| File name: | 1 (1454) |
| Full analysis: | https://app.any.run/tasks/2281df8f-4212-4cd5-b8b1-cf820560d218 |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2025, 13:53:12 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections |
| MD5: | E47541B98668F7453A4996ACE422E3D0 |
| SHA1: | 05BC6E1DF861E03B699306E37275C355F7384864 |
| SHA256: | 2657FEB48740D0AAE79B697D5DB86E679CFAF4FF5E1B67CB818CCCB635B4C556 |
| SSDEEP: | 6144:OCdgd7+wQDAHA9h4H7sqKofx5pBEovJGBa/WpSaCNk/8SwjwpyAOEhTt1sUUYNWt:OcUyYHA9eHQMBbhaaOpSaCBx4DxDsR |
| .exe | | | Win32 Executable Microsoft Visual Basic 6 (90.6) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (4.9) |
| .exe | | | Generic Win/DOS Executable (2.2) |
| .exe | | | DOS Executable Generic (2.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:01:19 13:34:56+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 299008 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13d4 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | UEFI |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProdctVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 208 | C:\Users\admin\AppData\Local\Temp\Unicorn-12721.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-12721.exe | Unicorn-50718.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 684 | C:\Users\admin\AppData\Local\Temp\Unicorn-37920.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-37920.exe | — | Unicorn-27418.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 728 | C:\Users\admin\AppData\Local\Temp\Unicorn-57032.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-57032.exe | Unicorn-4079.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 736 | C:\Users\admin\AppData\Local\Temp\Unicorn-29058.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-29058.exe | Unicorn-62970.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 904 | C:\Users\admin\AppData\Local\Temp\Unicorn-45586.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-45586.exe | Unicorn-5964.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 960 | C:\Users\admin\AppData\Local\Temp\Unicorn-35586.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-35586.exe | Unicorn-37380.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1240 | C:\Users\admin\AppData\Local\Temp\Unicorn-5108.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-5108.exe | Unicorn-27802.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1272 | C:\Users\admin\AppData\Local\Temp\Unicorn-24081.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-24081.exe | Unicorn-44994.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1328 | C:\Users\admin\AppData\Local\Temp\Unicorn-46892.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-46892.exe | Unicorn-3769.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1348 | C:\Users\admin\AppData\Local\Temp\Unicorn-46826.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-46826.exe | Unicorn-49976.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7576 | Unicorn-42394.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-38864.exe | executable | |
MD5:45D812D87B9C1E06B3F2A339C6AAD145 | SHA256:CCDEEF52E4F742B33E58AD568BD27AAE80CA105BADDEFC822627D863FC0F71CA | |||
| 7200 | Unicorn-55326.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-3769.exe | executable | |
MD5:42B5D4ECCB9D602F82C8E8C9A96649BE | SHA256:0904C93D1BCCA319C349F961224036F83196BFC8972216BF48B95E3D07B4FC2B | |||
| 5512 | Unicorn-12772.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-10209.exe | executable | |
MD5:2DC8E4D5D283C6B7405E1BE17B2D4B57 | SHA256:2DB2D8D0BD6A2BEA867CB8517298D355E735B3973456AD1BFF87B4ACDD0925F8 | |||
| 8172 | Unicorn-20002.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-57609.exe | executable | |
MD5:838A36CC2B10946263A1DC5D4A4DB592 | SHA256:7F8BFE724BE058A346B0CE6B07F9C285E1D6225E0D959C467468CE602804813E | |||
| 4448 | Unicorn-57609.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-27802.exe | executable | |
MD5:ACCB328A442D2C0C2C89CB5D677D5B9D | SHA256:4B2769504C313BBA8E2A17B2E408CC2BD7D234CDE0126F2643C4578C52EBFC5E | |||
| 7360 | 1 (1454).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-12772.exe | executable | |
MD5:FB004CFBA3496D1DD6509057D234A1AD | SHA256:31828099DBFBA5CFE2626F5E993E0F27E03D6F9F7CC62514E6E5551935B2A26E | |||
| 7272 | Unicorn-3769.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-55430.exe | executable | |
MD5:7B2145876DA6EB9D8AB06286C5093631 | SHA256:C0094CC2EFBFE87511E814D328186EEAE42299185F0ABCA6AC2D47B20C67BFA2 | |||
| 7360 | 1 (1454).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-42394.exe | executable | |
MD5:1397BCD7B109F722A89EC103EEA04480 | SHA256:090477CB31A80F415E1C1EA27EA444E7E3270C346EF13594CD53D99FE03422DE | |||
| 7576 | Unicorn-42394.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-47713.exe | executable | |
MD5:73B6C5E7D1B84DB103E8C29F768E35F0 | SHA256:988B39943445692A94B42E5C46CF5512AA9183FDBC6F1626A02DCA88694F2AED | |||
| 7360 | 1 (1454).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-4079.exe | executable | |
MD5:1B7F64258C6CEAD3E3F9A8332A676A96 | SHA256:9A1AE66732ED0126DE0E77CDE24D308B8C61AAF1BF66313F077A37FEE0C71E35 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.48.23.180:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
9048 | SIHClient.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | unknown |
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | unknown |
7900 | backgroundTaskHost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | unknown |
9048 | SIHClient.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
— | — | 23.48.23.180:80 | crl.microsoft.com | Akamai International B.V. | DE | unknown |
5496 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
6544 | svchost.exe | 20.190.160.67:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
6544 | svchost.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | unknown |
3216 | svchost.exe | 20.197.71.89:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | SG | unknown |
2104 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
7900 | backgroundTaskHost.exe | 20.31.169.57:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| unknown |
google.com |
| unknown |
crl.microsoft.com |
| unknown |
login.live.com |
| unknown |
ocsp.digicert.com |
| unknown |
client.wns.windows.com |
| unknown |
arc.msn.com |
| unknown |
slscr.update.microsoft.com |
| unknown |
www.microsoft.com |
| unknown |
fe3cr.delivery.mp.microsoft.com |
| unknown |