:52
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

496735BA53F15AFBA30233C7C1B11E13

SHA1:

66DF0DA35A8567F3F1387716DBD152A3F9C6B3B4

SHA256:

8EFD264263CA146CACC03A301D2852D1FA3625228C39C6676AB620FC67054E92

SSDEEP:

49152:FthbBxbPxmhGLesRyQ8j0KHPSq191doCp8B0p3u+ts1HpQ2RqD7OdEYG9RG:F7NxbP0YCQI0KL1dbp8Op3u+ypQ2RcSl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • bootskin_free.exe (PID: 1748)
    • Searches for installed software

      • bootskin_free.exe (PID: 1748)
    • Creates a software uninstall entry

      • bootskin_free.exe (PID: 1748)
    • Creates files in the driver directory

      • bootskin_free.exe (PID: 1748)
    • Drops a system driver (possible attempt to evade defenses)

      • bootskin_free.exe (PID: 1748)
    • Reads the Internet Settings

      • bootskin_free.exe (PID: 1748)
    • Reads security settings of Internet Explorer

      • bootskin_free.exe (PID: 1748)
    • Creates or modifies Windows services

      • bootskin_free.exe (PID: 1748)
      • BootSkin.exe (PID: 3044)
    • There is functionality for taking screenshot (YARA)

      • bootskin_free.exe (PID: 1748)
      • BootSkin.exe (PID: 3044)
  • INFO

    • Checks supported languages

      • bootskin_free.exe (PID: 1748)
      • BootSkin.exe (PID: 3044)
    • The sample compiled with english language support

      • bootskin_free.exe (PID: 1748)
    • Create files in a temporary directory

      • bootskin_free.exe (PID: 1748)
    • Reads the computer name

      • bootskin_free.exe (PID: 1748)
    • Creates files in the program directory

      • bootskin_free.exe (PID: 1748)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 2948)
    • Reads the Internet Settings

      • explorer.exe (PID: 2948)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Wise Installer executable (96.9)
.dll | Win32 Dynamic Link Library (generic) (1.3)
.exe | Win32 Executable (generic) (0.9)
.exe | Generic Win/DOS Executable (0.4)
.exe | DOS Executable Generic (0.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2000:04:25 14:37:12+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, Removable run from swap
PEType: PE32
LinkerVersion: 6
CodeSize: 8704
InitializedDataSize: 5632
UninitializedDataSize: -
EntryPoint: 0x21af
OSVersion: 4
ImageVersion: 4
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows 16-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Stardock.net, Inc. www.stardock.com
FileDescription: BootSkin
FileVersion: 1.x
LegalCopyright: Stardock.net, Inc. 2003
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start bootskin_free.exe explorer.exe no specs explorer.exe no specs bootskin.exe no specs bootskin_free.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
672"C:\Windows\explorer.exe" C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinCustomizeC:\Windows\explorer.exebootskin_free.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1748"C:\Users\admin\AppData\Local\Temp\bootskin_free.exe" C:\Users\admin\AppData\Local\Temp\bootskin_free.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\bootskin_free.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2168"C:\Users\admin\AppData\Local\Temp\bootskin_free.exe" C:\Users\admin\AppData\Local\Temp\bootskin_free.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\bootskin_free.exe
c:\windows\system32\ntdll.dll
2948C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3044"C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" C:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exebootskin_free.exe
User:
admin
Integrity Level:
HIGH
Description:
Stardock BootSkin!
Version:
1, 0, 6, 0
Modules
Images
c:\program files\stardock\wincustomize\bootskin\bootskin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
5 018
Read events
4 918
Write events
97
Delete events
3

Modification events

(PID) Process:(1748) bootskin_free.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BootSkin
Operation:writeName:DisplayName
Value:
BootSkin
(PID) Process:(1748) bootskin_free.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BootSkin
Operation:writeName:UninstallString
Value:
C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\UNWISE.EXE C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\INSTALL.LOG
(PID) Process:(1748) bootskin_free.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Common Files\Stardock\ODZip.dll
Value:
1
(PID) Process:(1748) bootskin_free.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1748) bootskin_free.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1748) bootskin_free.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1748) bootskin_free.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1748) bootskin_free.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Stardock\ObjectDesktop
Operation:writeName:ODCommonFiles
Value:
C:\PROGRA~1\COMMON~1\Stardock
(PID) Process:(1748) bootskin_free.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Stardock\ObjectDesktop
Operation:writeName:ODZip
Value:
C:\PROGRA~1\COMMON~1\Stardock\odzip.dll
(PID) Process:(1748) bootskin_free.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BootScreen
Operation:writeName:Group
Value:
Boot Bus Extender
Executable files
12
Suspicious files
100
Text files
73
Unknown types
0

Dropped files

PID
Process
Filename
Type
1748bootskin_free.exeC:\Program Files\Stardock\WinCustomize\BootSkin\~GLH0001.TMPexecutable
MD5:3A938ED2427DF10E571041069E6980CB
SHA256:4751A3547F3B482BB4A2440D4E91E3DCBA9B4B0F5B1BB50416A32FB47AE75C5E
1748bootskin_free.exeC:\Users\admin\AppData\Local\Temp\~GLH0000.TMPexecutable
MD5:B9B41E50D612E00BF3A49A6405B89D74
SHA256:50E7A30E1825FAB93B94B698C2C6D2CC1787B094C6CEE53EEED5C497F77443C9
1748bootskin_free.exeC:\Users\admin\AppData\Local\Temp\GLK1DC5.tmpexecutable
MD5:3DF61E5730883B2D338ADDD7ACBE4BC4
SHA256:2EFE9A54C8EB878711D9B6CD18F276838645AFF52FE69D8A864376CB258EC616
1748bootskin_free.exeC:\Program Files\Stardock\WinCustomize\BootSkin\~GLH0002.TMPexecutable
MD5:998492D3C53EEF257308C016AC9DD825
SHA256:22F45F5366BB6B14FE12187C97AB96C1C4FD93EDD2B46F4DA7D13D44E589A245
1748bootskin_free.exeC:\Program Files\Stardock\WinCustomize\BootSkin\BootSkin.exeexecutable
MD5:998492D3C53EEF257308C016AC9DD825
SHA256:22F45F5366BB6B14FE12187C97AB96C1C4FD93EDD2B46F4DA7D13D44E589A245
1748bootskin_free.exeC:\Program Files\Stardock\WinCustomize\BootSkin\~GLH0004.TMPtext
MD5:0765402CC5637DCC74DB267AC3627DA4
SHA256:873270B63FB67A1EEACD6D939E57D391104EDEE82CF0A47C20750D4EE6C5D5FE
1748bootskin_free.exeC:\Program Files\Stardock\WinCustomize\BootSkin\~GLH0003.TMPtext
MD5:39DA5AD27749FE8356A57F8A63F2CD7E
SHA256:5A7AE7565A37BE63D96D073A03EBBF3E9E82534DD2DEA24D114B5F4409B1C88F
1748bootskin_free.exeC:\Program Files\Stardock\WinCustomize\BootSkin\eula.txttext
MD5:39DA5AD27749FE8356A57F8A63F2CD7E
SHA256:5A7AE7565A37BE63D96D073A03EBBF3E9E82534DD2DEA24D114B5F4409B1C88F
1748bootskin_free.exeC:\Program Files\Stardock\WinCustomize\BootSkin\readme.txttext
MD5:0765402CC5637DCC74DB267AC3627DA4
SHA256:873270B63FB67A1EEACD6D939E57D391104EDEE82CF0A47C20750D4EE6C5D5FE
1748bootskin_free.exeC:\Windows\System32\drivers\~GLH0005.TMPexecutable
MD5:D9393B767A3BDEE076C123D03F2E233B
SHA256:856815C615C6EA77E56B28B7D39EE076A42AF5B762C327213080397531AC0062
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.212.142
whitelisted

Threats

No threats detected
No debug info