File name:

hitpaw-voice-changer.exe

Full analysis: https://app.any.run/tasks/1a9c745a-27ce-4cd9-8534-17e983eedea2
Verdict: Malicious activity
Analysis date: November 19, 2023, 00:22:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

05F2EDB8621E49275E0029C6754B942D

SHA1:

F0AE6CAFDED1BF60C70E5050F6D2A6AD1B13D8A8

SHA256:

90279B02D3AFB48D50D70201AE740DAA2761D0D3F06FD60C4DB8690D9BA586FE

SSDEEP:

49152:RBfoNtu1abLX7EzIZdMOo305WebRyyfdEGUYcz57GO00Bx0KY8D2kwU3st0sUZ:RBfBSH9Ro305WeFyyfdEHYoyGBhpD2kN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Connects to the CnC server

      • hitpaw-voice-changer.exe (PID: 3228)
  • SUSPICIOUS

    • Reads settings of System Certificates

      • hitpaw-voice-changer.exe (PID: 3228)
    • Checks Windows Trust Settings

      • hitpaw-voice-changer.exe (PID: 3228)
    • Reads the Internet Settings

      • hitpaw-voice-changer.exe (PID: 3228)
    • Reads security settings of Internet Explorer

      • hitpaw-voice-changer.exe (PID: 3228)
    • Checks for external IP

      • hitpaw-voice-changer.exe (PID: 3228)
  • INFO

    • Reads the computer name

      • hitpaw-voice-changer.exe (PID: 3228)
      • wmpnscfg.exe (PID: 3644)
    • Checks supported languages

      • hitpaw-voice-changer.exe (PID: 3228)
      • wmpnscfg.exe (PID: 3644)
    • Checks proxy server information

      • hitpaw-voice-changer.exe (PID: 3228)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3644)
    • Reads the machine GUID from the registry

      • hitpaw-voice-changer.exe (PID: 3228)
      • wmpnscfg.exe (PID: 3644)
    • Creates files or folders in the user directory

      • hitpaw-voice-changer.exe (PID: 3228)
    • Reads Environment values

      • hitpaw-voice-changer.exe (PID: 3228)
    • Create files in a temporary directory

      • hitpaw-voice-changer.exe (PID: 3228)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (76)
.exe | Win32 Executable (generic) (12.6)
.exe | Generic Win/DOS Executable (5.6)
.exe | DOS Executable Generic (5.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:07:11 10:06:20+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 2023424
InitializedDataSize: 868352
UninitializedDataSize: 2789376
EntryPoint: 0x497130
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.7.11.0
ProductVersionNumber: 2.7.11.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: HitPaw Co., Ltd.
FileDescription: HitPaw Voice Changer
FileVersion: 2.7.11.0
LegalCopyright: Copyright © 2007-2023 HitPaw Co.,Ltd.
ProductName: 20230711160553
ProductVersion: 2.7.11.0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start hitpaw-voice-changer.exe wmpnscfg.exe no specs hitpaw-voice-changer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3228"C:\Users\admin\AppData\Local\Temp\hitpaw-voice-changer.exe" C:\Users\admin\AppData\Local\Temp\hitpaw-voice-changer.exe
explorer.exe
User:
admin
Company:
HitPaw Co., Ltd.
Integrity Level:
HIGH
Description:
HitPaw Voice Changer
Exit code:
0
Version:
2.7.11.0
Modules
Images
c:\users\admin\appdata\local\temp\hitpaw-voice-changer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
3448"C:\Users\admin\AppData\Local\Temp\hitpaw-voice-changer.exe" C:\Users\admin\AppData\Local\Temp\hitpaw-voice-changer.exeexplorer.exe
User:
admin
Company:
HitPaw Co., Ltd.
Integrity Level:
MEDIUM
Description:
HitPaw Voice Changer
Exit code:
3221226540
Version:
2.7.11.0
Modules
Images
c:\users\admin\appdata\local\temp\hitpaw-voice-changer.exe
c:\windows\system32\ntdll.dll
3644"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
Total events
4 769
Read events
4 742
Write events
24
Delete events
3

Modification events

(PID) Process:(3228) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3228) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000059010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3228) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3228) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3228) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3228) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3228) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3228) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3228) hitpaw-voice-changer.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3644) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{20C7142B-1552-49F8-BA9C-9A4483F292D7}\{078B5770-37B1-411F-8AC7-2B20E334BD5B}
Operation:delete keyName:(default)
Value:
Executable files
0
Suspicious files
4
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
3228hitpaw-voice-changer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\C0R8OFB2.txttext
MD5:C40BA10C65E591617BFE82949AB84F52
SHA256:60C35A38BF39011E276EA07E0F91B7705705D1E576619B828C963870889B4710
3228hitpaw-voice-changer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
3228hitpaw-voice-changer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cbinary
MD5:260FB7F10305425B17500EE4FD8CA5B8
SHA256:F6A78E475D5F70C891D7F69E1770609E63B595FBB92E2F9222492E515C88D176
3228hitpaw-voice-changer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cbinary
MD5:52D6F476FEE5F16EAB0B1D1C29836B7D
SHA256:9088C3803BA34D16ED591A3E698A4D118235749D02BC613EAB7EF9AE2AB313C4
3228hitpaw-voice-changer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:4CA4293C7DC02AE1A182FAE6D714958A
SHA256:B328B74B067C332918066CE2C85052F3C351321F854F314B826FDA0A9B758491
3228hitpaw-voice-changer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\TLWEEKPD.txttext
MD5:8D6D839E32D9C25EF83E1C02908EF775
SHA256:35C075A2B297D4925B001B3FF6E88C497B697F96F20C9CBEBCF4561771CB133F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
12
DNS requests
6
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3228
hitpaw-voice-changer.exe
GET
200
208.95.112.1:80
http://ip-api.com/csv
unknown
text
152 b
3228
hitpaw-voice-changer.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?b54a2c574b0476d0
unknown
compressed
4.66 Kb
3228
hitpaw-voice-changer.exe
GET
301
104.18.24.249:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
html
245 b
3228
hitpaw-voice-changer.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D
unknown
binary
471 b
3228
hitpaw-voice-changer.exe
POST
200
142.250.186.78:80
http://www.google-analytics.com/collect
unknown
image
35 b
3228
hitpaw-voice-changer.exe
POST
200
142.250.186.78:80
http://www.google-analytics.com/collect
unknown
image
35 b
3228
hitpaw-voice-changer.exe
POST
200
142.250.186.78:80
http://www.google-analytics.com/collect
unknown
image
35 b
3228
hitpaw-voice-changer.exe
POST
200
142.250.186.78:80
http://www.google-analytics.com/collect
unknown
image
35 b
3228
hitpaw-voice-changer.exe
POST
200
142.250.186.78:80
http://www.google-analytics.com/collect
unknown
image
35 b
3228
hitpaw-voice-changer.exe
POST
200
142.250.186.78:80
http://www.google-analytics.com/collect
unknown
image
35 b
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
3228
hitpaw-voice-changer.exe
104.18.24.249:80
www.tenorshare.com
CLOUDFLARENET
unknown
2588
svchost.exe
239.255.255.250:1900
unknown
4
System
192.168.100.255:138
unknown
3228
hitpaw-voice-changer.exe
104.18.24.249:443
www.tenorshare.com
CLOUDFLARENET
unknown
3228
hitpaw-voice-changer.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
unknown
3228
hitpaw-voice-changer.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3228
hitpaw-voice-changer.exe
208.95.112.1:80
ip-api.com
TUT-AS
US
unknown
3228
hitpaw-voice-changer.exe
142.250.186.78:443
www.google-analytics.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
www.tenorshare.com
  • 104.18.24.249
  • 104.18.25.249
unknown
ctldl.windowsupdate.com
  • 93.184.221.240
unknown
ocsp.digicert.com
  • 192.229.221.95
unknown
ip-api.com
  • 208.95.112.1
unknown
www.google-analytics.com
  • 142.250.186.78
unknown
update.tenorshare.com
  • 104.18.24.249
  • 104.18.25.249
unknown

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
Possibly Unwanted Program Detected
ET ADWARE_PUP Tensorshare Google Analytics Checkin
2 ETPRO signatures available at the full report
No debug info