12f0163df05421e58d28e8052eeb375fd843711638f29f720ab87e8ced53d3be

Summary

Architecture IMAGE_FILE_MACHINE_I386
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 2021-Sep-25 21:56:47
Detected languages English - United States
Comments Clownfish Voice Changer: The ultimate system wide voice changer for Windows
CompanyName Shark Labs
FileDescription Clownfish Voice Changer Setup
FileVersion 1.98.0.0
InternalName Clownfish Voice Changer Setup
LegalCopyright Shark Labs
LegalTrademarks Clownfish is a freeware. Visit http://clownfish-translator.com/voicechanger/ for more details.
OriginalFilename VoiceChanger64.exe
ProductName Clownfish Voice Changer Setup
ProductVersion 1.98.0.0

Plugin Output

Info Interesting strings found in the binary: Contains domain names:
  • clownfish-translator.com
  • http://clownfish-translator.com
  • http://nsis.sf.net
  • http://nsis.sf.net/NSIS_Error
  • nsis.sf.net
  • translator.com
Suspicious The PE is an NSIS installer Unusual section name found: .ndata
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • GetProcAddress
  • LoadLibraryExW
Can access the registry:
  • RegCreateKeyExW
  • RegEnumKeyW
  • RegQueryValueExW
  • RegSetValueExW
  • RegCloseKey
  • RegDeleteValueW
  • RegDeleteKeyW
  • RegOpenKeyExW
  • RegEnumValueW
Possibly launches other programs:
  • CreateProcessW
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Functions related to the privilege level:
  • AdjustTokenPrivileges
  • OpenProcessToken
Changes object ACLs:
  • SetFileSecurityW
Can shut the system down or lock the screen:
  • ExitWindowsEx
Info The PE is digitally signed. Signer: Bogdan Blagoev Sharkov
Issuer: Certum Code Signing 2021 CA
Safe VirusTotal score: 0/72 (Scanned on 2026-03-21 09:44:12) All the AVs think this file is safe.

Hashes

MD5 2827692f64b73b9f7ea0122bee7fe1cc
SHA1 f2704c53fce9aaf39c733f0f51ecc68805402849
SHA256 12f0163df05421e58d28e8052eeb375fd843711638f29f720ab87e8ced53d3be
SHA3 815eb204abdfcc8f2581eed7bbdf66593bf0a83b57860ccd8739f771f169e957
SSDeep 24576:IYjR/E6HtAJlbUfG8GDVajCoGjQtMpARiETCuG4XSvrMQ8j6:ZxEkObdZRBoGjYIctG6Sve6
Imports Hash 61259b55b8912888e90f516ca08dc514

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xd8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_I386
NumberofSections 5
TimeDateStamp 2021-Sep-25 21:56:47
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xe0
Characteristics IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED

Image Optional Header

Magic PE32
LinkerVersion 6.0
SizeOfCode 0x6800
SizeOfInitializedData 0x22a00
SizeOfUninitializedData 0x800
AddressOfEntryPoint 0x00003640 (Section: .text)
BaseOfCode 0x1000
BaseOfData 0x8000
ImageBase 0x400000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion 4.0
ImageVersion 6.0
SubsystemVersion 4.0
Win32VersionValue 0
SizeOfImage 0x5a000
SizeOfHeaders 0x400
Checksum 0x1502a6
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x100000
SizeofStackCommit 0x1000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 6f5abe9eeda26ee84b3c1ed1a6c82001
SHA1 55517dc6ad93689679677d152abfdd1ce20f1135
SHA256 6683c31450d22725f8046313577f87ed284052143421d41ca971ebf03a732b4a
SHA3 0166ffe9450ef9b8cd85513de36173358cc6d06134a32f515f12aa858073020f
VirtualSize 0x6676
VirtualAddress 0x1000
SizeOfRawData 0x6800
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.41746

.rdata

MD5 8c5edfd8ff9cc0135e197611be38ca18
SHA1 dc4f14d019cad6646b38852dfb7370532acafebc
SHA256 95df72950424a97746c83c619f9aa736879b408a87751927b5d41994e8183a9c
SHA3 b74f8f6ea5fb7e429da44419f9d163743fd38ce97f3b9819fb2397744d42dad2
VirtualSize 0x139a
VirtualAddress 0x8000
SizeOfRawData 0x1400
PointerToRawData 0x6c00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.14107

.data

MD5 4b2421975c21b032f7ea000f5e7f9fbf
SHA1 f45486287d474fdcafc99c24e37c4eb61bf613b3
SHA256 f05daf3c91cc357d04794a740f21eaaeb870f250877e3a6dc498c5c3046cb414
SHA3 03ddd58bddd9af320b79e443521aae041b4098e328b842349f29c2bda6bdb122
VirtualSize 0x20378
VirtualAddress 0xa000
SizeOfRawData 0x600
PointerToRawData 0x8000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 4.11058

.ndata

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x2a000
VirtualAddress 0x2b000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rsrc

MD5 ca3c00c9440952879f06bef3ca2f9084
SHA1 1817e5f2be293c8e4b10a6aab2925ef5e0822d45
SHA256 a6a01123bc9c42015123b31e57ba7079d718fb565188921cefdb29b7c8587045
SHA3 0bb430f198152ae4ec168783fdd6957eae70a0c6a961491d769e198aefd50b40
VirtualSize 0x4fa8
VirtualAddress 0x55000
SizeOfRawData 0x5000
PointerToRawData 0x8600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 2.99114

Imports

ADVAPI32.dll RegCreateKeyExW
RegEnumKeyW
RegQueryValueExW
RegSetValueExW
RegCloseKey
RegDeleteValueW
RegDeleteKeyW
AdjustTokenPrivileges
LookupPrivilegeValueW
OpenProcessToken
SetFileSecurityW
RegOpenKeyExW
RegEnumValueW
SHELL32.dll SHGetSpecialFolderLocation
SHFileOperationW
SHBrowseForFolderW
SHGetPathFromIDListW
ShellExecuteExW
SHGetFileInfoW
ole32.dll OleInitialize
OleUninitialize
CoCreateInstance
IIDFromString
CoTaskMemFree
COMCTL32.dll #17
ImageList_Create
ImageList_Destroy
ImageList_AddMasked
USER32.dll GetClientRect
EndPaint
DrawTextW
IsWindowEnabled
DispatchMessageW
wsprintfA
CharNextA
CharPrevW
MessageBoxIndirectW
GetDlgItemTextW
SetDlgItemTextW
GetSystemMetrics
FillRect
AppendMenuW
TrackPopupMenu
OpenClipboard
SetClipboardData
CloseClipboard
IsWindowVisible
CallWindowProcW
GetMessagePos
CheckDlgButton
LoadCursorW
SetCursor
GetSysColor
SetWindowPos
GetWindowLongW
PeekMessageW
SetClassLongW
GetSystemMenu
EnableMenuItem
GetWindowRect
ScreenToClient
EndDialog
RegisterClassW
SystemParametersInfoW
CreateWindowExW
GetClassInfoW
DialogBoxParamW
CharNextW
ExitWindowsEx
DestroyWindow
CreateDialogParamW
SetTimer
SetWindowTextW
PostQuitMessage
SetForegroundWindow
ShowWindow
wsprintfW
SendMessageTimeoutW
FindWindowExW
IsWindow
GetDlgItem
SetWindowLongW
LoadImageW
GetDC
ReleaseDC
EnableWindow
InvalidateRect
SendMessageW
DefWindowProcW
BeginPaint
EmptyClipboard
CreatePopupMenu
GDI32.dll SetBkMode
SetBkColor
GetDeviceCaps
CreateFontIndirectW
CreateBrushIndirect
DeleteObject
SetTextColor
SelectObject
KERNEL32.dll GetExitCodeProcess
WaitForSingleObject
GetModuleHandleA
GetProcAddress
GetSystemDirectoryW
lstrcatW
Sleep
lstrcpyA
WriteFile
GetTempFileNameW
lstrcmpiA
RemoveDirectoryW
CreateProcessW
CreateDirectoryW
GetLastError
CreateThread
GlobalLock
GlobalUnlock
GetDiskFreeSpaceW
WideCharToMultiByte
lstrcpynW
lstrlenW
SetErrorMode
GetVersionExW
GetCommandLineW
GetTempPathW
GetWindowsDirectoryW
SetEnvironmentVariableW
CopyFileW
ExitProcess
GetCurrentProcess
GetModuleFileNameW
GetFileSize
CreateFileW
GetTickCount
MulDiv
SetFileAttributesW
GetFileAttributesW
SetCurrentDirectoryW
MoveFileW
GetFullPathNameW
GetShortPathNameW
SearchPathW
CompareFileTime
SetFileTime
CloseHandle
lstrcmpiW
lstrcmpW
ExpandEnvironmentStringsW
GlobalFree
GlobalAlloc
GetModuleHandleW
LoadLibraryExW
MoveFileExW
FreeLibrary
WritePrivateProfileStringW
GetPrivateProfileStringW
lstrlenA
MultiByteToWideChar
ReadFile
SetFilePointer
FindClose
FindNextFileW
FindFirstFileW
DeleteFileW

Delayed Imports

110

Type RT_BITMAP
Language English - United States
Codepage UNKNOWN
Size 0x666
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.82633
MD5 b6bf70baab40fe438feff063bfb9ff6f
SHA1 7d4659d43e08d368ddacd31945872461c0b06253
SHA256 0e90a9e4b8f3a5bf990e8aadfd8096ad7aeaf1a4e032ac7b6395ce191d61c142
SHA3 cab98fabaf20118d9a8a4d2bcff4383a7291a0e04ff11a8690e71eed619c75e7
Preview

1

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x10a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.77815
Detected Filetype PNG graphic file
MD5 dd0a4ef8c5f9a08ba6f153849d71b373
SHA1 0f17f8892c02dee7fc50627a07e711a71ea41ed7
SHA256 cc85d7c4e337ac957849cd38c73b38383bd3375fcbe2233a2a13647dad0127b9
SHA3 83f9cbdcd1f99991f768b4d122aa335ec14b99d2e1a11b897db7514b0b6cb3eb

2

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0xea8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 0d3a12fd3f68decc694da04b57e61d8c
SHA1 f73d4d591f6ef0b2b04fc90d2e840329f7590743
SHA256 ee0352f75df1009fa6f5eaf323a1ed55c127cc679ac6b9de70b1b3f8dc9ece76
SHA3 42ec79da319d9c0b1f8ee21fbb28002d15857d9af0c8a1f2db5e41f6c5e23c88

3

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x8a8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 28f8d082df931688124f25f23c688904
SHA1 2f057655ecdd3ab25cfe985714e270786ce16cae
SHA256 4e7a8c59942ff527ff680aa88cc66bb8c8e7b6c02a018bc85ba36794e278670f
SHA3 99f004163a598b6df87372bd9b7d5e7704dbfdf7cfb3ec96da9e31c0275f7465

4

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x568
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 a42b23f1c58701e073db2e9de0b27333
SHA1 f22232cbadff165ceb212527a6d77124312d0688
SHA256 e253c6a87bdd62e771c0ef1b9850dbc9523c51408ca282f994d3530dbbad9b11
SHA3 bc93a26ac3218cac12b89fa3242b509e44b087d2c22a54d9a47c63692dc8dc57

5

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x468
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 7e1b34650fb04bc15a494a1d712cffee
SHA1 43e1808e4308baf093556946552f4fabc05278d8
SHA256 3731b0a75ab19d96b774da62d37eccacd517c6593af20aa66525dc0b951cdba9
SHA3 79a9c096a1a56ae4f98f1e8ad4c44fa5c08e5d98e745898df9031e3b3a13c46c

6

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x2e8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 809457c05fe696f5d34ac5ac8768cdd4
SHA1 a2c3e4966415100c7d24f7f3dc7e27d2a60d20c9
SHA256 1b66520d471367f736d50c070a2e2bba8ad88ac58743394a764b888e9cb6f6be
SHA3 002d1b10f28d74c7572fc7c5b403eb32f2a0540c4958d7878ef67edfd17c8109

7

Type RT_ICON
Language English - United States
Codepage UNKNOWN
Size 0x128
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0
MD5 982079681d7ad12766abc44f06946f3e
SHA1 50f73ed0787bf5911bb907e487efbc84a9714e48
SHA256 250f52cb2d6f1966a29f6ac771fa1cd185b8f8531396c8a4026c0fe635617e0c
SHA3 b8805d45012d79cfa8bb45e23c9b4a4421cd91538d569e58437efa0f545cf4d4

103

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x120
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.56193
MD5 db6dd0434da4d7cac564518725167e09
SHA1 a65a1367d7cd96450f089a8f8108239bbcea9f5b
SHA256 c50631fc1f8425a95fd1edcc8e730d339e193a38f18d42372c32847a5ad2c016
SHA3 4e3be5455c51e1cb04836e318cb69ecdffd2deadd0f338d4bc985d8f5ca653ff

104

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x158
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.70411
MD5 9bf5ce4f6c93b09e4f5659e204c7ef69
SHA1 70260f4f07476e289d4f0da08f6ea81edf377c05
SHA256 4978808cfa3a9f541262585edca9b87268d2025e637f7254b269cef216b39a79
SHA3 006381732c2dfc87ce25f0b93f7446bbeb1549e901e375f8a720af89e0ef211a

105

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0x202
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.73893
MD5 386770584473e271f23dced36427f4ff
SHA1 d14ce95f784b35e4e3ebee535476ebcd3e380c19
SHA256 425b8270f7ca42a927eae6bea468acf414a3e4b58b5ba2c56aaae4d1b2c11014
SHA3 db13e5969376b27e8443eebff685230e2b74685aeb2fba73973f06e5cddc8662

106

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xf8
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.91148
MD5 fa83652660409e90e0db9731ad2adb17
SHA1 0a8f0af67723c87fe26ccf676b8e19ec6357b4dc
SHA256 4a55bd714f5d50cd8eabba10e57f0618f1842717dcfa582d73a917b1933cd1d4
SHA3 5b3e1cb25be7a2dbae4f08f0d4794ed23dbd6ea37a3f9702be12dba588f42a7b

111

Type RT_DIALOG
Language English - United States
Codepage UNKNOWN
Size 0xee
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.92767
MD5 1db3e4c32b9560257ddf3506fef9dd3f
SHA1 6666e0c8336456cfacec71d84415c6516e9e2673
SHA256 587a03198c39f990e77691056bb5705e21374281862ce06de94c68172f50f763
SHA3 30ca0affc3f1d2ef8b37f2103db7581caaf88548823fb3ae1d308fae9738dab4

103 (#2)

Type RT_GROUP_ICON
Language English - United States
Codepage UNKNOWN
Size 0x68
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 0.576486
Detected Filetype Icon file
MD5 2a67efacbffea8c92810c75cded6723f
SHA1 e6461afa6b61ba49ad140a349c8ec7bb874405bf
SHA256 67c6404cab2b66fe073a476efcd41a1051a3ffcbcad702f98071bc2441cbfbf1
SHA3 c033d518d50dab69ae2587ede9a5c281bc045d28afba28f067f470ebfdf8b08a

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x4c4
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.36651
MD5 7c0166420bb70efab87bbdf918da2fee
SHA1 840def8fe5ecae1592ee65ffef4c5c1e3c3eef0a
SHA256 b80f0d3213f17f098a03b14f0479bb3de37b82553708953b8ae8e6d36165d3e7
SHA3 a484c1ad3548d23d5a3e85329996c4f6e4c32377ddcc7b7da771890231cedc37

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x42e
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 5.28834
MD5 5ee6190e98bb9546fc0551de48610550
SHA1 dd7f27311a739a7ccf8222c022f631361240c3b9
SHA256 a01b1e9b03ff72f72efff34927cef73a3e6f6b7e2beed90120cbde3ad41de1f0
SHA3 f3ad692e880902439757fb96c355d7094e7b7773681ed70ec19e6d569f8e611b

Version Info

Signature 0xfeef04bd
StructVersion 0
FileVersion 1.98.0.0
ProductVersion 1.98.0.0
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT_WINDOWS32
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
Comments Clownfish Voice Changer: The ultimate system wide voice changer for Windows
CompanyName Shark Labs
FileDescription Clownfish Voice Changer Setup
FileVersion (#2) 1.98.0.0
InternalName Clownfish Voice Changer Setup
LegalCopyright Shark Labs
LegalTrademarks Clownfish is a freeware. Visit http://clownfish-translator.com/voicechanger/ for more details.
OriginalFilename VoiceChanger64.exe
ProductName Clownfish Voice Changer Setup
ProductVersion (#2) 1.98.0.0
Resource LangID English - United States

TLS Callbacks

Load Configuration

RICH Header

XOR Key 0xd26650e9
Unmarked objects 0
C objects (VS2003 (.NET) build 4035) 2
Total imports 165
Imports (VS2003 (.NET) build 4035) 15
48 (9044) 10
Resource objects (VS98 SP6 cvtres build 1736) 1

Errors

[*] Warning: Section .ndata has a size of 0!
Leave a comment

No comments yet.