Classification: Malicious
ext-cs2-skin-changer.exe is a malicious file sample. Reported by 3 threat sources, last seen 2026-09-02. Detected by 42 antivirus engines.
Detection summary
- 42 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2026-07-10 15:45:06 |
2026-09-02 12:45:04 |
malicious-activity
|
|
| Generic Malware |
Cyber Threat Alliance |
2026-08-18 17:00:43 |
2026-08-18 17:00:43 |
malicious-activity
|
|
| Generic Malware |
Triage |
2026-03-15 05:28:21 |
2026-03-15 05:28:21 |
malicious-activity
|
|
Sample information
- Filenames
- ext-cs2-skin-changer.exe, 2026-03-15_3d43bc6afb2d10a0b5446c7064e53aec_cobalt-strike_icedid_luca-stealer_njrat_stealc
- File type
- PE32+ executable for MS Windows 6.00 (console), x8 ...
- MD5
3d43bc6afb2d10a0b5446c7064e53aec
- SHA-1
8ed278d132e148f1afb51e1ace26d21b729e9ccf
- SHA-256
b3268f8b97c41ba71d9b81c39106732138f5f78279b7d1bf332cc5425b94e698
- SHA-512
4a1a863bb09508eaf507b4a8272f2f6269af2a1e13099745185ffe19cf97b5f4ad039cbb4f01f95a14e0e18de8ee6332102878e277c86ce6eac2fd628c91f97c
- First indexed
- 2026-03-15 05:28:21
- Last updated
- 2026-08-18 17:00:43
Antivirus detections
| Engine | Detection |
| ALYac | Gen:Variant.Application.Tedy.11863 |
| AVG | Win64:MalwareX-gen [Misc] |
| AhnLab-V3 | Malware/Win.Tedy.R761262 |
| Antiy-AVL | RiskWare/Win64.Gamehack |
| Arcabit | Trojan.Application.Tedy.D2E57 |
| Avast | Win64:MalwareX-gen [Misc] |
| Avira | TR/W64.Agent |
| BitDefender | Gen:Variant.Application.Tedy.11863 |
| CTX | exe.trojan.tedy |
| CrowdStrike | win/malicious_confidence_70% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| ESET-NOD32 | Win64/GameHack.YC potentially unsafe application |
| Elastic | malicious (moderate confidence) |
| Emsisoft | Gen:Variant.Application.Tedy.11863 (B) |
| F-Secure | Trojan.TR/W64.Agent |
| Fortinet | Adware/GameHack_AGen |
| GData | Gen:Variant.Application.Tedy.11863 |
| Google | Detected |
| Gridinsoft | Hack.Win64.GameHack.oa!s1 |
| K7AntiVirus | Unwanted-Program ( 006d8a691 ) |
| K7GW | Unwanted-Program ( 006d8a691 ) |
| Lionic | Trojan.Win32.GameHack.4!c |
| Malwarebytes | RiskWare.GameHack |
| MaxSecure | Trojan.Malware.585697978.susgen |
| McAfeeD | ti!B3268F8B97C4 |
| MicroWorld-eScan | Gen:Variant.Application.Tedy.11863 |
| Microsoft | Trojan:Win32/Kepavll!rfn |
| Paloalto | generic.ml |
| Panda | Trj/GdSda.A |
| Sangfor | Trojan.Win32.Save.a |
| Sophos | Generic Reputation PUA (PUA) |
| Symantec | ML.Attribute.HighConfidence |
| Trapmine | suspicious.low.ml.score |
| TrellixENS | Artemis!3D43BC6AFB2D |
| TrendMicro | Trojan.Win32.ZYX.USBLEO26 |
| TrendMicro-HouseCall | Trojan.Win32.ZYX.USBLEO26 |
| VBA32 | Trojan.Kepavll |
| VIPRE | Gen:Variant.Application.Tedy.11863 |
| Varist | W64/ABApplication.MAHK-6524 |
| ViRobot | PUP.Tedy.946688 |
| Zillya | Trojan.GameHackAGen.Win64.7579 |