File name:

Voice.ai-Downloader.exe

Full analysis: https://app.any.run/tasks/c0b350a2-6f26-40d0-870d-68d1858c315e
Verdict: Malicious activity
Analysis date: January 25, 2025, 08:55:40
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
netreactor
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

40FFAEA0C96BC8FD1AC022ECF287980B

SHA1:

C9FF64FECEE39AA1A4F1C930D6B6AD423E1B1C14

SHA256:

100DBA151EFE66C842FDE4337857FD3DB4568C1E3EE008E412927E67ED72094E

SSDEEP:

12288:NFl/zbr+CSgb1cLlmei0PPiKGjgQ5l2yLGwNtRl5Y9zMDIBEHgdwPRM3EFtSCy+B:bl/zbr+CSgb1cLlmei0PPiKGjgSl2yLL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Create files in the Startup directory

      • VoiceAI-Installer.exe (PID: 6772)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Voice.ai-Downloader.exe (PID: 6180)
      • VoiceAI-Installer.exe (PID: 6772)
      • vc2019.exe (PID: 6920)
      • vc2019.exe (PID: 6896)
      • VoiceAI.exe (PID: 6968)
      • drvinst.exe (PID: 1688)
    • The process creates files with name similar to system file names

      • Voice.ai-Downloader.exe (PID: 6180)
      • VoiceAI-Installer.exe (PID: 6772)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • Voice.ai-Downloader.exe (PID: 6180)
      • VoiceAI-Installer.exe (PID: 6772)
    • Reads security settings of Internet Explorer

      • Voice.ai-Downloader.exe (PID: 6180)
      • VoiceAI-Installer.exe (PID: 6772)
      • VoiceAI.exe (PID: 6968)
      • VoiceAI.exe (PID: 6012)
      • VoiceAI.exe (PID: 6284)
      • VoiceAI.exe (PID: 6384)
      • VoiceAI.exe (PID: 2072)
      • VoiceAI.exe (PID: 3564)
      • VoiceAI.exe (PID: 6528)
      • VoiceAI.exe (PID: 6660)
      • VoiceAI.exe (PID: 6380)
      • VoiceAI.exe (PID: 520)
      • VoiceAI.exe (PID: 3732)
      • VoiceAI.exe (PID: 6756)
    • Checks Windows Trust Settings

      • Voice.ai-Downloader.exe (PID: 6180)
      • VoiceAI-Installer.exe (PID: 6772)
      • VoiceAI.exe (PID: 6968)
      • drvinst.exe (PID: 1688)
      • VoiceAI.exe (PID: 6012)
      • VoiceAI.exe (PID: 6284)
      • VoiceAI.exe (PID: 3564)
      • VoiceAI.exe (PID: 6528)
      • VoiceAI.exe (PID: 6384)
      • VoiceAI.exe (PID: 2072)
      • VoiceAI.exe (PID: 6660)
      • VoiceAI.exe (PID: 6380)
      • VoiceAI.exe (PID: 520)
      • VoiceAI.exe (PID: 3732)
      • VoiceAI.exe (PID: 6756)
    • There is functionality for taking screenshot (YARA)

      • Voice.ai-Downloader.exe (PID: 6180)
      • VoiceAI-Installer.exe (PID: 6772)
    • Drops a system driver (possible attempt to evade defenses)

      • VoiceAI-Installer.exe (PID: 6772)
      • VoiceAI.exe (PID: 6968)
      • drvinst.exe (PID: 1688)
    • Starts a Microsoft application from unusual location

      • vc2019.exe (PID: 6920)
    • Process drops legitimate windows executable

      • VoiceAI-Installer.exe (PID: 6772)
      • vc2019.exe (PID: 6896)
    • Searches for installed software

      • vc2019.exe (PID: 6920)
    • Creates a software uninstall entry

      • VoiceAI-Installer.exe (PID: 6772)
      • Voice.ai-Downloader.exe (PID: 6180)
    • Adds/modifies Windows certificates

      • VoiceAI.exe (PID: 6968)
    • Creates files in the driver directory

      • drvinst.exe (PID: 1688)
    • Creates or modifies Windows services

      • drvinst.exe (PID: 3984)
    • Explorer used for Indirect Command Execution

      • explorer.exe (PID: 1580)
    • Application launched itself

      • VoiceAI.exe (PID: 6012)
  • INFO

    • Checks supported languages

      • Voice.ai-Downloader.exe (PID: 6180)
      • VoiceAI-Installer.exe (PID: 6772)
      • vc2019.exe (PID: 6920)
      • VoiceAI.exe (PID: 6968)
      • vc2019.exe (PID: 6896)
      • drvinst.exe (PID: 1688)
      • drvinst.exe (PID: 3984)
      • VoiceAI.exe (PID: 6012)
      • VoiceAI.exe (PID: 6284)
      • VoiceAI.exe (PID: 3564)
      • VoiceAI.exe (PID: 2072)
      • VoiceAI.exe (PID: 6384)
      • VoiceAI.exe (PID: 6380)
      • VoiceAI.exe (PID: 6528)
      • VoiceAI.exe (PID: 6660)
      • VoiceAI.exe (PID: 3732)
      • VoiceAI.exe (PID: 6756)
      • VoiceAI.exe (PID: 520)
    • Reads the machine GUID from the registry

      • Voice.ai-Downloader.exe (PID: 6180)
      • VoiceAI-Installer.exe (PID: 6772)
      • VoiceAI.exe (PID: 6968)
      • drvinst.exe (PID: 1688)
      • VoiceAI.exe (PID: 6012)
      • VoiceAI.exe (PID: 6284)
      • VoiceAI.exe (PID: 6384)
      • VoiceAI.exe (PID: 2072)
      • VoiceAI.exe (PID: 3564)
      • VoiceAI.exe (PID: 6380)
      • VoiceAI.exe (PID: 6660)
      • VoiceAI.exe (PID: 6528)
      • VoiceAI.exe (PID: 3732)
      • VoiceAI.exe (PID: 520)
      • VoiceAI.exe (PID: 6756)
    • The sample compiled with english language support

      • Voice.ai-Downloader.exe (PID: 6180)
      • vc2019.exe (PID: 6920)
      • VoiceAI-Installer.exe (PID: 6772)
      • vc2019.exe (PID: 6896)
      • VoiceAI.exe (PID: 6968)
      • drvinst.exe (PID: 1688)
    • Reads the computer name

      • Voice.ai-Downloader.exe (PID: 6180)
      • VoiceAI-Installer.exe (PID: 6772)
      • vc2019.exe (PID: 6920)
      • drvinst.exe (PID: 1688)
      • drvinst.exe (PID: 3984)
      • VoiceAI.exe (PID: 6012)
      • VoiceAI.exe (PID: 6284)
      • VoiceAI.exe (PID: 3564)
      • VoiceAI.exe (PID: 2072)
      • VoiceAI.exe (PID: 6384)
      • VoiceAI.exe (PID: 6528)
      • VoiceAI.exe (PID: 6968)
      • VoiceAI.exe (PID: 6380)
      • VoiceAI.exe (PID: 520)
      • VoiceAI.exe (PID: 6660)
      • VoiceAI.exe (PID: 3732)
      • VoiceAI.exe (PID: 6756)
    • Reads the software policy settings

      • Voice.ai-Downloader.exe (PID: 6180)
      • VoiceAI-Installer.exe (PID: 6772)
      • VoiceAI.exe (PID: 6968)
      • drvinst.exe (PID: 1688)
      • VoiceAI.exe (PID: 6012)
      • VoiceAI.exe (PID: 6284)
      • VoiceAI.exe (PID: 6384)
      • VoiceAI.exe (PID: 2072)
      • VoiceAI.exe (PID: 3564)
      • VoiceAI.exe (PID: 6528)
      • VoiceAI.exe (PID: 6660)
      • VoiceAI.exe (PID: 520)
      • VoiceAI.exe (PID: 3732)
      • VoiceAI.exe (PID: 6756)
      • VoiceAI.exe (PID: 6380)
    • Checks proxy server information

      • Voice.ai-Downloader.exe (PID: 6180)
      • VoiceAI.exe (PID: 6968)
      • VoiceAI-Installer.exe (PID: 6772)
      • VoiceAI.exe (PID: 6012)
    • Create files in a temporary directory

      • Voice.ai-Downloader.exe (PID: 6180)
      • VoiceAI-Installer.exe (PID: 6772)
      • vc2019.exe (PID: 6920)
      • VoiceAI.exe (PID: 6968)
      • VoiceAI.exe (PID: 6012)
    • Creates files or folders in the user directory

      • Voice.ai-Downloader.exe (PID: 6180)
      • VoiceAI.exe (PID: 6968)
      • VoiceAI.exe (PID: 6012)
      • VoiceAI-Installer.exe (PID: 6772)
      • VoiceAI.exe (PID: 6384)
    • Creates files in the program directory

      • Voice.ai-Downloader.exe (PID: 6180)
      • VoiceAI-Installer.exe (PID: 6772)
    • Reads Environment values

      • VoiceAI.exe (PID: 6968)
      • VoiceAI.exe (PID: 6012)
      • VoiceAI.exe (PID: 6284)
      • VoiceAI.exe (PID: 2072)
      • VoiceAI.exe (PID: 6384)
      • VoiceAI.exe (PID: 3564)
      • VoiceAI.exe (PID: 6528)
      • VoiceAI.exe (PID: 6380)
      • VoiceAI.exe (PID: 520)
      • VoiceAI.exe (PID: 6660)
      • VoiceAI.exe (PID: 3732)
      • VoiceAI.exe (PID: 6756)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 5320)
    • Process checks computer location settings

      • VoiceAI.exe (PID: 6012)
      • VoiceAI.exe (PID: 6528)
      • VoiceAI.exe (PID: 6380)
      • VoiceAI.exe (PID: 6756)
    • .NET Reactor protector has been detected

      • VoiceAI.exe (PID: 2072)
      • VoiceAI.exe (PID: 6012)
      • VoiceAI.exe (PID: 6384)
      • VoiceAI.exe (PID: 3564)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:57:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26112
InitializedDataSize: 162816
UninitializedDataSize: 1024
EntryPoint: 0x33b3
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
151
Monitored processes
21
Malicious processes
5
Suspicious processes
2

Behavior graph

Click at the process to see the details
start voice.ai-downloader.exe voiceai-installer.exe vc2019.exe vc2019.exe voiceai.exe drvinst.exe drvinst.exe no specs explorer.exe no specs explorer.exe no specs voiceai.exe no specs voiceai.exe no specs voiceai.exe no specs voiceai.exe no specs voiceai.exe voiceai.exe no specs voiceai.exe no specs voiceai.exe no specs voiceai.exe no specs voiceai.exe no specs voiceai.exe no specs voice.ai-downloader.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
520"C:\Program Files\Voice.ai\VoiceAI.exe" --type=gpu-process --no-sandbox --log-severity=disable --lang=en-US --user-data-dir="C:\Users\admin\AppData\Local\CEF\User Data" --cefsharpexitsub --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=disabled --log-file="C:\Program Files\Voice.ai\debug.log" --mojo-platform-channel-handle=3856 --field-trial-handle=2660,i,1184594912798034307,9380011464542674876,131072 --disable-features=CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:2 --host-process-id=6012C:\Program Files\Voice.ai\VoiceAI.exeVoiceAI.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Voice.ai - Voice Changer
Version:
0.1.41.4
Modules
Images
c:\program files\voice.ai\voiceai.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1580"C:\WINDOWS\explorer.exe" "C:\Program Files\Voice.ai\VoiceAI.exe"C:\Windows\explorer.exeVoiceAI-Installer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Exit code:
1
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
1688DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{d93171a0-6234-544f-8a95-1fc4b265d2ba}\voiceaidriver.inf" "9" "46b7f3743" "00000000000001D8" "WinSta0\Default" "00000000000001F0" "208" "c:\program files\voice.ai\voiceaidriver"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
2072"C:\Program Files\Voice.ai\VoiceAI.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=utility --no-sandbox --log-severity=disable --lang=en-US --user-data-dir="C:\Users\admin\AppData\Local\CEF\User Data" --cefsharpexitsub --log-file="C:\Program Files\Voice.ai\debug.log" --mojo-platform-channel-handle=3288 --field-trial-handle=2660,i,1184594912798034307,9380011464542674876,131072 --disable-features=CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 --host-process-id=6012C:\Program Files\Voice.ai\VoiceAI.exeVoiceAI.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Voice.ai - Voice Changer
Version:
0.1.41.4
Modules
Images
c:\program files\voice.ai\voiceai.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3564"C:/Program Files/Voice.ai/VoiceAI.exe" discord 6012C:\Program Files\Voice.ai\VoiceAI.exeVoiceAI.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Voice.ai - Voice Changer
Version:
0.1.41.4
Modules
Images
c:\program files\voice.ai\voiceai.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3732"C:\Program Files\Voice.ai\VoiceAI.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --lang=en-US --service-sandbox-type=audio --no-sandbox --log-severity=disable --lang=en-US --user-data-dir="C:\Users\admin\AppData\Local\CEF\User Data" --cefsharpexitsub --log-file="C:\Program Files\Voice.ai\debug.log" --mojo-platform-channel-handle=3568 --field-trial-handle=2660,i,1184594912798034307,9380011464542674876,131072 --disable-features=CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 --host-process-id=6012C:\Program Files\Voice.ai\VoiceAI.exeVoiceAI.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Voice.ai - Voice Changer
Version:
0.1.41.4
Modules
Images
c:\program files\voice.ai\voiceai.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3984DrvInst.exe "2" "211" "ROOT\MEDIA\0000" "C:\WINDOWS\INF\oem1.inf" "oem1.inf:ed86ca11bfc96d40:VOICEAIDRIVER_SA:16.36.0.99:root\voiceaidriver," "46b7f3743" "00000000000001D8"C:\Windows\System32\drvinst.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
5092"C:\Users\admin\Desktop\Voice.ai-Downloader.exe" C:\Users\admin\Desktop\Voice.ai-Downloader.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\voice.ai-downloader.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
5320C:\WINDOWS\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shcore.dll
6012"C:\Program Files\Voice.ai\VoiceAI.exe" C:\Program Files\Voice.ai\VoiceAI.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Voice.ai - Voice Changer
Version:
0.1.41.4
Modules
Images
c:\program files\voice.ai\voiceai.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
49 684
Read events
49 024
Write events
651
Delete events
9

Modification events

(PID) Process:(6180) Voice.ai-Downloader.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6180) Voice.ai-Downloader.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6180) Voice.ai-Downloader.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6180) Voice.ai-Downloader.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Voice.ai\Voice.ai Voice Changer
Operation:writeName:InstallId
Value:
A-99bcdab3-4be3-43db-bac4-9010d527b72d
(PID) Process:(6772) VoiceAI-Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6772) VoiceAI-Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6772) VoiceAI-Installer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6772) VoiceAI-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Voice.ai
Operation:writeName:UninstallString
Value:
"C:\Program Files\Voice.ai\uninstall.exe"
(PID) Process:(6772) VoiceAI-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Voice.ai
Operation:writeName:QuietUninstallString
Value:
"C:\Program Files\Voice.ai\uninstall.exe" /S
(PID) Process:(6772) VoiceAI-Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Voice.ai
Operation:writeName:InstallLocation
Value:
"C:\Program Files\Voice.ai"
Executable files
51
Suspicious files
211
Text files
57
Unknown types
1

Dropped files

PID
Process
Filename
Type
6180Voice.ai-Downloader.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\773CFF2C7835D48C4E76FE153DBA9F81_06BAAB4B106148BBEEB533DB7B1C6AE1binary
MD5:04E1582B97BA4D411F6DCB0CD26CEAD6
SHA256:1B788CD097A198D22C7719BF0E6E2E74D691951C172D6B5F6A47949102A62D81
6180Voice.ai-Downloader.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:B544E179CD8050349FE0B9A1DF875C1C
SHA256:0B7627742D00DA6F7E0A67A4F41F53598D72AFD0FFC741162CC9C013C708C1D0
6180Voice.ai-Downloader.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\Voice.ai-Installer[1].exe
MD5:
SHA256:
6180Voice.ai-Downloader.exeC:\Program Files\Voice.ai\VoiceAI-Installer.exe
MD5:
SHA256:
6180Voice.ai-Downloader.exeC:\Users\admin\AppData\Local\Temp\nsz55F4.tmp\INetC.dllexecutable
MD5:2B342079303895C50AF8040A91F30F71
SHA256:2D5D89025911E2E273F90F393624BE4819641DBEE1606DE792362E442E54612F
6180Voice.ai-Downloader.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\user-event[1].jsonbinary
MD5:7363E85FE9EDEE6F053A4B319588C086
SHA256:C955E57777EC0D73639DCA6748560D00AA5EB8E12F13EBB2ED9656ADD3908F97
6180Voice.ai-Downloader.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:0BAE895B71FE83D91DFE32E08C3C3669
SHA256:D2126C484D166541E52775E4C8F5B46B76D902B1C6FCBE6B1F83EF85F3E5B664
6180Voice.ai-Downloader.exeC:\Users\admin\AppData\Local\Temp\nsz55F4.tmp\nsProcess.dllexecutable
MD5:05450FACE243B3A7472407B999B03A72
SHA256:95FE9D92512FF2318CC2520311EF9145B2CEE01209AB0E1B6E45C7CE1D4D0E89
6180Voice.ai-Downloader.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\mt[1].txttext
MD5:309D46EE962317F6D7B8B3EB5866A519
SHA256:BF28046639407A9FF6B715E5A15F42599C85F5249B0741A4893FFBD4348519DB
6180Voice.ai-Downloader.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12binary
MD5:C9BE626E9715952E9B70F92F912B9787
SHA256:C13E8D22800C200915F87F71C31185053E4E60CA25DE2E41E160E09CD2D815D4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
15
TCP/UDP connections
69
DNS requests
35
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.77.197.149:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4308
svchost.exe
GET
200
2.20.118.102:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.20.118.102:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.20.118.102:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.51.98.7:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6180
Voice.ai-Downloader.exe
GET
200
142.250.178.131:80
http://c.pki.goog/r/gsr1.crl
unknown
whitelisted
6180
Voice.ai-Downloader.exe
GET
200
142.250.178.131:80
http://c.pki.goog/r/r4.crl
unknown
whitelisted
6968
VoiceAI.exe
GET
200
104.18.38.233:80
http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSdE3gf41WAic8Uh9lF92%2BIJqh5qwQUMuuSmv81lkgvKEBCcCA2kVwXheYCEDPXCKiRQFMZ4qW70zm5rW4%3D
unknown
whitelisted
6632
SIHClient.exe
GET
200
2.20.118.102:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6632
SIHClient.exe
GET
200
2.20.118.102:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
23.77.197.149:80
crl.microsoft.com
Akamai International B.V.
FR
whitelisted
4308
svchost.exe
23.77.197.149:80
crl.microsoft.com
Akamai International B.V.
FR
whitelisted
5064
SearchApp.exe
2.22.251.22:443
www.bing.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
2.20.118.102:80
www.microsoft.com
RCS & RDS
RO
whitelisted
4308
svchost.exe
2.20.118.102:80
www.microsoft.com
RCS & RDS
RO
whitelisted
2.20.118.102:80
www.microsoft.com
RCS & RDS
RO
whitelisted
4
System
192.168.100.255:138
whitelisted
23.51.98.7:80
ocsp.digicert.com
Akamai International B.V.
US
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 23.77.197.149
whitelisted
www.bing.com
  • 2.22.251.22
whitelisted
google.com
  • 142.250.179.110
whitelisted
www.microsoft.com
  • 2.20.118.102
whitelisted
ocsp.digicert.com
  • 23.51.98.7
whitelisted
sv.voice.ai
  • 54.242.46.35
unknown
status.rapidssl.com
  • 23.51.98.7
whitelisted
voice.ai
  • 104.26.6.223
unknown
c.pki.goog
  • 142.250.178.131
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted

Threats

PID
Process
Class
Message
6384
VoiceAI.exe
Not Suspicious Traffic
INFO [ANY.RUN] Global content delivery network (unpkg .com)
No debug info