| File name: | Kawaii-Unicorn.exe |
| Full analysis: | https://app.any.run/tasks/8a3b0b2c-4d54-47cc-a6f3-5a680ec69e7b |
| Verdict: | Malicious activity |
| Analysis date: | August 23, 2024, 02:15:30 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | C9E1C2CE804E82476E7BAF8500CDDD5B |
| SHA1: | 2CB03DD12B0ADF0469D79957A27B8C8723A721C6 |
| SHA256: | 2428265DBF3AFA15F6DA7C56233DACE4FF0BA2700E4CD7C9E8330EDFB5CD794B |
| SSDEEP: | 3072:qAeQF3V/0DUCVBNXikWNWf4u6zEuDoxMfpfu4hQoLcBuIX:qAeQF3V8D9FZW3us0Sfpfu4hQoLcBuI |
| .exe | | | Win32 Executable Microsoft Visual Basic 6 (90.6) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (4.9) |
| .exe | | | Generic Win/DOS Executable (2.2) |
| .exe | | | DOS Executable Generic (2.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:04:26 10:28:09+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 8192 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13b0 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| ComanyName: | aaaa |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 184 | C:\Users\admin\Downloads\Unicorn-19427.exe | C:\Users\admin\Downloads\Unicorn-19427.exe | Unicorn-30717.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 240 | C:\Users\admin\Downloads\Unicorn-19392.exe | C:\Users\admin\Downloads\Unicorn-19392.exe | Unicorn-11443.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 292 | C:\Users\admin\Downloads\Unicorn-2403.exe | C:\Users\admin\Downloads\Unicorn-2403.exe | Unicorn-44852.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 312 | C:\Users\admin\Downloads\Unicorn-28045.exe | C:\Users\admin\Downloads\Unicorn-28045.exe | Unicorn-36109.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 524 | C:\Users\admin\Downloads\Unicorn-59456.exe | C:\Users\admin\Downloads\Unicorn-59456.exe | Unicorn-2403.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 568 | C:\Users\admin\Downloads\Unicorn-39677.exe | C:\Users\admin\Downloads\Unicorn-39677.exe | Unicorn-11443.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 660 | C:\Users\admin\Downloads\Unicorn-2214.exe | C:\Users\admin\Downloads\Unicorn-2214.exe | Unicorn-63773.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 680 | C:\Users\admin\Downloads\Unicorn-42515.exe | C:\Users\admin\Downloads\Unicorn-42515.exe | — | Unicorn-3244.exe | |||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 748 | C:\Users\admin\Downloads\Unicorn-21997.exe | C:\Users\admin\Downloads\Unicorn-21997.exe | Unicorn-49565.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 832 | C:\Users\admin\Downloads\Unicorn-25971.exe | C:\Users\admin\Downloads\Unicorn-25971.exe | Unicorn-49876.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2788 | Kawaii-Unicorn.exe | C:\Users\admin\Downloads\Unicorn-64397.exe | executable | |
MD5:E857284183B2CD99BA225D49B4609E49 | SHA256:83EEC306AFB91D176866E4BDC36CD6536E002AF3939ADEFDDA00A68442A5AB20 | |||
| 2484 | Unicorn-64397.exe | C:\Users\admin\Downloads\Unicorn-64989.exe | executable | |
MD5:19EF49BAEBB2F1A82279BBA7A0759135 | SHA256:E29253344F376A990686DE074EDE872A787F85F60EC585EA556A8E54E98FA20E | |||
| 2788 | Kawaii-Unicorn.exe | C:\Users\admin\Downloads\Unicorn-28787.exe | executable | |
MD5:EBE7E0A5552C686AA49653043301039B | SHA256:AEC67F7655EB73664DCBCBEB0B008D5D9F0FA3BD9B9F27EB58FFEF7C08D93093 | |||
| 2436 | Unicorn-28787.exe | C:\Users\admin\Downloads\Unicorn-12140.exe | executable | |
MD5:16A95C92B2758EBC946B45BFD362C681 | SHA256:E07750DBC3328A4A3D5E3B508E475A6185BCE8A29E34BAE8D2974BBBFFD90E36 | |||
| 2484 | Unicorn-64397.exe | C:\Users\admin\Downloads\Unicorn-25139.exe | executable | |
MD5:18825A51758362993D2CA4AC89591FE3 | SHA256:13BE0396619387CA84636A470EC0845359D8183E3B6CEFFAB04ED0AAF546E7A9 | |||
| 2788 | Kawaii-Unicorn.exe | C:\Users\admin\Downloads\Unicorn-38875.exe | executable | |
MD5:CAEAB1EAB561F1E174C4A81296268D7D | SHA256:C809E95C28E4B1829E19FD970E6DAF365DC9D29880B3BCD54C76E45E8000C009 | |||
| 2040 | Unicorn-12140.exe | C:\Users\admin\Downloads\Unicorn-64909.exe | executable | |
MD5:CC6209CA245B0E1DCF37FCAFE7B11FB2 | SHA256:BCAA19D272BB91C24DA50B422C6CFE8DEA80C1FFCFA6AE5A76502E1EBABF19C8 | |||
| 2460 | Unicorn-64989.exe | C:\Users\admin\Downloads\Unicorn-10918.exe | executable | |
MD5:2F29E0353F73C271467ECAC04D93E74E | SHA256:133364EFDDB83B3D503D55C65787796DC999B3E80DB4ECB9BF74E9FD18D5E550 | |||
| 2436 | Unicorn-28787.exe | C:\Users\admin\Downloads\Unicorn-44852.exe | executable | |
MD5:1E0C1926475FFAD1C3629EAD6FBF42F8 | SHA256:F54003AA83FFFD85F1924E1E96A4041FE5121A4CD39B08265532BC42BF086488 | |||
| 2460 | Unicorn-64989.exe | C:\Users\admin\Downloads\Unicorn-61291.exe | executable | |
MD5:6E5DFDB659C2686A33E06F03C731C0B8 | SHA256:75C4C147F54C68325D15EB2860FE9B39997FD0419A80D2818B393D36FAB15EB8 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1372 | svchost.exe | GET | 304 | 23.50.131.200:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33 | unknown | — | — | whitelisted |
1372 | svchost.exe | GET | 200 | 23.32.238.107:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1372 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1060 | svchost.exe | GET | 304 | 199.232.214.172:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?8f69642324cc87bd | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
— | — | 239.255.255.250:3702 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1060 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
1372 | svchost.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
1372 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1372 | svchost.exe | 23.50.131.200:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
1372 | svchost.exe | 23.32.238.107:80 | crl.microsoft.com | Akamai International B.V. | DE | unknown |
1372 | svchost.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |