File name:

hitpaw-voice-changer.exe

Full analysis: https://app.any.run/tasks/5fa620ed-7f43-4d29-8ee9-03fb878584cc
Verdict: Malicious activity
Analysis date: December 07, 2023, 09:37:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

05F2EDB8621E49275E0029C6754B942D

SHA1:

F0AE6CAFDED1BF60C70E5050F6D2A6AD1B13D8A8

SHA256:

90279B02D3AFB48D50D70201AE740DAA2761D0D3F06FD60C4DB8690D9BA586FE

SSDEEP:

49152:RBfoNtu1abLX7EzIZdMOo305WebRyyfdEGUYcz57GO00Bx0KY8D2kwU3st0sUZ:RBfBSH9Ro305WeFyyfdEHYoyGBhpD2kN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Connects to the CnC server

      • hitpaw-voice-changer.exe (PID: 2928)
    • Drops the executable file immediately after the start

      • voicechanger_hitpaw_1.3.0.exe (PID: 1128)
      • voicechanger_hitpaw_1.3.0.tmp (PID: 2864)
  • SUSPICIOUS

    • Reads the Internet Settings

      • hitpaw-voice-changer.exe (PID: 2928)
      • voicechanger_hitpaw_1.3.0.tmp (PID: 2864)
    • Reads security settings of Internet Explorer

      • hitpaw-voice-changer.exe (PID: 2928)
    • Reads settings of System Certificates

      • hitpaw-voice-changer.exe (PID: 2928)
    • Checks Windows Trust Settings

      • hitpaw-voice-changer.exe (PID: 2928)
    • Checks for external IP

      • hitpaw-voice-changer.exe (PID: 2928)
    • Reads the Windows owner or organization settings

      • voicechanger_hitpaw_1.3.0.tmp (PID: 2864)
    • Starts CMD.EXE for commands execution

      • voicechanger_hitpaw_1.3.0.tmp (PID: 2864)
    • Get information on the list of running processes

      • voicechanger_hitpaw_1.3.0.tmp (PID: 2864)
      • cmd.exe (PID: 2916)
    • Process drops legitimate windows executable

      • voicechanger_hitpaw_1.3.0.tmp (PID: 2864)
    • The process drops C-runtime libraries

      • voicechanger_hitpaw_1.3.0.tmp (PID: 2864)
    • Drops a system driver (possible attempt to evade defenses)

      • voicechanger_hitpaw_1.3.0.tmp (PID: 2864)
    • Drops 7-zip archiver for unpacking

      • voicechanger_hitpaw_1.3.0.tmp (PID: 2864)
  • INFO

    • Checks supported languages

      • hitpaw-voice-changer.exe (PID: 2928)
      • wmpnscfg.exe (PID: 3112)
      • voicechanger_hitpaw_1.3.0.exe (PID: 1128)
      • voicechanger_hitpaw_1.3.0.tmp (PID: 2864)
    • Reads the computer name

      • hitpaw-voice-changer.exe (PID: 2928)
      • wmpnscfg.exe (PID: 3112)
      • voicechanger_hitpaw_1.3.0.tmp (PID: 2864)
    • Checks proxy server information

      • hitpaw-voice-changer.exe (PID: 2928)
    • Reads Environment values

      • hitpaw-voice-changer.exe (PID: 2928)
    • Reads the machine GUID from the registry

      • hitpaw-voice-changer.exe (PID: 2928)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3112)
    • Creates files or folders in the user directory

      • hitpaw-voice-changer.exe (PID: 2928)
    • Create files in a temporary directory

      • voicechanger_hitpaw_1.3.0.exe (PID: 1128)
      • hitpaw-voice-changer.exe (PID: 2928)
      • voicechanger_hitpaw_1.3.0.tmp (PID: 2864)
    • Creates files in the program directory

      • hitpaw-voice-changer.exe (PID: 2928)
      • voicechanger_hitpaw_1.3.0.tmp (PID: 2864)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (76)
.exe | Win32 Executable (generic) (12.6)
.exe | Generic Win/DOS Executable (5.6)
.exe | DOS Executable Generic (5.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:07:11 10:06:20+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 2023424
InitializedDataSize: 868352
UninitializedDataSize: 2789376
EntryPoint: 0x497130
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.7.11.0
ProductVersionNumber: 2.7.11.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: HitPaw Co., Ltd.
FileDescription: HitPaw Voice Changer
FileVersion: 2.7.11.0
LegalCopyright: Copyright © 2007-2023 HitPaw Co.,Ltd.
ProductName: 20230711160553
ProductVersion: 2.7.11.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start hitpaw-voice-changer.exe wmpnscfg.exe no specs voicechanger_hitpaw_1.3.0.exe no specs voicechanger_hitpaw_1.3.0.tmp no specs cmd.exe no specs tasklist.exe no specs find.exe no specs hitpaw-voice-changer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
564tasklist /nhC:\Windows\System32\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1128 /VERYSILENT /SP- /NORESTART /DIR="C:\Program Files\HitPaw\HitPaw Voice Changer\" /LANG=en /LOG="C:\Users\admin\AppData\Local\Temp\HitPaw Voice Changer_Setup_20231207094106.log" /sptrack nullC:\Users\admin\AppData\Local\Temp\voicechanger_hitpaw\voicechanger_hitpaw_1.3.0.exehitpaw-voice-changer.exe
User:
admin
Company:
Copyright (c) 2023 HitPaw Co., Ltd. All Rights Reserved.
Integrity Level:
HIGH
Description:
HitPaw Voice Changer Setup
Exit code:
0
Version:
1.3.0.18
Modules
Images
c:\users\admin\appdata\local\temp\voicechanger_hitpaw\voicechanger_hitpaw_1.3.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1864"C:\Users\admin\AppData\Local\Temp\hitpaw-voice-changer.exe" C:\Users\admin\AppData\Local\Temp\hitpaw-voice-changer.exeexplorer.exe
User:
admin
Company:
HitPaw Co., Ltd.
Integrity Level:
MEDIUM
Description:
HitPaw Voice Changer
Exit code:
3221226540
Version:
2.7.11.0
Modules
Images
c:\users\admin\appdata\local\temp\hitpaw-voice-changer.exe
c:\windows\system32\ntdll.dll
2864"C:\Users\admin\AppData\Local\Temp\is-ADQDI.tmp\voicechanger_hitpaw_1.3.0.tmp" /SL5="$11015A,298551279,711680,C:\Users\admin\AppData\Local\Temp\voicechanger_hitpaw\voicechanger_hitpaw_1.3.0.exe" /VERYSILENT /SP- /NORESTART /DIR="C:\Program Files\HitPaw\HitPaw Voice Changer\" /LANG=en /LOG="C:\Users\admin\AppData\Local\Temp\HitPaw Voice Changer_Setup_20231207094106.log" /sptrack nullC:\Users\admin\AppData\Local\Temp\is-ADQDI.tmp\voicechanger_hitpaw_1.3.0.tmpvoicechanger_hitpaw_1.3.0.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-adqdi.tmp\voicechanger_hitpaw_1.3.0.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2916"C:\Windows\system32\cmd.exe" /c tasklist /nh|find /c /i "VoiceChanger.exe" > "C:\Users\admin\AppData\Local\Temp\findSoftRes.txt"C:\Windows\System32\cmd.exevoicechanger_hitpaw_1.3.0.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2928"C:\Users\admin\AppData\Local\Temp\hitpaw-voice-changer.exe" C:\Users\admin\AppData\Local\Temp\hitpaw-voice-changer.exe
explorer.exe
User:
admin
Company:
HitPaw Co., Ltd.
Integrity Level:
HIGH
Description:
HitPaw Voice Changer
Exit code:
0
Version:
2.7.11.0
Modules
Images
c:\users\admin\appdata\local\temp\hitpaw-voice-changer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
3112"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3476find /c /i "VoiceChanger.exe" C:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
7 042
Read events
7 010
Write events
32
Delete events
0

Modification events

(PID) Process:(2928) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2928) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005A010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2928) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2928) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2928) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2928) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2928) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2928) hitpaw-voice-changer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2928) hitpaw-voice-changer.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2864) voicechanger_hitpaw_1.3.0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
331
Suspicious files
24
Text files
99
Unknown types
0

Dropped files

PID
Process
Filename
Type
2928hitpaw-voice-changer.exeC:\Users\admin\AppData\Local\Temp\voicechanger_hitpaw\voicechanger_hitpaw_1.3.0.exe
MD5:
SHA256:
2928hitpaw-voice-changer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\LF7TW27N.txttext
MD5:86C3EF2B85D61D423F74D97CD20B60D1
SHA256:B9AC586A38A3AC8E6ECA20F0A1ADC278369165EF705DA5D3625DCB9B994062D9
2928hitpaw-voice-changer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cbinary
MD5:878C4F371C53540BE4A43F83BCE51B1B
SHA256:80212FCE1A79E7B72ED6D9153562E2DCA669B31141A496D0C48D7E230F3BA6A4
2928hitpaw-voice-changer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\A7W0F4YD.txttext
MD5:CE30CD363A11C08E71F618C4F3F5D4B9
SHA256:DA5E8F1305323D4C953A6F998F2F4AC2635AC5BD652CDA6F545AF216C80F7DA8
2928hitpaw-voice-changer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
2928hitpaw-voice-changer.exeC:\Users\admin\AppData\Local\Temp\voicechanger_hitpaw\voicechanger_hitpaw_1.3.0.exe.xmltext
MD5:42A8F9CF3E7611E0801C35E3A05761A4
SHA256:637DD7CEE47E64EAB5A8E221346568025D7FA12BF30DA06891DE362DCB0B223D
2864voicechanger_hitpaw_1.3.0.tmpC:\Program Files\HitPaw\HitPaw Voice Changer\is-U45DU.tmpexecutable
MD5:06D25EF536B9889D66371DEC7AAE43CD
SHA256:323C253524238E41F419C2F41F28DA37C6A539AF50E9C70290A33C8CC3EFC4C6
2928hitpaw-voice-changer.exeC:\Users\admin\AppData\Local\Temp\voicechanger_hitpaw\voicechanger_hitpaw_1.3.0.exe.dbtext
MD5:CBCACA237FB6A4AAE4871B36F19E4634
SHA256:E4C0A1B9781C790D1CA297D12941F6A6F842C1CA71821B26984B2F94F90ED4B4
2928hitpaw-voice-changer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_E5BB0F21B386C88093E718A87A877885binary
MD5:3075088570F2D1524F075B4BD77EBF01
SHA256:46C3FA4BA9C30685C613D800F6EAA4DA9B8DA2D1104DC8351D13284B82DB2A45
2928hitpaw-voice-changer.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cbinary
MD5:9E4C7179CCE8C190DBECE2C7579393CF
SHA256:863EAB738D2F6060B10CBB4EDE71ED85B928DB890BFECAD037DC9053F2645B8E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
35
TCP/UDP connections
302
DNS requests
10
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2928
hitpaw-voice-changer.exe
GET
301
104.18.24.249:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
html
245 b
unknown
2928
hitpaw-voice-changer.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D
unknown
binary
471 b
unknown
2928
hitpaw-voice-changer.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fec2c6a5ad4236b4
unknown
compressed
4.66 Kb
unknown
2928
hitpaw-voice-changer.exe
GET
200
208.95.112.1:80
http://ip-api.com/csv
unknown
text
171 b
unknown
2928
hitpaw-voice-changer.exe
POST
200
142.250.185.142:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
2928
hitpaw-voice-changer.exe
POST
200
142.250.185.142:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
2928
hitpaw-voice-changer.exe
POST
200
142.250.185.142:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
2928
hitpaw-voice-changer.exe
POST
200
142.250.185.142:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
2928
hitpaw-voice-changer.exe
POST
200
142.250.185.142:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
2928
hitpaw-voice-changer.exe
POST
200
142.250.185.142:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2928
hitpaw-voice-changer.exe
104.18.24.249:80
www.tenorshare.com
CLOUDFLARENET
unknown
2928
hitpaw-voice-changer.exe
104.18.24.249:443
www.tenorshare.com
CLOUDFLARENET
unknown
2928
hitpaw-voice-changer.exe
104.18.25.249:443
www.tenorshare.com
CLOUDFLARENET
unknown
4
System
192.168.100.255:138
whitelisted
868
svchost.exe
2.18.96.131:80
armmf.adobe.com
Akamai International B.V.
FR
unknown
2928
hitpaw-voice-changer.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
2928
hitpaw-voice-changer.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2928
hitpaw-voice-changer.exe
208.95.112.1:80
ip-api.com
TUT-AS
US
unknown
2928
hitpaw-voice-changer.exe
142.250.185.142:443
www.google-analytics.com
GOOGLE
US
whitelisted
2928
hitpaw-voice-changer.exe
142.250.185.142:80
www.google-analytics.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
www.tenorshare.com
  • 104.18.24.249
  • 104.18.25.249
whitelisted
update.tenorshare.com
  • 104.18.24.249
  • 104.18.25.249
unknown
armmf.adobe.com
  • 2.18.96.131
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ip-api.com
  • 208.95.112.1
shared
www.google-analytics.com
  • 142.250.185.142
whitelisted
download.hitpaw.com
  • 104.18.24.102
  • 104.18.25.102
unknown

Threats

PID
Process
Class
Message
2928
hitpaw-voice-changer.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
2928
hitpaw-voice-changer.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
2928
hitpaw-voice-changer.exe
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
2928
hitpaw-voice-changer.exe
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
2928
hitpaw-voice-changer.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Tensorshare Google Analytics Checkin
2 ETPRO signatures available at the full report
No debug info