File name:

SkyVPNSetup-official.exe

Full analysis: https://app.any.run/tasks/31fd2864-c6c3-4030-af84-229a754a1ef3
Verdict: Malicious activity
Analysis date: February 13, 2024, 21:49:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

66056B58020EDE859C4A55F353385B56

SHA1:

6C736CBEB439A12A75BC966175A2C4375426C231

SHA256:

F770862FD4F2AE86D66E9D6768A17BCDF0F85CAB09B5F27475F865E5710F2D68

SSDEEP:

196608:+w5KLjH4osXZQepRFP7m//zarN9Nt+4yb4hNQhoPt4lVniJo65iMQkt:+wCjHQXOepRd6Xzah9Nt0b4bQuPwY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • SkyVPNSetup-official.exe (PID: 3944)
      • SkyVPNSetup-official.tmp (PID: 3228)
      • tap-windows-9.21.2.exe (PID: 3964)
      • tapinstall.exe (PID: 2792)
      • drvinst.exe (PID: 2168)
      • drvinst.exe (PID: 2576)
    • Creates a writable file in the system directory

      • drvinst.exe (PID: 2168)
      • drvinst.exe (PID: 2576)
    • Changes the autorun value in the registry

      • SkyVPNSetup-official.tmp (PID: 3228)
      • drvinst.exe (PID: 2576)
  • SUSPICIOUS

    • The process drops C-runtime libraries

      • SkyVPNSetup-official.tmp (PID: 3228)
    • Reads the Windows owner or organization settings

      • SkyVPNSetup-official.tmp (PID: 3228)
    • Executable content was dropped or overwritten

      • SkyVPNSetup-official.tmp (PID: 3228)
      • SkyVPNSetup-official.exe (PID: 3944)
      • tap-windows-9.21.2.exe (PID: 3964)
      • tapinstall.exe (PID: 2792)
      • drvinst.exe (PID: 2168)
      • drvinst.exe (PID: 2576)
    • Process drops legitimate windows executable

      • SkyVPNSetup-official.tmp (PID: 3228)
    • Drops a system driver (possible attempt to evade defenses)

      • SkyVPNSetup-official.tmp (PID: 3228)
      • tap-windows-9.21.2.exe (PID: 3964)
      • tapinstall.exe (PID: 2792)
      • drvinst.exe (PID: 2168)
      • drvinst.exe (PID: 2576)
    • Adds/modifies Windows certificates

      • CertMgr.Exe (PID: 1696)
      • CertMgr.Exe (PID: 120)
      • tapinstall.exe (PID: 2792)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • tap-windows-9.21.2.exe (PID: 3964)
    • Starts application with an unusual extension

      • tap-windows-9.21.2.exe (PID: 3964)
    • Reads security settings of Internet Explorer

      • tapinstall.exe (PID: 2792)
      • skyvpn.exe (PID: 1232)
      • skyvpn.exe (PID: 3320)
    • Checks Windows Trust Settings

      • tapinstall.exe (PID: 2792)
      • drvinst.exe (PID: 2168)
      • drvinst.exe (PID: 2576)
    • Reads settings of System Certificates

      • tapinstall.exe (PID: 2792)
    • The process creates files with name similar to system file names

      • tap-windows-9.21.2.exe (PID: 3964)
    • Creates files in the driver directory

      • drvinst.exe (PID: 2168)
      • drvinst.exe (PID: 2576)
    • Executes as Windows Service

      • VSSVC.exe (PID: 2184)
    • Creates a software uninstall entry

      • tap-windows-9.21.2.exe (PID: 3964)
    • Searches for installed software

      • SkyVPNSetup-official.tmp (PID: 3228)
      • skyvpn.exe (PID: 1232)
      • skyvpn.exe (PID: 3320)
    • Reads the Internet Settings

      • skyvpn.exe (PID: 1232)
      • skyvpn.exe (PID: 3320)
    • Process uses IPCONFIG to clear DNS cache

      • skyvpn.exe (PID: 1232)
      • skyvpn.exe (PID: 3320)
    • Suspicious use of NETSH.EXE

      • skyvpn.exe (PID: 1232)
      • skyvpn.exe (PID: 3320)
    • Detected use of alternative data streams (AltDS)

      • skyvpn.exe (PID: 1232)
      • skyvpn.exe (PID: 3320)
    • Connects to unusual port

      • skyvpn.exe (PID: 1232)
  • INFO

    • Create files in a temporary directory

      • SkyVPNSetup-official.exe (PID: 3944)
      • SkyVPNSetup-official.tmp (PID: 3228)
      • tap-windows-9.21.2.exe (PID: 3964)
      • tapinstall.exe (PID: 2792)
      • skyvpn.exe (PID: 3320)
    • Checks supported languages

      • SkyVPNSetup-official.tmp (PID: 3228)
      • SkyVPNSetup-official.exe (PID: 3944)
      • CertMgr.Exe (PID: 120)
      • CertMgr.Exe (PID: 1696)
      • tap-windows-9.21.2.exe (PID: 3964)
      • tapinstall.exe (PID: 2892)
      • tapinstall.exe (PID: 2792)
      • nsA8E0.tmp (PID: 2756)
      • drvinst.exe (PID: 2168)
      • drvinst.exe (PID: 2576)
      • skyvpn.exe (PID: 1232)
      • nsA862.tmp (PID: 3940)
      • wmpnscfg.exe (PID: 1956)
      • wmpnscfg.exe (PID: 3524)
      • wmpnscfg.exe (PID: 3396)
      • wmpnscfg.exe (PID: 1040)
      • wmpnscfg.exe (PID: 2408)
      • wmpnscfg.exe (PID: 1768)
      • wmpnscfg.exe (PID: 2768)
      • skyvpn.exe (PID: 3320)
      • wmpnscfg.exe (PID: 2384)
      • wmpnscfg.exe (PID: 1924)
      • wmpnscfg.exe (PID: 3180)
      • wmpnscfg.exe (PID: 3788)
      • wmpnscfg.exe (PID: 3312)
    • Reads the machine GUID from the registry

      • SkyVPNSetup-official.tmp (PID: 3228)
      • tapinstall.exe (PID: 2792)
      • drvinst.exe (PID: 2168)
      • drvinst.exe (PID: 2576)
      • skyvpn.exe (PID: 1232)
      • skyvpn.exe (PID: 3320)
    • Creates files in the program directory

      • SkyVPNSetup-official.tmp (PID: 3228)
      • tap-windows-9.21.2.exe (PID: 3964)
    • Creates a software uninstall entry

      • SkyVPNSetup-official.tmp (PID: 3228)
    • Reads the computer name

      • SkyVPNSetup-official.tmp (PID: 3228)
      • tap-windows-9.21.2.exe (PID: 3964)
      • tapinstall.exe (PID: 2892)
      • tapinstall.exe (PID: 2792)
      • drvinst.exe (PID: 2168)
      • drvinst.exe (PID: 2576)
      • skyvpn.exe (PID: 1232)
      • wmpnscfg.exe (PID: 3524)
      • wmpnscfg.exe (PID: 1956)
      • wmpnscfg.exe (PID: 3396)
      • wmpnscfg.exe (PID: 1040)
      • wmpnscfg.exe (PID: 2408)
      • wmpnscfg.exe (PID: 1768)
      • skyvpn.exe (PID: 3320)
      • wmpnscfg.exe (PID: 2384)
      • wmpnscfg.exe (PID: 1924)
      • wmpnscfg.exe (PID: 3312)
      • wmpnscfg.exe (PID: 3180)
      • wmpnscfg.exe (PID: 3788)
      • wmpnscfg.exe (PID: 2768)
    • Reads the software policy settings

      • tapinstall.exe (PID: 2792)
      • drvinst.exe (PID: 2168)
      • drvinst.exe (PID: 2576)
    • Reads Environment values

      • drvinst.exe (PID: 2576)
    • Creates files or folders in the user directory

      • skyvpn.exe (PID: 1232)
      • skyvpn.exe (PID: 3320)
    • Process checks computer location settings

      • skyvpn.exe (PID: 1232)
      • skyvpn.exe (PID: 3320)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1956)
      • wmpnscfg.exe (PID: 3524)
      • wmpnscfg.exe (PID: 3396)
      • wmpnscfg.exe (PID: 1040)
      • wmpnscfg.exe (PID: 2408)
      • wmpnscfg.exe (PID: 2384)
      • wmpnscfg.exe (PID: 1768)
      • skyvpn.exe (PID: 3204)
      • skyvpn.exe (PID: 3320)
      • wmpnscfg.exe (PID: 1924)
      • wmpnscfg.exe (PID: 3312)
      • wmpnscfg.exe (PID: 3180)
      • wmpnscfg.exe (PID: 3788)
      • wmpnscfg.exe (PID: 2768)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37888
InitializedDataSize: 28160
UninitializedDataSize: -
EntryPoint: 0x9c14
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2022.5.26.222
ProductVersionNumber: 2022.5.26.222
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Talktone, Inc.
FileDescription: SkyVPN Setup
FileVersion: 2022.05.26.222
LegalCopyright: Copyright 2019 Talktone,Inc.
ProductName: SkyVPN
ProductVersion: 0.9.27
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
126
Monitored processes
53
Malicious processes
9
Suspicious processes
0

Behavior graph

Click at the process to see the details
start skyvpnsetup-official.exe skyvpnsetup-official.tmp certmgr.exe no specs certmgr.exe no specs tap-windows-9.21.2.exe nsa862.tmp no specs tapinstall.exe no specs nsa8e0.tmp no specs tapinstall.exe drvinst.exe vssvc.exe no specs drvinst.exe skyvpn.exe ipconfig.exe no specs netsh.exe wmpnscfg.exe no specs netsh.exe no specs ipconfig.exe no specs ipconfig.exe no specs wmpnscfg.exe no specs netsh.exe wmpnscfg.exe no specs netsh.exe no specs ipconfig.exe no specs ipconfig.exe no specs wmpnscfg.exe no specs netsh.exe wmpnscfg.exe no specs netsh.exe no specs ipconfig.exe no specs ipconfig.exe no specs wmpnscfg.exe no specs netsh.exe wmpnscfg.exe no specs netsh.exe no specs ipconfig.exe no specs ipconfig.exe no specs wmpnscfg.exe no specs netsh.exe wmpnscfg.exe no specs netsh.exe no specs ipconfig.exe no specs ipconfig.exe no specs wmpnscfg.exe no specs skyvpn.exe no specs skyvpn.exe netsh.exe wmpnscfg.exe no specs netsh.exe no specs ipconfig.exe no specs ipconfig.exe no specs wmpnscfg.exe no specs skyvpnsetup-official.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Program Files\SkyVPN\driver\certmgr.exe" -add -c "C:\Program Files\SkyVPN\driver\openvpn-sha1.cer" -s -r localMachine trustedpublisherC:\Program Files\SkyVPN\driver\CertMgr.ExeSkyVPNSetup-official.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
ECM Certificate Manager
Exit code:
0
Version:
6.0.6001.17131 (longhorn_rtm.080108-2300)
Modules
Images
c:\program files\skyvpn\driver\certmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
268netsh interface ip set subinterface "18" mtu=1180C:\Windows\System32\netsh.exeskyvpn.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
844"C:\Windows\System32\ipconfig.exe" /flushdnsC:\Windows\System32\ipconfig.exeskyvpn.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
IP Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
1040"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1172"C:\Windows\System32\ipconfig.exe" /flushdnsC:\Windows\System32\ipconfig.exeskyvpn.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
IP Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
1216"C:\Windows\System32\ipconfig.exe" /flushdnsC:\Windows\System32\ipconfig.exeskyvpn.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
IP Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
1232"C:\Program Files\SkyVPN\skyvpn.exe"C:\Program Files\SkyVPN\skyvpn.exe
SkyVPNSetup-official.tmp
User:
admin
Company:
Talktone
Integrity Level:
HIGH
Description:
SkyVPN
Exit code:
0
Version:
2022.05.26.222
Modules
Images
c:\program files\skyvpn\skyvpn.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\skyvpn\log4cxx.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\odbc32.dll
1604"C:\Windows\System32\ipconfig.exe" /flushdnsC:\Windows\System32\ipconfig.exeskyvpn.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
IP Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
1612netsh interface ip set dnsservers "18" static 8.8.8.8C:\Windows\System32\netsh.exe
skyvpn.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
1696"C:\Program Files\SkyVPN\driver\certmgr.exe" -add -c "C:\Program Files\SkyVPN\driver\openvpn-sha256.cer" -s -r localMachine trustedpublisherC:\Program Files\SkyVPN\driver\CertMgr.ExeSkyVPNSetup-official.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
ECM Certificate Manager
Exit code:
0
Version:
6.0.6001.17131 (longhorn_rtm.080108-2300)
Modules
Images
c:\program files\skyvpn\driver\certmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
65 435
Read events
64 233
Write events
1 135
Delete events
67

Modification events

(PID) Process:(3228) SkyVPNSetup-official.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
9C0C000016403983C65EDA01
(PID) Process:(3228) SkyVPNSetup-official.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
C1C9884FFB707089F7E03D778717AB0817B3C971584C96F5C2046A4B66037DD0
(PID) Process:(3228) SkyVPNSetup-official.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3228) SkyVPNSetup-official.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Program Files\SkyVPN\skyvpn.exe
(PID) Process:(3228) SkyVPNSetup-official.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
F4081E2085E673E560089111E815C9DD5FE29666D2E314DBA45B0FEC72EEBBFC
(PID) Process:(3228) SkyVPNSetup-official.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{822796AC-24D2-4DE2-939B-CE3531305189}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.5.1.ee2 (a)
(PID) Process:(3228) SkyVPNSetup-official.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{822796AC-24D2-4DE2-939B-CE3531305189}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\SkyVPN
(PID) Process:(3228) SkyVPNSetup-official.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{822796AC-24D2-4DE2-939B-CE3531305189}_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\SkyVPN\
(PID) Process:(3228) SkyVPNSetup-official.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{822796AC-24D2-4DE2-939B-CE3531305189}_is1
Operation:writeName:Inno Setup: Icon Group
Value:
(Default)
(PID) Process:(3228) SkyVPNSetup-official.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{822796AC-24D2-4DE2-939B-CE3531305189}_is1
Operation:writeName:Inno Setup: User
Value:
admin
Executable files
83
Suspicious files
27
Text files
786
Unknown types
13

Dropped files

PID
Process
Filename
Type
3228SkyVPNSetup-official.tmpC:\Users\admin\AppData\Local\Temp\is-UNUQV.tmp\innocallback.dllexecutable
MD5:1C55AE5EF9980E3B1028447DA6105C75
SHA256:6AFA2D104BE6EFE3D9A2AB96DBB75DB31565DAD64DD0B791E402ECC25529809F
3228SkyVPNSetup-official.tmpC:\Users\admin\AppData\Local\Temp\is-UNUQV.tmp\_isetup\_RegDLL.tmpexecutable
MD5:0EE914C6F0BB93996C75941E1AD629C6
SHA256:4DC09BAC0613590F1FAC8771D18AF5BE25A1E1CB8FDBF4031AA364F3057E74A2
3944SkyVPNSetup-official.exeC:\Users\admin\AppData\Local\Temp\is-17AJI.tmp\SkyVPNSetup-official.tmpexecutable
MD5:83486A64D3B1B6BEDE392ED2450AD0CC
SHA256:E2002DAFFF5CD785027118BFAA2A0366A6ACCEB1776D221B544F5B8358727BFC
3228SkyVPNSetup-official.tmpC:\Users\admin\AppData\Local\Temp\is-UNUQV.tmp\bg_msgbox.pngimage
MD5:36056BE64E3F58BC701EF7DFFF89A28C
SHA256:3ECD23D3F42C2A537207A68BBF29E34C07B34300F1089533CDED1B763FDEFA86
3228SkyVPNSetup-official.tmpC:\Users\admin\AppData\Local\Temp\is-UNUQV.tmp\msvcr120.dllexecutable
MD5:6A14BBAEA1CC14C2DCF8B67DF97D0D75
SHA256:A3F5330A6AA9E1E6220934381689E52729EBA5FE41D9FA1C289F4E80F1948C6F
3228SkyVPNSetup-official.tmpC:\Users\admin\AppData\Local\Temp\is-UNUQV.tmp\botva2.dllexecutable
MD5:DD01877C71F8DBCBDD5C2A351F1D7EA7
SHA256:209EDEF5F6DDFEB93B710426A9E60E7C291A50B338FF6701475727CA60D2A9FC
3228SkyVPNSetup-official.tmpC:\Users\admin\AppData\Local\Temp\is-UNUQV.tmp\rpt.dllexecutable
MD5:7AE1430D4E741F499B2E0D9ABB0DE96D
SHA256:444D59D4240E61170DE3249E481A7572384E7BE9E3478728CDC8267EAED7196B
3228SkyVPNSetup-official.tmpC:\Users\admin\AppData\Local\Temp\is-UNUQV.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
3228SkyVPNSetup-official.tmpC:\Users\admin\AppData\Local\Temp\is-UNUQV.tmp\libeay32.dllexecutable
MD5:29E27E91C2031FEBAFA594012C433A86
SHA256:179CCDA05DCF8925D2E060412743EE8865AAD8AA1EB3BF59BAF8FB9BFEAC248B
3228SkyVPNSetup-official.tmpC:\Users\admin\AppData\Local\Temp\is-UNUQV.tmp\btn_install.pngimage
MD5:17B457F24E906004A11CF6DCA0B4B8EF
SHA256:0764B50B57637621816DF9ADB169F09F412BA1C28FBC74037641F2631BBC058B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
68
TCP/UDP connections
427
DNS requests
42
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1232
skyvpn.exe
GET
159.89.246.204:80
http://spanish.academy/
unknown
unknown
1232
skyvpn.exe
GET
165.227.220.117:80
http://spanish.academy/
unknown
unknown
1232
skyvpn.exe
GET
159.89.246.204:80
http://spanish.academy/
unknown
unknown
1232
skyvpn.exe
GET
143.244.203.155:80
http://classcraft.com/
unknown
unknown
1232
skyvpn.exe
GET
143.244.203.155:80
http://classcraft.com/
unknown
unknown
1232
skyvpn.exe
GET
165.227.220.117:80
http://spanish.academy/
unknown
unknown
1232
skyvpn.exe
GET
200
45.55.97.71:80
http://classcraft.com/
unknown
binary
441 b
unknown
1232
skyvpn.exe
GET
161.35.176.156:80
http://questclubs.net/
unknown
unknown
1232
skyvpn.exe
GET
161.35.176.156:80
http://questclubs.net/
unknown
unknown
1232
skyvpn.exe
GET
68.183.152.115:80
http://characterfirsteducation.com/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3228
SkyVPNSetup-official.tmp
143.204.205.164:443
d1u61jvzmljc3v.cloudfront.net
AMAZON-02
US
unknown
3228
SkyVPNSetup-official.tmp
143.204.205.61:443
d1u61jvzmljc3v.cloudfront.net
AMAZON-02
US
unknown
1232
skyvpn.exe
13.224.98.218:443
d1qji4igqoqucw.cloudfront.net
AMAZON-02
US
whitelisted
1232
skyvpn.exe
159.89.246.204:18869
unknown
1232
skyvpn.exe
143.244.203.155:32297
unknown
1232
skyvpn.exe
45.55.97.71:10547
unknown
1232
skyvpn.exe
165.227.220.117:53239
unknown

DNS requests

Domain
IP
Reputation
d1u61jvzmljc3v.cloudfront.net
  • 143.204.205.164
  • 143.204.205.151
  • 143.204.205.178
  • 143.204.205.61
whitelisted
d1qji4igqoqucw.cloudfront.net
  • 13.224.98.218
  • 13.224.98.53
  • 13.224.98.78
  • 13.224.98.98
whitelisted
www.microsoft.com
unknown
dm46l3i5mnhr0.cloudfront.net
  • 13.224.103.102
  • 13.224.103.43
  • 13.224.103.122
  • 13.224.103.75
whitelisted
6to4.ipv6.microsoft.com
  • 192.88.99.1
whitelisted
www.google.com
  • 172.217.16.132
whitelisted
dt-apigateway-log.dt-pn1.com
  • 18.165.183.72
  • 18.165.183.16
  • 18.165.183.54
  • 18.165.183.57
unknown

Threats

PID
Process
Class
Message
1232
skyvpn.exe
Potential Corporate Privacy Violation
POLICY [ANY.RUN] A SSH banner has been detected on a non-standard port number
Process
Message
skyvpn.exe
21:50:23.950-T1:[Keyfo]------------------------------Jucontext_t start(release) at Windows-----------------------------------
skyvpn.exe
21:50:23.950-T1:[Keyfo]Jucontext_t::Jucontext_t,context(id=0,sdk_version=0,and bin_version=1) start from thread(2)
skyvpn.exe
21:50:23.950-T1:[Keyfo]------------xclient release build(ver:1.3.5) at local date and time: Jan 4 2022 11:29:53 ------------
skyvpn.exe
21:50:23.950-T1:[Keyfo]>>>>>>>>>>> (xclient start at time of gmt(2024-2-13 21:50:23) vs local(2024-2-13 21:50:23),time ticks(1629515) <<<<<<<<<<<<<<<
skyvpn.exe
21:50:23.950-T1:[Keyfo]Jucontext::start,current status=0,site_id=0,subsite_id=0,node_id=0,process_id=0
skyvpn.exe
21:50:23.950-T1:[Keyfo]Jucontext::start,init_thread type=16 with count=1,wait_thread_to_started=1
skyvpn.exe
21:50:23.950-T1:[Keyfo]Juthread_base::Juthread_base,this(27853960) ,execute_thread(1), host-thread-id(0),cond_size=96 and cond_offset=8
skyvpn.exe
21:50:23.950-T1:[Keyfo]Jumailbox_t::Jumailbox_t,this=27842256,objectid(72057594037927937) at status(1),thread_id(0)
skyvpn.exe
21:50:23.950-T1:[Keyfo]Jusignaler_t::Jusignaler_t,m_w_handle(796).send_buffer(8192) and m_r_handle(804).recv_buffer(8192),object_id=72057594037927938
skyvpn.exe
21:50:23.950-T1:[Keyfo]Jusignaler_t::Jusignaler_t,m_w_handle(808).send_buffer(8192) and m_r_handle(812).recv_buffer(8192),object_id=72057594037927939