File name:

LiteSkinUtils.dll

Full analysis: https://app.any.run/tasks/a04a14ce-6dcb-45d8-8ddc-265b679a1003
Verdict: Malicious activity
Analysis date: April 16, 2024, 19:13:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
MIME: application/x-dosexec
File info: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
MD5:

059D94E8944ECA4056E92D60F7044F14

SHA1:

46A491ABBBB434B6A1A2A1B1A793D24ACD1D6C4B

SHA256:

9FA7CACB5730FAACC2B17D735C45EE1370130D863C3366D08EC013AFE648BFA6

SSDEEP:

1536:gfeTndjhwbPMHbXTiGwTJq1qmz0HDYMU8u+ybAv:gfeTndjhwbPMHbXTiGwTJq1q3E+ybAv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • rundll32.exe (PID: 2108)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • filezilla.exe (PID: 3904)
  • INFO

    • Checks supported languages

      • filezilla.exe (PID: 3904)
    • Reads the computer name

      • filezilla.exe (PID: 3904)
    • Reads the machine GUID from the registry

      • filezilla.exe (PID: 3904)
    • Manual execution by a user

      • filezilla.exe (PID: 3904)
    • Creates files or folders in the user directory

      • filezilla.exe (PID: 3904)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2003:06:26 18:57:17+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, 32-bit, DLL
PEType: PE32
LinkerVersion: 6
CodeSize: 28160
InitializedDataSize: 20480
UninitializedDataSize: -
EntryPoint: 0x61ff
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.1
ProductVersionNumber: 1.0.0.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: -
FileDescription: SkinUtils DLL
FileVersion: 1, 0, 0, 1
InternalName: SkinUtils
LegalCopyright: Copyright (C) 2002
LegalTrademarks: -
OriginalFileName: SkinUtils.DLL
ProductName: SkinUtils Dynamic Link Library
ProductVersion: 1, 0, 0, 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
3
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start rundll32.exe no specs Shell Security Editor no specs filezilla.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2108"C:\Windows\System32\rundll32.exe" C:\Users\admin\AppData\Local\Temp\LiteSkinUtils.dll, #1C:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3044C:\Windows\system32\DllHost.exe /Processid:{4D111E08-CBF7-4F12-A926-2C7920AF52FC}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3904"C:\Program Files\FileZilla FTP Client\filezilla.exe" C:\Program Files\FileZilla FTP Client\filezilla.exeexplorer.exe
User:
admin
Company:
FileZilla Project
Integrity Level:
MEDIUM
Description:
FileZilla FTP Client
Exit code:
0
Version:
3, 65, 0, 0
Modules
Images
c:\program files\filezilla ftp client\filezilla.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\filezilla ftp client\libfzclient-commonui-private-3-65-0.dll
c:\program files\filezilla ftp client\libfzclient-private-3-65-0.dll
c:\program files\filezilla ftp client\libfilezilla-40.dll
c:\program files\filezilla ftp client\libgmp-10.dll
c:\windows\system32\msvcrt.dll
c:\program files\filezilla ftp client\libgcc_s_dw2-1.dll
Total events
3 986
Read events
3 986
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
30
Unknown types
0

Dropped files

PID
Process
Filename
Type
3904filezilla.exeC:\Users\admin\AppData\Roaming\FileZilla\layout.xml~xml
MD5:
SHA256:
3904filezilla.exeC:\Users\admin\AppData\Roaming\FileZilla\layout.xmlxml
MD5:
SHA256:
3904filezilla.exeC:\Users\admin\AppData\Local\FileZilla\default_leds24x24.pngimage
MD5:
SHA256:
3904filezilla.exeC:\Users\admin\AppData\Local\FileZilla\default_speedlimits16x16.pngimage
MD5:
SHA256:
3904filezilla.exeC:\Users\admin\AppData\Local\FileZilla\default_sitemanager20x20.pngimage
MD5:
SHA256:
3904filezilla.exeC:\Users\admin\AppData\Local\FileZilla\default_logview20x20.pngimage
MD5:
SHA256:
3904filezilla.exeC:\Users\admin\AppData\Local\FileZilla\default_localtreeview20x20.pngimage
MD5:
SHA256:
3904filezilla.exeC:\Users\admin\AppData\Local\FileZilla\default_remotetreeview20x20.pngimage
MD5:
SHA256:
3904filezilla.exeC:\Users\admin\AppData\Local\FileZilla\default_queueview20x20.pngimage
MD5:
SHA256:
3904filezilla.exeC:\Users\admin\AppData\Local\FileZilla\default_refresh20x20.pngimage
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info