File name:

VoiceChanger64f(1.80).exe

Full analysis: https://app.any.run/tasks/68172f0c-596a-40dd-84cb-600612aca3f4
Verdict: Malicious activity
Analysis date: July 24, 2025, 02:51:43
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

AE3109B3AF57F51DD095D190F219682A

SHA1:

1ABA3D5DCB8084C5F6E70855CDB5975ED1D15D6F

SHA256:

9573713822C9DFE73A1135737CE0BF6C31B7973E120FEC8BE107C0DA9B862EF4

SSDEEP:

49152:cJ82xWU3B3zquGsFV4fhONjEDv8lVI09o6emZtG14MNqFriZpssFGbz59SVnuux6:cJ82QEquVNgL8lVq6em2KMe6pLG5uor9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts NET.EXE for service management

      • net.exe (PID: 4060)
      • net.exe (PID: 4232)
      • VoiceChanger64f(1.80).exe (PID: 3392)
      • net.exe (PID: 3852)
      • net.exe (PID: 5236)
    • Registers / Runs the DLL via REGSVR32.EXE

      • VoiceChanger64f(1.80).exe (PID: 3392)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • VoiceChanger64f(1.80).exe (PID: 3392)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • VoiceChanger64f(1.80).exe (PID: 3392)
    • The process creates files with name similar to system file names

      • VoiceChanger64f(1.80).exe (PID: 3392)
    • There is functionality for taking screenshot (YARA)

      • VoiceChanger64f(1.80).exe (PID: 3392)
    • Creates a software uninstall entry

      • VoiceChanger64f(1.80).exe (PID: 3392)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 620)
    • Reads security settings of Internet Explorer

      • ClownfishVoiceChanger.exe (PID: 5780)
  • INFO

    • Reads the computer name

      • VoiceChanger64f(1.80).exe (PID: 3392)
      • APOConfig.exe (PID: 2064)
      • ClownfishVoiceChanger.exe (PID: 5780)
    • Checks supported languages

      • VoiceChanger64f(1.80).exe (PID: 3392)
      • APOConfig.exe (PID: 2064)
      • ClownfishVoiceChanger.exe (PID: 5780)
    • The sample compiled with english language support

      • VoiceChanger64f(1.80).exe (PID: 3392)
    • Creates files in the program directory

      • VoiceChanger64f(1.80).exe (PID: 3392)
    • Create files in a temporary directory

      • VoiceChanger64f(1.80).exe (PID: 3392)
    • Manual execution by a user

      • ClownfishVoiceChanger.exe (PID: 5780)
    • Creates files or folders in the user directory

      • ClownfishVoiceChanger.exe (PID: 5780)
    • Reads the machine GUID from the registry

      • ClownfishVoiceChanger.exe (PID: 5780)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:56:47+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 141824
UninitializedDataSize: 2048
EntryPoint: 0x3640
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.80.0.0
ProductVersionNumber: 1.80.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: Clownfish Voice Changer: The ultimate system wide voice changer for Windows
CompanyName: Shark Labs
FileDescription: Clownfish Voice Changer Setup
FileVersion: 1.80.0.0
InternalName: Clownfish Voice Changer Setup
LegalCopyright: Shark Labs
LegalTrademarks: Clownfish is a freeware. Visit http://clownfish-translator.com/voicechanger/ for more details.
OriginalFileName: VoiceChanger64.exe
ProductName: Clownfish Voice Changer Setup
ProductVersion: 1.80.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
161
Monitored processes
19
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start voicechanger64f(1.80).exe net.exe no specs conhost.exe no specs net1.exe no specs net.exe no specs conhost.exe no specs net1.exe no specs net.exe no specs conhost.exe no specs net1.exe no specs net.exe no specs conhost.exe no specs net1.exe no specs regsvr32.exe no specs regsvr32.exe no specs apoconfig.exe no specs conhost.exe no specs clownfishvoicechanger.exe voicechanger64f(1.80).exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
620 /s "C:\Program Files (x86)\ClownfishVoiceChanger\ClownfshAPO64.dll"C:\Windows\System32\regsvr32.exeregsvr32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1660\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1964C:\WINDOWS\system32\net1 start AudioEndpointBuilderC:\Windows\SysWOW64\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\sechost.dll
2064"C:\Program Files (x86)\ClownfishVoiceChanger\APOConfig.exe"C:\Program Files (x86)\ClownfishVoiceChanger\APOConfig.exeVoiceChanger64f(1.80).exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\clownfishvoicechanger\apoconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
2596\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3392"C:\Users\admin\AppData\Local\Temp\VoiceChanger64f(1.80).exe" C:\Users\admin\AppData\Local\Temp\VoiceChanger64f(1.80).exe
explorer.exe
User:
admin
Company:
Shark Labs
Integrity Level:
HIGH
Description:
Clownfish Voice Changer Setup
Exit code:
0
Version:
1.80.0.0
Modules
Images
c:\users\admin\appdata\local\temp\voicechanger64f(1.80).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3480\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeAPOConfig.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3852"C:\WINDOWS\system32\net.exe" start AudioEndpointBuilderC:\Windows\SysWOW64\net.exeVoiceChanger64f(1.80).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\net.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
3976"C:\Users\admin\AppData\Local\Temp\VoiceChanger64f(1.80).exe" C:\Users\admin\AppData\Local\Temp\VoiceChanger64f(1.80).exeexplorer.exe
User:
admin
Company:
Shark Labs
Integrity Level:
MEDIUM
Description:
Clownfish Voice Changer Setup
Exit code:
3221226540
Version:
1.80.0.0
Modules
Images
c:\users\admin\appdata\local\temp\voicechanger64f(1.80).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4060"C:\WINDOWS\system32\net.exe" stop AudiosrvC:\Windows\SysWOW64\net.exeVoiceChanger64f(1.80).exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\net.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
Total events
1 862
Read events
1 637
Write events
223
Delete events
2

Modification events

(PID) Process:(3392) VoiceChanger64f(1.80).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\ClownfishVoiceChanger
Operation:writeName:Install_Dir
Value:
C:\Program Files (x86)\ClownfishVoiceChanger
(PID) Process:(3392) VoiceChanger64f(1.80).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ClownfishVoiceChanger
Operation:writeName:DisplayName
Value:
Clownfish Voice Changer
(PID) Process:(3392) VoiceChanger64f(1.80).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ClownfishVoiceChanger
Operation:writeName:UninstallString
Value:
"C:\Program Files (x86)\ClownfishVoiceChanger\uninstall.exe"
(PID) Process:(3392) VoiceChanger64f(1.80).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ClownfishVoiceChanger
Operation:writeName:NoModify
Value:
1
(PID) Process:(3392) VoiceChanger64f(1.80).exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ClownfishVoiceChanger
Operation:writeName:NoRepair
Value:
1
(PID) Process:(620) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AudioEngine\AudioProcessingObjects\{80E0C6D1-9465-43B2-9BD5-27A3A56CF1B3}
Operation:writeName:FriendlyName
Value:
ClownfishAPO
(PID) Process:(620) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AudioEngine\AudioProcessingObjects\{80E0C6D1-9465-43B2-9BD5-27A3A56CF1B3}
Operation:writeName:Copyright
Value:
Developed in Shark Labs, Sofia, 2016-2023
(PID) Process:(620) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AudioEngine\AudioProcessingObjects\{80E0C6D1-9465-43B2-9BD5-27A3A56CF1B3}
Operation:writeName:MajorVersion
Value:
1
(PID) Process:(620) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AudioEngine\AudioProcessingObjects\{80E0C6D1-9465-43B2-9BD5-27A3A56CF1B3}
Operation:writeName:MinorVersion
Value:
0
(PID) Process:(620) regsvr32.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AudioEngine\AudioProcessingObjects\{80E0C6D1-9465-43B2-9BD5-27A3A56CF1B3}
Operation:writeName:Flags
Value:
15
Executable files
9
Suspicious files
2
Text files
47
Unknown types
39

Dropped files

PID
Process
Filename
Type
3392VoiceChanger64f(1.80).exeC:\Users\admin\AppData\Local\Temp\nskCAB0.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
3392VoiceChanger64f(1.80).exeC:\Users\admin\AppData\Local\Temp\nskCAB0.tmp\KillProcDLL.dllexecutable
MD5:586270250A1ACCE8126A0877FD5BB981
SHA256:0FE15B023E21B7054FABB3D47B6084D60F8E474D8F9CA3A0A25DCB2097D6F0B8
3392VoiceChanger64f(1.80).exeC:\Users\admin\AppData\Local\Temp\nskCAB0.tmp\System.dllexecutable
MD5:CFF85C549D536F651D4FB8387F1976F2
SHA256:8DC562CDA7217A3A52DB898243DE3E2ED68B80E62DDCB8619545ED0B4E7F65A8
3392VoiceChanger64f(1.80).exeC:\Program Files (x86)\ClownfishVoiceChanger\res\Alien.icoimage
MD5:B4912B4E5AC58C1DA8DEB5834E3C366B
SHA256:99D1D4618D0AC84F70B30334C94208C617C76F8F1604F665F8DC5C424E638F4D
3392VoiceChanger64f(1.80).exeC:\Program Files (x86)\ClownfishVoiceChanger\ClownfshAPO64.dllexecutable
MD5:D048BE47EE5D18DC78B90873F9E3C300
SHA256:E423958D600F19B5B20BE5E8F855640DD28699F55DB14A61BA556D735955B364
3392VoiceChanger64f(1.80).exeC:\Program Files (x86)\ClownfishVoiceChanger\AudioChanger.exeexecutable
MD5:0CE719B8BE5385517A8D2B1152B81CB5
SHA256:D1314CDDFDA3B2F09C37D5BCCA4DDD03C59D0DB650FF1C82ECD62F4D806DA49C
3392VoiceChanger64f(1.80).exeC:\Program Files (x86)\ClownfishVoiceChanger\ClownfishVoiceChanger.exeexecutable
MD5:D938D8D428318A28580E197E28C258C0
SHA256:F8EEC01DFC8F1CDB1CC3D9E8FAEF83CE84E050DE30A22785EE4EBBD741FA07D2
3392VoiceChanger64f(1.80).exeC:\Program Files (x86)\ClownfishVoiceChanger\res\Cave-Off.icoimage
MD5:FC40DFADE66AB7CF24962BCA246834C0
SHA256:671D371F7B2F07FC7B1E8EA9F0AB1BDF2A9055E79F3C859B19B6F579FC17987F
3392VoiceChanger64f(1.80).exeC:\Program Files (x86)\ClownfishVoiceChanger\res\Atari-Off.icoimage
MD5:6F984A4938BA524BA9657D3C63845790
SHA256:6DF6A6464C72AF219094CF3787CF0D1F858E2FD3B6C5CC213DEECABD911769AF
3392VoiceChanger64f(1.80).exeC:\Program Files (x86)\ClownfishVoiceChanger\res\Cave.icoimage
MD5:F8B303268883F3500B9723C5F82843D2
SHA256:716CC28267DCDAFD13CA183D11FD74394F7E55063874D5C19A088EC40E225590
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
24
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
3940
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5780
ClownfishVoiceChanger.exe
GET
200
195.191.149.84:80
http://clownfish-translator.com/voicechanger/version.txt
unknown
whitelisted
3688
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5780
ClownfishVoiceChanger.exe
GET
200
195.191.149.84:80
http://clownfish-translator.com/voicechanger/versioninfo.txt
unknown
whitelisted
3688
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3288
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3940
svchost.exe
20.190.160.132:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
  • 20.73.194.208
whitelisted
google.com
  • 142.250.185.238
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.42
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
login.live.com
  • 20.190.160.132
  • 20.190.160.67
  • 20.190.160.128
  • 40.126.32.68
  • 40.126.32.138
  • 20.190.160.66
  • 20.190.160.17
  • 40.126.32.134
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
api.ispeech.org
  • 173.251.126.244
whitelisted
translate.google.com
  • 142.250.186.142
whitelisted
tts.voicetech.yandex.net
  • 87.250.250.202
whitelisted
clownfish-translator.com
  • 195.191.149.84
whitelisted

Threats

No threats detected
No debug info