Summary | ZeroBOX

VoiceChangerAi.exe

Gen1 Malicious Library UPX Malicious Packer Anti_VM ftp PE64 PNG Format PE File OS Processor Check ZIP Format DLL icon
Category Machine Started Completed
FILE s1_win7_x6401 Jan. 8, 2024, 7:47 a.m. Jan. 8, 2024, 7:50 a.m.
Size 15.1MB
Type PE32+ executable (GUI) x86-64, for MS Windows
MD5 a95c886c9107dfc61f02274ec206f559
SHA256 df74b92aec13912e659a4f5fe8d9b7613806d49bf0ebfa8bd4e42cb957d3f65f
CRC32 1AAE20CC
ssdeep 393216:zjId074k3meCcGfd0aw2L2tbfRuAW8eb08aQ:fIdZaY5FO2LODdW8egQ
Yara
  • Malicious_Library_Zero - Malicious_Library
  • PE_Header_Zero - PE File Signature
  • IsPE64 - (no description)
  • ftp_command - ftp command
  • UPX_Zero - UPX packed file
  • OS_Processor_Check_Zero - OS Processor Check

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
section _RDATA
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl86t.dll
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tk86t.dll
file C:\Users\test22\AppData\Local\Temp\_MEI25642\libffi-8.dll
file C:\Users\test22\AppData\Local\Temp\_MEI25642\VCRUNTIME140.dll
file C:\Users\test22\AppData\Local\Temp\_MEI25642\libcrypto-3.dll
file C:\Users\test22\AppData\Local\Temp\_MEI25642\libssl-3.dll
file C:\Users\test22\AppData\Local\Temp\_MEI25642\python311.dll
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\iso8859-1.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\macCyrillic.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\iso2022.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\iso8859-13.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\cp869.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\iso2022-jp.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\cp852.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\iso8859-16.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\euc-cn.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\cp1251.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\gb1988.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\symbol.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\macRoman.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\cp1254.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\cp1255.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\iso8859-7.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\macThai.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\cns11643.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\iso8859-15.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\cp857.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\cp775.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\cp737.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\euc-kr.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\iso8859-2.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\iso2022-kr.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\macDingbats.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\big5.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\macIceland.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\cp860.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\cp936.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\cp866.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\iso8859-9.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\macRomania.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\ksc5601.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\iso8859-10.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\iso8859-11.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\gb2312-raw.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\koi8-u.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\jis0201.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\macCentEuro.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\dingbats.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\jis0208.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\cp1250.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\tis-620.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\cp850.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\cp874.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\cp865.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\macGreek.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\cp1253.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\cp863.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tk\pkgIndex.tcl
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Brazil\Acre
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\UCT
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Chile\Continental
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\America\Winnipeg
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Europe\Prague
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Africa\Harare
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Canada\Saskatchewan
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\msgs\da.msg
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Asia\Bishkek
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Australia\Hobart
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Africa\Banjul
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Australia\Lindeman
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\macThai.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Atlantic\Faroe
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\msgs\es_bo.msg
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\America\Santarem
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\SystemV\HST10
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\America\Ensenada
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Antarctica\McMurdo
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\America\Nome
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Africa\Ouagadougou
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\America\Argentina\La_Rioja
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Pacific\Nauru
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\cp866.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Pacific\Ponape
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\msgs\en_au.msg
file C:\Users\test22\AppData\Local\Temp\_MEI25642\_lzma.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI25642\Cryptodome\Cipher\_raw_aesni.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Europe\Kirov
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tk\images\pwrdLogo.eps
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Asia\Tashkent
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\America\Boise
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Asia\Manila
file C:\Users\test22\AppData\Local\Temp\_MEI25642\Cryptodome\Hash\_SHA512.pyd
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\msgs\kl.msg
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Universal
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Africa\Luanda
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Canada\Central
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Asia\Kashgar
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\America\Grand_Turk
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Africa\Ndjamena
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tk\choosedir.tcl
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\msgs\te_in.msg
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\America\Ojinaga
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\America\St_Johns
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\cp949.enc
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\Asia\Aqtau
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\tzdata\US\Central
file C:\Users\test22\AppData\Local\Temp\_MEI25642\tcl\encoding\iso8859-14.enc