URL:

https://clownfish-translator.com/voicechanger/download/download32.php?v=181

Full analysis: https://app.any.run/tasks/46a03cf8-a983-4953-9b86-d73b5caa7719
Verdict: Malicious activity
Analysis date: January 28, 2024, 22:00:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MD5:

FF37D68C7EC533866E9C328938064FA5

SHA1:

D126072EC68A85FECF43326B83A80FBBD469BF27

SHA256:

91A2196C03140269E5A03F2DDAA1E3EF8FD870E31D3061CD9CEB8970D5EB34D6

SSDEEP:

3:N8UJHax1KIrWMCARSLJkXJ4XLVHY5dU:2Ulc8ZMmOaVY5dU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • VoiceChanger32(1.81).exe (PID: 2900)
    • Starts NET.EXE for service management

      • VoiceChanger32(1.81).exe (PID: 2900)
      • net.exe (PID: 3324)
      • net.exe (PID: 1484)
      • net.exe (PID: 3000)
      • net.exe (PID: 3136)
    • Registers / Runs the DLL via REGSVR32.EXE

      • VoiceChanger32(1.81).exe (PID: 2900)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • VoiceChanger32(1.81).exe (PID: 2900)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • VoiceChanger32(1.81).exe (PID: 2900)
    • The process creates files with name similar to system file names

      • VoiceChanger32(1.81).exe (PID: 2900)
  • INFO

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 2624)
      • iexplore.exe (PID: 2404)
    • The process uses the downloaded file

      • iexplore.exe (PID: 2624)
    • Drops the executable file immediately after the start

      • iexplore.exe (PID: 2404)
      • iexplore.exe (PID: 2624)
    • Application launched itself

      • iexplore.exe (PID: 2624)
    • Checks supported languages

      • VoiceChanger32(1.81).exe (PID: 2900)
      • APOConfig.exe (PID: 2764)
      • ClownfishVoiceChanger.exe (PID: 3756)
      • ClownfishVoiceChanger.exe (PID: 3832)
      • ClownfishVoiceChanger.exe (PID: 3876)
      • ClownfishVoiceChanger.exe (PID: 3688)
    • Reads the computer name

      • VoiceChanger32(1.81).exe (PID: 2900)
      • APOConfig.exe (PID: 2764)
      • ClownfishVoiceChanger.exe (PID: 3756)
    • Create files in a temporary directory

      • VoiceChanger32(1.81).exe (PID: 2900)
    • Creates files in the program directory

      • VoiceChanger32(1.81).exe (PID: 2900)
    • Manual execution by a user

      • ClownfishVoiceChanger.exe (PID: 3756)
      • ClownfishVoiceChanger.exe (PID: 3832)
      • ClownfishVoiceChanger.exe (PID: 3688)
      • ClownfishVoiceChanger.exe (PID: 3876)
    • Creates files or folders in the user directory

      • ClownfishVoiceChanger.exe (PID: 3756)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
66
Monitored processes
18
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start iexplore.exe iexplore.exe voicechanger32(1.81).exe no specs voicechanger32(1.81).exe net.exe no specs net1.exe no specs net.exe no specs net1.exe no specs net.exe no specs net1.exe no specs net.exe no specs net1.exe no specs regsvr32.exe no specs apoconfig.exe no specs clownfishvoicechanger.exe clownfishvoicechanger.exe no specs clownfishvoicechanger.exe no specs clownfishvoicechanger.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1484"C:\Windows\system32\net.exe" stop AudioEndpointBuilderC:\Windows\System32\net.exeVoiceChanger32(1.81).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
2372C:\Windows\system32\net1 stop AudiosrvC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
2404"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2624 CREDAT:267521 /prefetch:2C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2624"C:\Program Files\Internet Explorer\iexplore.exe" "https://clownfish-translator.com/voicechanger/download/download32.php?v=181"C:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
0
Version:
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iertutil.dll
2728"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\VoiceChanger32(1.81).exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\VoiceChanger32(1.81).exeiexplore.exe
User:
admin
Company:
Shark Labs
Integrity Level:
MEDIUM
Description:
Clownfish Voice Changer Setup
Exit code:
3221226540
Version:
1.81.0.0
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\voicechanger32(1.81).exe
c:\windows\system32\ntdll.dll
2764"C:\Program Files\ClownfishVoiceChanger\APOConfig.exe"C:\Program Files\ClownfishVoiceChanger\APOConfig.exeVoiceChanger32(1.81).exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\clownfishvoicechanger\apoconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2900"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\VoiceChanger32(1.81).exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\VoiceChanger32(1.81).exe
iexplore.exe
User:
admin
Company:
Shark Labs
Integrity Level:
HIGH
Description:
Clownfish Voice Changer Setup
Exit code:
0
Version:
1.81.0.0
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\b6qgx7lp\voicechanger32(1.81).exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3000"C:\Windows\system32\net.exe" start AudiosrvC:\Windows\System32\net.exeVoiceChanger32(1.81).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
3036C:\Windows\system32\net1 stop AudioEndpointBuilderC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
3052C:\Windows\system32\net1 start AudiosrvC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
Total events
12 949
Read events
12 853
Write events
87
Delete events
9

Modification events

(PID) Process:(2624) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPDaysSinceLastAutoMigration
Value:
0
(PID) Process:(2624) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing
Operation:writeName:NTPLastLaunchHighDateTime
Value:
30847387
(PID) Process:(2624) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
30847437
(PID) Process:(2624) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2624) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2624) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2624) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2624) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2624) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2624) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
12
Suspicious files
53
Text files
50
Unknown types
0

Dropped files

PID
Process
Filename
Type
2404iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:7764A5782B02C99F3F4E8B4656E87FDA
SHA256:7950E44815FEF30523EE8A5A2B911E6E63BF2EB53941EBAE3DF55AE92938F5A5
2404iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0255CEC2C51D081EFF40366512890989_39ECE203CA8E83C69BF359CF6C636881binary
MD5:FA709AF12A105C7DE63702C52E5AC816
SHA256:2448A1FDB823A8817EB0B846FB0DEF15D9DA25BE36F020344BB196572BC26D94
2404iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B2FAF7692FD9FFBD64EDE317E42334BA_2DBE917624E9880FE0C7C5570D56E691binary
MD5:D9812C63157A303B9E22F8D6B20775C3
SHA256:9C479E06EF10E2321A407744F40823A94810417B38A35B33DFECF30F3A2FEA30
2404iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0255CEC2C51D081EFF40366512890989_39ECE203CA8E83C69BF359CF6C636881binary
MD5:EBB4DFF2279D943BAE4D8E2AA6DEBF6E
SHA256:4A90BCDEA06BE7A038908352F0F69D1B96E7449355463E6C9CE174A0B4DBEE4C
2404iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\5080DC7A65DB6A5960ECD874088F3328_862BA1770B2FEE013603D2FF9ABEAFDAbinary
MD5:227C826544AA9C3726A15B7C1A98AD59
SHA256:2EE397ADC49B91F67569F08C1D67EF88FBDAD06751AF80EEA6129AE445961614
2404iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\5080DC7A65DB6A5960ECD874088F3328_862BA1770B2FEE013603D2FF9ABEAFDAbinary
MD5:3FE7B6662BF2F48B2451FE9143F62BDC
SHA256:009397F725AA3C04212E6A4F3AA0D55A9643DD6FBC04547CFA989EFB7B00C133
2404iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B2FAF7692FD9FFBD64EDE317E42334BA_2DBE917624E9880FE0C7C5570D56E691binary
MD5:3B0A6CC77FE276C52B92CEE1588C2208
SHA256:9ADA0E1A66D41AE3A687292FE1C94834BC93390459072BE7E4AF0BA9337E2581
2900VoiceChanger32(1.81).exeC:\Users\admin\AppData\Local\Temp\nsrA6CF.tmp\KillProcDLL.dllexecutable
MD5:586270250A1ACCE8126A0877FD5BB981
SHA256:0FE15B023E21B7054FABB3D47B6084D60F8E474D8F9CA3A0A25DCB2097D6F0B8
2900VoiceChanger32(1.81).exeC:\Users\admin\AppData\Local\Temp\nsrA6CF.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
2900VoiceChanger32(1.81).exeC:\Users\admin\AppData\Local\Temp\nsrA6CF.tmp\nsDialogs.dllexecutable
MD5:6C3F8C94D0727894D706940A8A980543
SHA256:56B96ADD1978B1ABBA286F7F8982B0EFBE007D4A48B3DED6A4D408E01D753FE2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
18
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2404
iexplore.exe
GET
304
184.24.77.197:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?da46b50ef2a0354a
unknown
unknown
2404
iexplore.exe
GET
304
184.24.77.197:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a0aa2a2858c872c9
unknown
unknown
2404
iexplore.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEGfe9D7xe9riT%2FWUBgbSwIQ%3D
unknown
binary
1.42 Kb
unknown
2404
iexplore.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69%2BAj36pvE8hI6t7jiY7NkyMtQCEQDwHUvue3yjezwFZqwFlyRY
unknown
binary
2.18 Kb
unknown
2404
iexplore.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSTufqHinruS%2FP9Wi1XSjRRzoTLfAQUfgNaZUFrp34K4bidCOodjh1qx2UCEQCMNI55VIveO8HLhrQ4luHH
unknown
binary
472 b
unknown
2624
iexplore.exe
GET
304
184.24.77.194:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?61accc075785c270
unknown
unknown
2624
iexplore.exe
GET
304
184.24.77.194:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?391819d7795f81a5
unknown
unknown
3756
ClownfishVoiceChanger.exe
GET
200
195.191.149.84:80
http://clownfish-translator.com/voicechanger/version.txt
unknown
text
33 b
unknown
2624
iexplore.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
1080
svchost.exe
GET
304
184.24.77.194:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?aa4b77dd5ef709e5
unknown
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2404
iexplore.exe
195.191.149.84:443
clownfish-translator.com
SuperHosting.BG Ltd.
BG
unknown
2404
iexplore.exe
184.24.77.197:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2404
iexplore.exe
104.18.38.233:80
ocsp.comodoca.com
CLOUDFLARENET
shared
3756
ClownfishVoiceChanger.exe
195.191.149.84:80
clownfish-translator.com
SuperHosting.BG Ltd.
BG
unknown
2624
iexplore.exe
152.199.19.161:443
iecvlist.microsoft.com
EDGECAST
US
whitelisted
2624
iexplore.exe
184.24.77.194:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1080
svchost.exe
184.24.77.194:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
clownfish-translator.com
  • 195.191.149.84
whitelisted
ctldl.windowsupdate.com
  • 184.24.77.197
  • 184.24.77.208
  • 184.24.77.194
  • 184.24.77.193
  • 184.24.77.205
  • 184.24.77.173
  • 184.24.77.210
  • 184.24.77.209
  • 184.24.77.174
whitelisted
ocsp.comodoca.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
api.ispeech.org
  • 173.251.126.244
unknown
translate.google.com
  • 142.250.185.142
whitelisted
tts.voicetech.yandex.net
  • 87.250.250.202
whitelisted
iecvlist.microsoft.com
  • 152.199.19.161
whitelisted
r20swj13mr.microsoft.com
  • 152.199.19.161
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
No debug info