File name:

hitpaw-voice-changer.exe

Full analysis: https://app.any.run/tasks/39da321e-15e5-4d4c-9861-92b4743eb10f
Verdict: Malicious activity
Analysis date: September 13, 2023, 11:03:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

05F2EDB8621E49275E0029C6754B942D

SHA1:

F0AE6CAFDED1BF60C70E5050F6D2A6AD1B13D8A8

SHA256:

90279B02D3AFB48D50D70201AE740DAA2761D0D3F06FD60C4DB8690D9BA586FE

SSDEEP:

49152:RBfoNtu1abLX7EzIZdMOo305WebRyyfdEGUYcz57GO00Bx0KY8D2kwU3st0sUZ:RBfBSH9Ro305WeFyyfdEHYoyGBhpD2kN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Connects to the CnC server

      • hitpaw-voice-changer.exe (PID: 2892)
  • SUSPICIOUS

    • Reads the Internet Settings

      • hitpaw-voice-changer.exe (PID: 2892)
      • voicechanger_hitpaw_1.0.2.tmp (PID: 2868)
    • Checks for external IP

      • hitpaw-voice-changer.exe (PID: 2892)
    • Get information on the list of running processes

      • voicechanger_hitpaw_1.0.2.tmp (PID: 2868)
      • cmd.exe (PID: 2148)
    • Starts CMD.EXE for commands execution

      • voicechanger_hitpaw_1.0.2.tmp (PID: 2868)
    • Reads settings of System Certificates

      • hitpaw-voice-changer.exe (PID: 2892)
    • Checks Windows Trust Settings

      • hitpaw-voice-changer.exe (PID: 2892)
    • Reads security settings of Internet Explorer

      • hitpaw-voice-changer.exe (PID: 2892)
    • Reads the Windows owner or organization settings

      • voicechanger_hitpaw_1.0.2.tmp (PID: 2868)
    • Drops a system driver (possible attempt to evade defenses)

      • voicechanger_hitpaw_1.0.2.tmp (PID: 2868)
  • INFO

    • Checks supported languages

      • hitpaw-voice-changer.exe (PID: 2892)
      • voicechanger_hitpaw_1.0.2.exe (PID: 1040)
      • voicechanger_hitpaw_1.0.2.tmp (PID: 2868)
      • wmpnscfg.exe (PID: 2548)
    • Reads the computer name

      • hitpaw-voice-changer.exe (PID: 2892)
      • voicechanger_hitpaw_1.0.2.tmp (PID: 2868)
      • wmpnscfg.exe (PID: 2548)
    • Checks proxy server information

      • hitpaw-voice-changer.exe (PID: 2892)
    • Reads the machine GUID from the registry

      • hitpaw-voice-changer.exe (PID: 2892)
      • wmpnscfg.exe (PID: 2548)
    • Reads Environment values

      • hitpaw-voice-changer.exe (PID: 2892)
    • Creates files in the program directory

      • hitpaw-voice-changer.exe (PID: 2892)
      • voicechanger_hitpaw_1.0.2.tmp (PID: 2868)
    • Application was dropped or rewritten from another process

      • voicechanger_hitpaw_1.0.2.tmp (PID: 2868)
    • Create files in a temporary directory

      • hitpaw-voice-changer.exe (PID: 2892)
      • voicechanger_hitpaw_1.0.2.exe (PID: 1040)
      • voicechanger_hitpaw_1.0.2.tmp (PID: 2868)
    • Creates files or folders in the user directory

      • hitpaw-voice-changer.exe (PID: 2892)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 2548)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (76)
.exe | Win32 Executable (generic) (12.6)
.exe | Generic Win/DOS Executable (5.6)
.exe | DOS Executable Generic (5.6)

EXIF

EXE

ProductVersion: 2.7.11.0
ProductName: 20230711160553
LegalCopyright: Copyright © 2007-2023 HitPaw Co.,Ltd.
FileVersion: 2.7.11.0
FileDescription: HitPaw Voice Changer
CompanyName: HitPaw Co., Ltd.
CharacterSet: Windows, Latin1
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 2.7.11.0
FileVersionNumber: 2.7.11.0
Subsystem: Windows GUI
SubsystemVersion: 5.1
ImageVersion: -
OSVersion: 5.1
EntryPoint: 0x497130
UninitializedDataSize: 2789376
InitializedDataSize: 868352
CodeSize: 2023424
LinkerVersion: 14
PEType: PE32
ImageFileCharacteristics: Executable, 32-bit
TimeStamp: 2023:07:11 08:06:20+00:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 11-Jul-2023 08:06:20

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000150

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 3
Time date stamp: 11-Jul-2023 08:06:20
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
UPX0
0x00001000
0x002A9000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
UPX1
0x002AA000
0x001EE000
0x001ED400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
7.89746
.rsrc
0x00498000
0x000D4000
0x000D3400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
7.77631

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
IMM32.dll
IPHLPAPI.DLL
KERNEL32.DLL
OLEAUT32.dll
SHELL32.dll
SHLWAPI.dll
SensApi.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
8
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start hitpaw-voice-changer.exe voicechanger_hitpaw_1.0.2.exe no specs voicechanger_hitpaw_1.0.2.tmp no specs cmd.exe no specs tasklist.exe no specs find.exe no specs wmpnscfg.exe no specs hitpaw-voice-changer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
272tasklist /nhC:\Windows\System32\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
1040 /VERYSILENT /SP- /NORESTART /DIR="C:\Program Files\HitPaw\HitPaw Voice Changer\" /LANG=fr /LOG="C:\Users\admin\AppData\Local\Temp\HitPaw Voice Changer_Setup_20230913120544.log" /sptrack nullC:\Users\admin\AppData\Local\Temp\voicechanger_hitpaw\voicechanger_hitpaw_1.0.2.exehitpaw-voice-changer.exe
User:
admin
Company:
Copyright (c) 2023 HitPaw Co., Ltd. All Rights Reserved.
Integrity Level:
HIGH
Description:
HitPaw Voice Changer Setup
Exit code:
0
Version:
1.0.2.2
Modules
Images
c:\users\admin\appdata\local\temp\voicechanger_hitpaw\voicechanger_hitpaw_1.0.2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
2148"C:\Windows\system32\cmd.exe" /c tasklist /nh|find /c /i "VoiceChanger.exe" > "C:\Users\admin\AppData\Local\Temp\findSoftRes.txt"C:\Windows\System32\cmd.exevoicechanger_hitpaw_1.0.2.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\cmd.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\gdi32.dll
2548"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
2564find /c /i "VoiceChanger.exe" C:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\find.exe
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\ulib.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
2868"C:\Users\admin\AppData\Local\Temp\is-40TRH.tmp\voicechanger_hitpaw_1.0.2.tmp" /SL5="$50166,186089924,711680,C:\Users\admin\AppData\Local\Temp\voicechanger_hitpaw\voicechanger_hitpaw_1.0.2.exe" /VERYSILENT /SP- /NORESTART /DIR="C:\Program Files\HitPaw\HitPaw Voice Changer\" /LANG=fr /LOG="C:\Users\admin\AppData\Local\Temp\HitPaw Voice Changer_Setup_20230913120544.log" /sptrack nullC:\Users\admin\AppData\Local\Temp\is-40TRH.tmp\voicechanger_hitpaw_1.0.2.tmpvoicechanger_hitpaw_1.0.2.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\users\admin\appdata\local\temp\is-40trh.tmp\voicechanger_hitpaw_1.0.2.tmp
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
2892"C:\Users\admin\AppData\Local\Temp\hitpaw-voice-changer.exe" C:\Users\admin\AppData\Local\Temp\hitpaw-voice-changer.exe
explorer.exe
User:
admin
Company:
HitPaw Co., Ltd.
Integrity Level:
HIGH
Description:
HitPaw Voice Changer
Exit code:
0
Version:
2.7.11.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3508"C:\Users\admin\AppData\Local\Temp\hitpaw-voice-changer.exe" C:\Users\admin\AppData\Local\Temp\hitpaw-voice-changer.exeexplorer.exe
User:
admin
Company:
HitPaw Co., Ltd.
Integrity Level:
MEDIUM
Description:
HitPaw Voice Changer
Exit code:
3221226540
Version:
2.7.11.0
Modules
Images
c:\users\admin\appdata\local\temp\hitpaw-voice-changer.exe
c:\windows\system32\ntdll.dll
Total events
5 894
Read events
5 833
Write events
58
Delete events
3

Modification events

(PID) Process:(2892) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2892) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000004F010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2892) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2892) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2892) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2892) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2892) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2892) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2892) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-36-3e-ff
Operation:writeName:WpadDecisionReason
Value:
1
(PID) Process:(2892) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\52-54-00-36-3e-ff
Operation:writeName:WpadDecisionTime
Value:
709B3EF431E6D901
Executable files
850
Suspicious files
391
Text files
1 445
Unknown types
1

Dropped files

PID
Process
Filename
Type
2892hitpaw-voice-changer.exeC:\Users\admin\AppData\Local\Temp\voicechanger_hitpaw\voicechanger_hitpaw_1.0.2.exe
MD5:
SHA256:
2892hitpaw-voice-changer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:24BE8A92460B5B7A555B1DA559296958
SHA256:77A3CFE6B7EB676AF438D5DE88C7EFCB6ABCC494E0B65DA90201969E6D79B2A3
2892hitpaw-voice-changer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\VJHSRL7M.txttext
MD5:097BB353964B2947B5249FCDE0208E98
SHA256:A45143498B29E145F7041EA1A8D441E2D6141511E1332180C225D43801C7B40C
2892hitpaw-voice-changer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8EC9B1D0ABBD7F98B401D425828828CE_E5BB0F21B386C88093E718A87A877885binary
MD5:F0396B86A86CF6961B149206636FB7B6
SHA256:1F7FC49238378C5300263A3C597C63993F82FFDB8D8D8D61D59175833DBFA187
2892hitpaw-voice-changer.exeC:\Users\admin\AppData\Local\Temp\voicechanger_hitpaw\voicechanger_hitpaw_1.0.2.exe.dbtext
MD5:226654B14F3C1B58F6DA88E5EB4E513F
SHA256:2424B6430EF34424634E7ECDDFA7FA7F274B206DF23183F178F33EC45DB126B8
2868voicechanger_hitpaw_1.0.2.tmpC:\Program Files\HitPaw\HitPaw Voice Changer\is-8UTHO.tmpexecutable
MD5:1D79425B0413D36ABC16C014F327A313
SHA256:B5841F87B8221034F45041EC74A998C4B52B50CBE3C44F736406CE7F9251AFD7
2868voicechanger_hitpaw_1.0.2.tmpC:\Program Files\HitPaw\HitPaw Voice Changer\7z.exeexecutable
MD5:1D79425B0413D36ABC16C014F327A313
SHA256:B5841F87B8221034F45041EC74A998C4B52B50CBE3C44F736406CE7F9251AFD7
2868voicechanger_hitpaw_1.0.2.tmpC:\Program Files\HitPaw\HitPaw Voice Changer\VoiceChanger.exeexecutable
MD5:5EBD41CDE210B0C692C5F116292F125F
SHA256:694E040F7D39AE729DF34EAF34DF5BCD499E7755F7283806D76656B193C3395A
2892hitpaw-voice-changer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_E5BB0F21B386C88093E718A87A877885binary
MD5:1B6A5E5D50C5E9FCEE8A2B1BF127EB43
SHA256:3107972224B8C9784C90D2A7165FD4EB991DF056724594F011008A99AC3C593F
2564find.exeC:\Users\admin\AppData\Local\Temp\findSoftRes.txttext
MD5:21438EF4B9AD4FC266B6129A2F60DE29
SHA256:13BF7B3039C63BF5A50491FA3CFD8EB4E699D1BA1436315AEF9CBE5711530354
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
38
TCP/UDP connections
214
DNS requests
11
Threats
9

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2892
hitpaw-voice-changer.exe
GET
104.18.25.249:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
unknown
2892
hitpaw-voice-changer.exe
GET
104.18.25.249:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
unknown
2892
hitpaw-voice-changer.exe
GET
200
208.95.112.1:80
http://ip-api.com/csv
unknown
text
153 b
unknown
2892
hitpaw-voice-changer.exe
GET
301
104.18.25.249:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
html
245 b
unknown
2892
hitpaw-voice-changer.exe
POST
200
142.250.186.78:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
2892
hitpaw-voice-changer.exe
POST
200
142.250.186.78:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
2892
hitpaw-voice-changer.exe
POST
200
142.250.186.78:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
2892
hitpaw-voice-changer.exe
POST
200
142.250.186.78:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
2892
hitpaw-voice-changer.exe
POST
200
142.250.186.78:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
2892
hitpaw-voice-changer.exe
POST
200
142.250.186.78:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
3284
svchost.exe
239.255.255.250:1900
whitelisted
2892
hitpaw-voice-changer.exe
104.18.25.249:80
www.tenorshare.com
CLOUDFLARENET
unknown
2892
hitpaw-voice-changer.exe
104.18.25.249:443
www.tenorshare.com
CLOUDFLARENET
unknown
2892
hitpaw-voice-changer.exe
104.18.24.249:443
www.tenorshare.com
CLOUDFLARENET
unknown
4
System
192.168.100.255:138
whitelisted
2892
hitpaw-voice-changer.exe
104.18.24.102:443
download.hitpaw.com
CLOUDFLARENET
unknown
2892
hitpaw-voice-changer.exe
104.18.25.102:443
download.hitpaw.com
CLOUDFLARENET
unknown
2892
hitpaw-voice-changer.exe
208.95.112.1:80
ip-api.com
TUT-AS
US
unknown
2892
hitpaw-voice-changer.exe
142.250.186.78:443
www.google-analytics.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
www.tenorshare.com
  • 104.18.25.249
  • 104.18.24.249
whitelisted
update.tenorshare.com
  • 104.18.25.249
  • 104.18.24.249
unknown
download.hitpaw.com
  • 104.18.24.102
  • 104.18.25.102
unknown
ip-api.com
  • 208.95.112.1
shared
www.google-analytics.com
  • 142.250.186.78
whitelisted
ctldl.windowsupdate.com
  • 23.216.77.69
  • 23.216.77.81
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

PID
Process
Class
Message
2892
hitpaw-voice-changer.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
2892
hitpaw-voice-changer.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
2892
hitpaw-voice-changer.exe
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
2892
hitpaw-voice-changer.exe
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
2892
hitpaw-voice-changer.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Tensorshare Google Analytics Checkin
4 ETPRO signatures available at the full report
No debug info