| File name: | 1 (395) |
| Full analysis: | https://app.any.run/tasks/8885f1f4-1831-426f-bdce-831a06539e11 |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2025, 19:48:45 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections |
| MD5: | 8ACE629E44567AF076DE042EBA8B9AA0 |
| SHA1: | EA51BEE61888D0EB171455D22CE7518679672EC3 |
| SHA256: | 1D6A7B074A595CE0DADFD00BD0E44D0C8282F97323B31AAA56A8E278B96C9461 |
| SSDEEP: | 3072:bwBUSwrbrDRCV/9XikWSW24F2zGcR/xxfpfu4hQoLcBuI2:bwBUSwrPDcVZWVFiRvfpfu4hQoLcBuI |
| .exe | | | Win32 Executable Microsoft Visual Basic 6 (90.6) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (4.9) |
| .exe | | | Generic Win/DOS Executable (2.2) |
| .exe | | | DOS Executable Generic (2.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:04:26 10:28:09+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 8192 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13b0 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| ComanyName: | aaaa |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 208 | C:\Users\admin\AppData\Local\Temp\Unicorn-2408.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-2408.exe | Unicorn-37499.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 616 | C:\Users\admin\AppData\Local\Temp\Unicorn-13992.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-13992.exe | Unicorn-2897.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 864 | C:\Users\admin\AppData\Local\Temp\Unicorn-21640.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-21640.exe | — | Unicorn-28937.exe | |||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 896 | C:\Users\admin\AppData\Local\Temp\Unicorn-60453.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-60453.exe | Unicorn-1740.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 968 | C:\Users\admin\AppData\Local\Temp\Unicorn-13390.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-13390.exe | Unicorn-32467.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1056 | C:\Users\admin\AppData\Local\Temp\Unicorn-22763.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-22763.exe | Unicorn-43364.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1180 | C:\Users\admin\AppData\Local\Temp\Unicorn-30137.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-30137.exe | Unicorn-31123.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1324 | C:\Users\admin\AppData\Local\Temp\Unicorn-2897.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-2897.exe | Unicorn-48791.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1616 | C:\Users\admin\AppData\Local\Temp\Unicorn-39129.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-39129.exe | Unicorn-42673.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1812 | C:\Users\admin\AppData\Local\Temp\Unicorn-37703.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-37703.exe | Unicorn-44646.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7584 | Unicorn-21315.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-35055.exe | executable | |
MD5:F92EC86C40420B3052096BAB890763FF | SHA256:6503F854C8BAC66A33AABD3E95CDA3C2DE50B01C145E80F4CB4309DD9483435C | |||
| 6480 | Unicorn-63089.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-650.exe | executable | |
MD5:45CCF49EBB37802BF341EBE7D1F94483 | SHA256:55B2A94922F89D189084DFD1F2FC4A52B6717B841CB6004B792EDD378AE4FF28 | |||
| 8140 | Unicorn-33349.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-63089.exe | executable | |
MD5:442497CEE7472FC0773305A4593A23AD | SHA256:1A44EBD959CB1EE342D6EB9A2040C734674FA1CC5C5AABA83EA78B416FD2671B | |||
| 7320 | 1 (395).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-48791.exe | executable | |
MD5:4961E2CC15204967FE84502C757910A2 | SHA256:8A878C278B8E17F17F4C9F00A511CB8A6E599CCB9B960982F3D1EB6BD1AA11AE | |||
| 7320 | 1 (395).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-21315.exe | executable | |
MD5:B7D45A991C515741D754E089B5C236A9 | SHA256:D6661B49790D872A9398A902E7C0F2CF2F5ECB02C6BD2E7C22C52BBAFE0CB7EF | |||
| 7584 | Unicorn-21315.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-33349.exe | executable | |
MD5:41566FF5EAC83DCC85831254D0B247F5 | SHA256:CC9A2E348E197E34BAB374B8907360193D3CA5EF33EEA02296BB1B4286FD222C | |||
| 8140 | Unicorn-33349.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-7427.exe | executable | |
MD5:C383C38CF5F7734C5DFD0987F7D9D5BD | SHA256:224D471E897369F38A2C8DC8C6FC152214B19874ACD465AF14981CCEEFF71F49 | |||
| 4164 | Unicorn-1636.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-12902.exe | executable | |
MD5:E136ABE5B4D77F6D144C7D1CE2DAD2E5 | SHA256:79AEA4172B40C740FA5BE1EBA7CD8D3F262301A429E39A83D430F406A13B578F | |||
| 8160 | Unicorn-31957.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-31931.exe | executable | |
MD5:F100D2A014FBD541A9D989AFCBD7E600 | SHA256:E3315091C3CCADA1AACDD1C6036CBDCE93C51ACB78E0F64365E40B6DC50A33A9 | |||
| 8160 | Unicorn-31957.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-1636.exe | executable | |
MD5:D2D27F1691992A143FACD627E448781A | SHA256:6EC22B4CD4121B3C666DD27647F286064062B2E5EFAD286F498F72B26C1514CA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6544 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.24.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
9264 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
9264 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7784 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 184.24.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6544 | svchost.exe | 40.126.32.68:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3216 | svchost.exe | 20.197.71.89:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | SG | whitelisted |
6544 | svchost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
2104 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
7784 | backgroundTaskHost.exe | 20.223.36.55:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
7784 | backgroundTaskHost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |