File name:

1 (1278)

Full analysis: https://app.any.run/tasks/dc96671c-2c0a-40b2-9a79-436a1ff3aada
Verdict: Malicious activity
Analysis date: March 24, 2025, 09:39:46
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections
MD5:

B37AEEA05FA0B492C4848AAEEB898480

SHA1:

4944D4DEA17FB1DCA0F12A015EE327AA065A1FCB

SHA256:

26F3A7182E85AAA350D07D04B328A13B9175B5020E2BD43763C62783F7EBE10A

SSDEEP:

6144:xCHnNlIcDDdgK5VG8SeyV1fxytBulp8GBfLOydO/wk/8SwuwpyArEhHBbo5Dn18/:xeNWggK5I8t/BY+af6ydO/NxxDxmDsR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 1 (1278).exe (PID: 7652)
      • Unicorn-32770.exe (PID: 7960)
      • Unicorn-46886.exe (PID: 7716)
      • Unicorn-35951.exe (PID: 7444)
      • Unicorn-34136.exe (PID: 7576)
      • Unicorn-36174.exe (PID: 7600)
      • Unicorn-59683.exe (PID: 1328)
      • Unicorn-9840.exe (PID: 1128)
      • Unicorn-38337.exe (PID: 3008)
      • Unicorn-9556.exe (PID: 1096)
      • Unicorn-55228.exe (PID: 5360)
      • Unicorn-14190.exe (PID: 1132)
      • Unicorn-13375.exe (PID: 6592)
      • Unicorn-23895.exe (PID: 5344)
      • Unicorn-3370.exe (PID: 5380)
      • Unicorn-35882.exe (PID: 3140)
      • Unicorn-8435.exe (PID: 6424)
      • Unicorn-26718.exe (PID: 2564)
      • Unicorn-6852.exe (PID: 5164)
      • Unicorn-41108.exe (PID: 3096)
      • Unicorn-47445.exe (PID: 1276)
      • Unicorn-20387.exe (PID: 7208)
      • Unicorn-33193.exe (PID: 7228)
      • Unicorn-45768.exe (PID: 7244)
      • Unicorn-2597.exe (PID: 8044)
      • Unicorn-20024.exe (PID: 8156)
      • Unicorn-58534.exe (PID: 7916)
      • Unicorn-47818.exe (PID: 896)
      • Unicorn-29344.exe (PID: 6392)
      • Unicorn-26360.exe (PID: 8084)
      • Unicorn-52971.exe (PID: 536)
      • Unicorn-53848.exe (PID: 3676)
      • Unicorn-47818.exe (PID: 2560)
      • Unicorn-29344.exe (PID: 3884)
      • Unicorn-45166.exe (PID: 7556)
      • Unicorn-50245.exe (PID: 3888)
      • Unicorn-11662.exe (PID: 516)
      • Unicorn-3282.exe (PID: 4652)
      • Unicorn-65031.exe (PID: 5548)
      • Unicorn-40889.exe (PID: 7192)
      • Unicorn-54625.exe (PID: 6192)
      • Unicorn-43027.exe (PID: 6388)
      • Unicorn-58901.exe (PID: 968)
      • Unicorn-3941.exe (PID: 3240)
      • Unicorn-62462.exe (PID: 4980)
      • Unicorn-37403.exe (PID: 2236)
      • Unicorn-20526.exe (PID: 5728)
      • Unicorn-34004.exe (PID: 6148)
      • Unicorn-5970.exe (PID: 6344)
      • Unicorn-44018.exe (PID: 1188)
      • Unicorn-41487.exe (PID: 6644)
      • Unicorn-29134.exe (PID: 5008)
      • Unicorn-41487.exe (PID: 2800)
      • Unicorn-50148.exe (PID: 7360)
      • Unicorn-31469.exe (PID: 5308)
      • Unicorn-6074.exe (PID: 7152)
      • Unicorn-49608.exe (PID: 5084)
      • Unicorn-10350.exe (PID: 4628)
      • Unicorn-33893.exe (PID: 7300)
      • Unicorn-14304.exe (PID: 2244)
      • Unicorn-32394.exe (PID: 6816)
      • Unicorn-15010.exe (PID: 7460)
      • Unicorn-41700.exe (PID: 6040)
      • Unicorn-49183.exe (PID: 7872)
      • Unicorn-12234.exe (PID: 7696)
      • Unicorn-50615.exe (PID: 5556)
      • Unicorn-50615.exe (PID: 1764)
      • Unicorn-26395.exe (PID: 6272)
      • Unicorn-7719.exe (PID: 3032)
      • Unicorn-5202.exe (PID: 2140)
      • Unicorn-41975.exe (PID: 872)
      • Unicorn-14455.exe (PID: 7484)
      • Unicorn-62950.exe (PID: 8128)
      • Unicorn-41975.exe (PID: 8168)
      • Unicorn-13002.exe (PID: 8232)
      • Unicorn-7055.exe (PID: 8340)
      • Unicorn-925.exe (PID: 8332)
      • Unicorn-55166.exe (PID: 8592)
      • Unicorn-62011.exe (PID: 8252)
      • Unicorn-22048.exe (PID: 8288)
      • Unicorn-45675.exe (PID: 8264)
      • Unicorn-11148.exe (PID: 2288)
      • Unicorn-39545.exe (PID: 8240)
      • Unicorn-43511.exe (PID: 8668)
      • Unicorn-18047.exe (PID: 8420)
      • Unicorn-24168.exe (PID: 8412)
      • Unicorn-46635.exe (PID: 8440)
      • Unicorn-17946.exe (PID: 8468)
      • Unicorn-23812.exe (PID: 8504)
      • Unicorn-43812.exe (PID: 8364)
      • Unicorn-46827.exe (PID: 8372)
      • Unicorn-43297.exe (PID: 8396)
      • Unicorn-14922.exe (PID: 8640)
      • Unicorn-15146.exe (PID: 8476)
      • Unicorn-21254.exe (PID: 8380)
      • Unicorn-14922.exe (PID: 8632)
      • Unicorn-31813.exe (PID: 8740)
      • Unicorn-62779.exe (PID: 8576)
      • Unicorn-47595.exe (PID: 8684)
      • Unicorn-39789.exe (PID: 8812)
      • Unicorn-38550.exe (PID: 8624)
      • Unicorn-18052.exe (PID: 8768)
      • Unicorn-63931.exe (PID: 8720)
      • Unicorn-7117.exe (PID: 8776)
      • Unicorn-36412.exe (PID: 8660)
      • Unicorn-34886.exe (PID: 8804)
      • Unicorn-65171.exe (PID: 8888)
      • Unicorn-2286.exe (PID: 8872)
      • Unicorn-49441.exe (PID: 8840)
      • Unicorn-52447.exe (PID: 9004)
      • Unicorn-54393.exe (PID: 9048)
      • Unicorn-53194.exe (PID: 8964)
      • Unicorn-60755.exe (PID: 7184)
      • Unicorn-6946.exe (PID: 9172)
      • Unicorn-18966.exe (PID: 9188)
      • Unicorn-64424.exe (PID: 8920)
      • Unicorn-11222.exe (PID: 9076)
      • Unicorn-3822.exe (PID: 9220)
      • Unicorn-7667.exe (PID: 9272)
      • Unicorn-11397.exe (PID: 6108)
      • Unicorn-9944.exe (PID: 8980)
      • Unicorn-35000.exe (PID: 1184)
      • Unicorn-46806.exe (PID: 2980)
      • Unicorn-28903.exe (PID: 9356)
      • Unicorn-9982.exe (PID: 9456)
      • Unicorn-53351.exe (PID: 9484)
      • Unicorn-58814.exe (PID: 8388)
      • Unicorn-36141.exe (PID: 9412)
      • Unicorn-314.exe (PID: 9500)
      • Unicorn-44383.exe (PID: 9604)
      • Unicorn-24517.exe (PID: 9612)
      • Unicorn-40683.exe (PID: 9540)
      • Unicorn-29884.exe (PID: 9716)
      • Unicorn-42437.exe (PID: 9572)
      • Unicorn-22654.exe (PID: 9656)
      • Unicorn-54196.exe (PID: 9764)
      • Unicorn-32113.exe (PID: 9688)
      • Unicorn-36883.exe (PID: 8520)
      • Unicorn-30281.exe (PID: 8648)
      • Unicorn-39789.exe (PID: 9844)
      • Unicorn-62810.exe (PID: 9868)
      • Unicorn-41434.exe (PID: 9128)
      • Unicorn-50771.exe (PID: 10000)
      • Unicorn-48394.exe (PID: 10060)
      • Unicorn-14398.exe (PID: 9956)
      • Unicorn-52582.exe (PID: 10192)
      • Unicorn-18591.exe (PID: 10220)
      • Unicorn-13647.exe (PID: 8280)
      • Unicorn-31673.exe (PID: 10124)
      • Unicorn-26057.exe (PID: 10100)
      • Unicorn-61745.exe (PID: 10148)
      • Unicorn-46717.exe (PID: 10204)
      • Unicorn-11357.exe (PID: 9092)
      • Unicorn-54279.exe (PID: 9100)
      • Unicorn-52198.exe (PID: 3396)
      • Unicorn-54279.exe (PID: 9068)
      • Unicorn-55396.exe (PID: 6228)
      • Unicorn-65462.exe (PID: 4932)
      • Unicorn-57434.exe (PID: 10324)
      • Unicorn-15514.exe (PID: 9480)
      • Unicorn-5108.exe (PID: 9996)
      • Unicorn-65078.exe (PID: 10272)
      • Unicorn-44980.exe (PID: 10252)
      • Unicorn-16069.exe (PID: 9640)
      • Unicorn-32597.exe (PID: 5452)
      • Unicorn-41642.exe (PID: 5036)
      • Unicorn-57294.exe (PID: 9028)
      • Unicorn-36489.exe (PID: 9952)
      • Unicorn-34818.exe (PID: 10308)
      • Unicorn-15322.exe (PID: 10080)
      • Unicorn-37699.exe (PID: 8216)
      • Unicorn-32233.exe (PID: 10332)
      • Unicorn-19141.exe (PID: 10280)
      • Unicorn-45426.exe (PID: 10592)
      • Unicorn-61954.exe (PID: 10492)
      • Unicorn-63629.exe (PID: 10452)
      • Unicorn-47425.exe (PID: 9860)
      • Unicorn-50963.exe (PID: 10420)
      • Unicorn-39125.exe (PID: 10380)
      • Unicorn-49339.exe (PID: 10396)
      • Unicorn-11820.exe (PID: 10360)
      • Unicorn-61954.exe (PID: 10500)
      • Unicorn-16837.exe (PID: 10552)
      • Unicorn-16837.exe (PID: 10544)
      • Unicorn-9375.exe (PID: 10428)
      • Unicorn-41591.exe (PID: 10536)
      • Unicorn-21990.exe (PID: 10528)
      • Unicorn-23172.exe (PID: 10912)
      • Unicorn-24366.exe (PID: 10652)
      • Unicorn-46215.exe (PID: 10708)
      • Unicorn-46215.exe (PID: 10700)
      • Unicorn-15514.exe (PID: 9452)
      • Unicorn-49832.exe (PID: 10644)
      • Unicorn-59161.exe (PID: 10600)
      • Unicorn-63245.exe (PID: 10628)
      • Unicorn-31916.exe (PID: 10728)
      • Unicorn-833.exe (PID: 10780)
      • Unicorn-37284.exe (PID: 10720)
      • Unicorn-38047.exe (PID: 10744)
      • Unicorn-49832.exe (PID: 10636)
      • Unicorn-11112.exe (PID: 10840)
      • Unicorn-9821.exe (PID: 10792)
      • Unicorn-30564.exe (PID: 10828)
    • Starts itself from another location

      • Unicorn-32770.exe (PID: 7960)
      • Unicorn-46886.exe (PID: 7716)
      • 1 (1278).exe (PID: 7652)
      • Unicorn-34136.exe (PID: 7576)
      • Unicorn-35951.exe (PID: 7444)
      • Unicorn-59683.exe (PID: 1328)
      • Unicorn-36174.exe (PID: 7600)
      • Unicorn-38337.exe (PID: 3008)
      • Unicorn-9556.exe (PID: 1096)
      • Unicorn-9840.exe (PID: 1128)
      • Unicorn-14190.exe (PID: 1132)
      • Unicorn-55228.exe (PID: 5360)
      • Unicorn-13375.exe (PID: 6592)
      • Unicorn-3370.exe (PID: 5380)
      • Unicorn-23895.exe (PID: 5344)
      • Unicorn-26395.exe (PID: 6272)
      • Unicorn-8435.exe (PID: 6424)
      • Unicorn-41108.exe (PID: 3096)
      • Unicorn-50245.exe (PID: 3888)
      • Unicorn-35882.exe (PID: 3140)
      • Unicorn-3282.exe (PID: 4652)
      • Unicorn-6852.exe (PID: 5164)
      • Unicorn-47445.exe (PID: 1276)
      • Unicorn-20387.exe (PID: 7208)
      • Unicorn-33193.exe (PID: 7228)
      • Unicorn-45768.exe (PID: 7244)
      • Unicorn-20024.exe (PID: 8156)
      • Unicorn-31469.exe (PID: 5308)
      • Unicorn-58534.exe (PID: 7916)
      • Unicorn-47818.exe (PID: 896)
      • Unicorn-29344.exe (PID: 6392)
      • Unicorn-52971.exe (PID: 536)
      • Unicorn-47818.exe (PID: 2560)
      • Unicorn-26718.exe (PID: 2564)
      • Unicorn-53848.exe (PID: 3676)
      • Unicorn-29344.exe (PID: 3884)
      • Unicorn-45166.exe (PID: 7556)
      • Unicorn-5202.exe (PID: 2140)
      • Unicorn-43027.exe (PID: 6388)
      • Unicorn-58901.exe (PID: 968)
      • Unicorn-65031.exe (PID: 5548)
      • Unicorn-40889.exe (PID: 7192)
      • Unicorn-11662.exe (PID: 516)
      • Unicorn-20526.exe (PID: 5728)
      • Unicorn-60755.exe (PID: 7184)
      • Unicorn-37403.exe (PID: 2236)
      • Unicorn-62462.exe (PID: 4980)
      • Unicorn-54625.exe (PID: 6192)
      • Unicorn-34004.exe (PID: 6148)
      • Unicorn-35000.exe (PID: 1184)
      • Unicorn-41487.exe (PID: 6644)
      • Unicorn-44018.exe (PID: 1188)
      • Unicorn-5970.exe (PID: 6344)
      • Unicorn-41487.exe (PID: 2800)
      • Unicorn-29134.exe (PID: 5008)
      • Unicorn-33893.exe (PID: 7300)
      • Unicorn-10350.exe (PID: 4628)
      • Unicorn-6074.exe (PID: 7152)
      • Unicorn-50148.exe (PID: 7360)
      • Unicorn-2597.exe (PID: 8044)
      • Unicorn-49608.exe (PID: 5084)
      • Unicorn-15010.exe (PID: 7460)
      • Unicorn-14304.exe (PID: 2244)
      • Unicorn-41700.exe (PID: 6040)
      • Unicorn-49183.exe (PID: 7872)
      • Unicorn-12234.exe (PID: 7696)
      • Unicorn-50615.exe (PID: 1764)
      • Unicorn-41975.exe (PID: 872)
      • Unicorn-7719.exe (PID: 3032)
      • Unicorn-14455.exe (PID: 7484)
      • Unicorn-50615.exe (PID: 5556)
      • Unicorn-46806.exe (PID: 2980)
      • Unicorn-62950.exe (PID: 8128)
      • Unicorn-13002.exe (PID: 8232)
      • Unicorn-41975.exe (PID: 8168)
      • Unicorn-7055.exe (PID: 8340)
      • Unicorn-925.exe (PID: 8332)
      • Unicorn-37699.exe (PID: 8216)
      • Unicorn-55166.exe (PID: 8592)
      • Unicorn-11148.exe (PID: 2288)
      • Unicorn-13647.exe (PID: 8280)
      • Unicorn-62011.exe (PID: 8252)
      • Unicorn-39545.exe (PID: 8240)
      • Unicorn-43511.exe (PID: 8668)
      • Unicorn-24168.exe (PID: 8412)
      • Unicorn-45675.exe (PID: 8264)
      • Unicorn-22048.exe (PID: 8288)
      • Unicorn-43812.exe (PID: 8364)
      • Unicorn-26360.exe (PID: 8084)
      • Unicorn-46635.exe (PID: 8440)
      • Unicorn-32394.exe (PID: 6816)
      • Unicorn-18047.exe (PID: 8420)
      • Unicorn-14922.exe (PID: 8640)
      • Unicorn-58814.exe (PID: 8388)
      • Unicorn-46827.exe (PID: 8372)
      • Unicorn-43297.exe (PID: 8396)
      • Unicorn-17946.exe (PID: 8468)
      • Unicorn-15146.exe (PID: 8476)
      • Unicorn-14922.exe (PID: 8632)
      • Unicorn-36883.exe (PID: 8520)
      • Unicorn-62779.exe (PID: 8576)
      • Unicorn-21254.exe (PID: 8380)
      • Unicorn-47595.exe (PID: 8684)
      • Unicorn-39789.exe (PID: 8812)
      • Unicorn-31813.exe (PID: 8740)
      • Unicorn-30281.exe (PID: 8648)
      • Unicorn-38550.exe (PID: 8624)
      • Unicorn-18052.exe (PID: 8768)
      • Unicorn-7117.exe (PID: 8776)
      • Unicorn-63931.exe (PID: 8720)
      • Unicorn-36412.exe (PID: 8660)
      • Unicorn-49441.exe (PID: 8840)
      • Unicorn-34886.exe (PID: 8804)
      • Unicorn-2286.exe (PID: 8872)
      • Unicorn-65171.exe (PID: 8888)
      • Unicorn-53194.exe (PID: 8964)
      • Unicorn-52447.exe (PID: 9004)
      • Unicorn-23812.exe (PID: 8504)
      • Unicorn-3941.exe (PID: 3240)
      • Unicorn-54393.exe (PID: 9048)
      • Unicorn-64424.exe (PID: 8920)
      • Unicorn-41434.exe (PID: 9128)
      • Unicorn-6946.exe (PID: 9172)
      • Unicorn-3822.exe (PID: 9220)
      • Unicorn-9944.exe (PID: 8980)
      • Unicorn-18966.exe (PID: 9188)
      • Unicorn-11397.exe (PID: 6108)
      • Unicorn-7667.exe (PID: 9272)
      • Unicorn-28903.exe (PID: 9356)
      • Unicorn-36141.exe (PID: 9412)
      • Unicorn-53351.exe (PID: 9484)
      • Unicorn-9982.exe (PID: 9456)
      • Unicorn-44383.exe (PID: 9604)
      • Unicorn-40683.exe (PID: 9540)
      • Unicorn-24517.exe (PID: 9612)
      • Unicorn-314.exe (PID: 9500)
      • Unicorn-22654.exe (PID: 9656)
      • Unicorn-42437.exe (PID: 9572)
      • Unicorn-29884.exe (PID: 9716)
    • Executes application which crashes

      • Unicorn-10189.exe (PID: 8852)
  • INFO

    • The sample compiled with chinese language support

      • 1 (1278).exe (PID: 7652)
      • Unicorn-32770.exe (PID: 7960)
      • Unicorn-35951.exe (PID: 7444)
      • Unicorn-46886.exe (PID: 7716)
      • Unicorn-34136.exe (PID: 7576)
      • Unicorn-36174.exe (PID: 7600)
      • Unicorn-59683.exe (PID: 1328)
      • Unicorn-9556.exe (PID: 1096)
      • Unicorn-55228.exe (PID: 5360)
      • Unicorn-9840.exe (PID: 1128)
      • Unicorn-38337.exe (PID: 3008)
      • Unicorn-14190.exe (PID: 1132)
      • Unicorn-13375.exe (PID: 6592)
      • Unicorn-23895.exe (PID: 5344)
      • Unicorn-3370.exe (PID: 5380)
      • Unicorn-8435.exe (PID: 6424)
      • Unicorn-35882.exe (PID: 3140)
      • Unicorn-6852.exe (PID: 5164)
      • Unicorn-26718.exe (PID: 2564)
      • Unicorn-41108.exe (PID: 3096)
      • Unicorn-47445.exe (PID: 1276)
      • Unicorn-20387.exe (PID: 7208)
      • Unicorn-33193.exe (PID: 7228)
      • Unicorn-45768.exe (PID: 7244)
      • Unicorn-2597.exe (PID: 8044)
      • Unicorn-20024.exe (PID: 8156)
      • Unicorn-58534.exe (PID: 7916)
      • Unicorn-26360.exe (PID: 8084)
      • Unicorn-47818.exe (PID: 2560)
      • Unicorn-53848.exe (PID: 3676)
      • Unicorn-47818.exe (PID: 896)
      • Unicorn-52971.exe (PID: 536)
      • Unicorn-29344.exe (PID: 6392)
      • Unicorn-3282.exe (PID: 4652)
      • Unicorn-29344.exe (PID: 3884)
      • Unicorn-50245.exe (PID: 3888)
      • Unicorn-45166.exe (PID: 7556)
      • Unicorn-11662.exe (PID: 516)
      • Unicorn-58901.exe (PID: 968)
      • Unicorn-54625.exe (PID: 6192)
      • Unicorn-43027.exe (PID: 6388)
      • Unicorn-65031.exe (PID: 5548)
      • Unicorn-40889.exe (PID: 7192)
      • Unicorn-20526.exe (PID: 5728)
      • Unicorn-3941.exe (PID: 3240)
      • Unicorn-37403.exe (PID: 2236)
      • Unicorn-60755.exe (PID: 7184)
      • Unicorn-41487.exe (PID: 6644)
      • Unicorn-34004.exe (PID: 6148)
      • Unicorn-44018.exe (PID: 1188)
      • Unicorn-5970.exe (PID: 6344)
      • Unicorn-29134.exe (PID: 5008)
      • Unicorn-41487.exe (PID: 2800)
      • Unicorn-31469.exe (PID: 5308)
      • Unicorn-50148.exe (PID: 7360)
      • Unicorn-10350.exe (PID: 4628)
      • Unicorn-6074.exe (PID: 7152)
      • Unicorn-33893.exe (PID: 7300)
      • Unicorn-49608.exe (PID: 5084)
      • Unicorn-32394.exe (PID: 6816)
      • Unicorn-14304.exe (PID: 2244)
      • Unicorn-41700.exe (PID: 6040)
      • Unicorn-15010.exe (PID: 7460)
      • Unicorn-49183.exe (PID: 7872)
      • Unicorn-12234.exe (PID: 7696)
      • Unicorn-50615.exe (PID: 1764)
      • Unicorn-26395.exe (PID: 6272)
      • Unicorn-50615.exe (PID: 5556)
      • Unicorn-41975.exe (PID: 872)
      • Unicorn-14455.exe (PID: 7484)
      • Unicorn-7719.exe (PID: 3032)
      • Unicorn-5202.exe (PID: 2140)
      • Unicorn-13002.exe (PID: 8232)
      • Unicorn-41975.exe (PID: 8168)
      • Unicorn-62950.exe (PID: 8128)
      • Unicorn-7055.exe (PID: 8340)
      • Unicorn-925.exe (PID: 8332)
      • Unicorn-55166.exe (PID: 8592)
      • Unicorn-62011.exe (PID: 8252)
      • Unicorn-45675.exe (PID: 8264)
      • Unicorn-11148.exe (PID: 2288)
      • Unicorn-39545.exe (PID: 8240)
      • Unicorn-43511.exe (PID: 8668)
      • Unicorn-24168.exe (PID: 8412)
      • Unicorn-22048.exe (PID: 8288)
      • Unicorn-46635.exe (PID: 8440)
      • Unicorn-17946.exe (PID: 8468)
      • Unicorn-23812.exe (PID: 8504)
      • Unicorn-18047.exe (PID: 8420)
      • Unicorn-43812.exe (PID: 8364)
      • Unicorn-15146.exe (PID: 8476)
      • Unicorn-46827.exe (PID: 8372)
      • Unicorn-43297.exe (PID: 8396)
      • Unicorn-14922.exe (PID: 8640)
      • Unicorn-14922.exe (PID: 8632)
      • Unicorn-62779.exe (PID: 8576)
      • Unicorn-21254.exe (PID: 8380)
      • Unicorn-38550.exe (PID: 8624)
      • Unicorn-47595.exe (PID: 8684)
      • Unicorn-39789.exe (PID: 8812)
      • Unicorn-31813.exe (PID: 8740)
      • Unicorn-7117.exe (PID: 8776)
      • Unicorn-63931.exe (PID: 8720)
      • Unicorn-36412.exe (PID: 8660)
      • Unicorn-18052.exe (PID: 8768)
      • Unicorn-49441.exe (PID: 8840)
      • Unicorn-34886.exe (PID: 8804)
      • Unicorn-65171.exe (PID: 8888)
      • Unicorn-2286.exe (PID: 8872)
      • Unicorn-54393.exe (PID: 9048)
      • Unicorn-53194.exe (PID: 8964)
      • Unicorn-52447.exe (PID: 9004)
      • Unicorn-11222.exe (PID: 9076)
      • Unicorn-6946.exe (PID: 9172)
      • Unicorn-64424.exe (PID: 8920)
      • Unicorn-62462.exe (PID: 4980)
      • Unicorn-9944.exe (PID: 8980)
      • Unicorn-18966.exe (PID: 9188)
      • Unicorn-11397.exe (PID: 6108)
      • Unicorn-3822.exe (PID: 9220)
      • Unicorn-35000.exe (PID: 1184)
      • Unicorn-7667.exe (PID: 9272)
      • Unicorn-46806.exe (PID: 2980)
      • Unicorn-28903.exe (PID: 9356)
      • Unicorn-9982.exe (PID: 9456)
      • Unicorn-53351.exe (PID: 9484)
      • Unicorn-58814.exe (PID: 8388)
      • Unicorn-36141.exe (PID: 9412)
      • Unicorn-40683.exe (PID: 9540)
      • Unicorn-24517.exe (PID: 9612)
      • Unicorn-314.exe (PID: 9500)
      • Unicorn-44383.exe (PID: 9604)
      • Unicorn-22654.exe (PID: 9656)
      • Unicorn-29884.exe (PID: 9716)
      • Unicorn-42437.exe (PID: 9572)
      • Unicorn-54196.exe (PID: 9764)
      • Unicorn-32113.exe (PID: 9688)
      • Unicorn-36883.exe (PID: 8520)
      • Unicorn-30281.exe (PID: 8648)
      • Unicorn-39789.exe (PID: 9844)
      • Unicorn-62810.exe (PID: 9868)
      • Unicorn-41434.exe (PID: 9128)
      • Unicorn-14398.exe (PID: 9956)
      • Unicorn-48394.exe (PID: 10060)
      • Unicorn-50771.exe (PID: 10000)
      • Unicorn-46717.exe (PID: 10204)
      • Unicorn-52582.exe (PID: 10192)
      • Unicorn-13647.exe (PID: 8280)
      • Unicorn-31673.exe (PID: 10124)
      • Unicorn-26057.exe (PID: 10100)
      • Unicorn-61745.exe (PID: 10148)
      • Unicorn-18591.exe (PID: 10220)
      • Unicorn-54279.exe (PID: 9100)
      • Unicorn-52198.exe (PID: 3396)
      • Unicorn-54279.exe (PID: 9068)
      • Unicorn-55396.exe (PID: 6228)
      • Unicorn-65462.exe (PID: 4932)
      • Unicorn-11357.exe (PID: 9092)
      • Unicorn-57434.exe (PID: 10324)
      • Unicorn-5108.exe (PID: 9996)
      • Unicorn-65078.exe (PID: 10272)
      • Unicorn-44980.exe (PID: 10252)
      • Unicorn-32597.exe (PID: 5452)
      • Unicorn-41642.exe (PID: 5036)
      • Unicorn-57294.exe (PID: 9028)
      • Unicorn-36489.exe (PID: 9952)
      • Unicorn-15514.exe (PID: 9480)
      • Unicorn-34818.exe (PID: 10308)
      • Unicorn-37699.exe (PID: 8216)
      • Unicorn-19141.exe (PID: 10280)
      • Unicorn-16069.exe (PID: 9640)
      • Unicorn-15322.exe (PID: 10080)
      • Unicorn-32233.exe (PID: 10332)
      • Unicorn-11820.exe (PID: 10360)
      • Unicorn-45426.exe (PID: 10592)
      • Unicorn-61954.exe (PID: 10492)
      • Unicorn-47425.exe (PID: 9860)
      • Unicorn-50963.exe (PID: 10420)
      • Unicorn-39125.exe (PID: 10380)
      • Unicorn-49339.exe (PID: 10396)
      • Unicorn-61954.exe (PID: 10500)
      • Unicorn-21990.exe (PID: 10528)
      • Unicorn-16837.exe (PID: 10544)
      • Unicorn-63629.exe (PID: 10452)
      • Unicorn-9375.exe (PID: 10428)
      • Unicorn-41591.exe (PID: 10536)
      • Unicorn-16837.exe (PID: 10552)
      • Unicorn-23172.exe (PID: 10912)
      • Unicorn-24366.exe (PID: 10652)
      • Unicorn-46215.exe (PID: 10708)
      • Unicorn-15514.exe (PID: 9452)
      • Unicorn-49832.exe (PID: 10644)
      • Unicorn-59161.exe (PID: 10600)
      • Unicorn-63245.exe (PID: 10628)
      • Unicorn-31916.exe (PID: 10728)
      • Unicorn-833.exe (PID: 10780)
      • Unicorn-37284.exe (PID: 10720)
      • Unicorn-38047.exe (PID: 10744)
      • Unicorn-46215.exe (PID: 10700)
      • Unicorn-49832.exe (PID: 10636)
      • Unicorn-11112.exe (PID: 10840)
      • Unicorn-9821.exe (PID: 10792)
      • Unicorn-30564.exe (PID: 10828)
    • Reads the computer name

      • Unicorn-46886.exe (PID: 7716)
      • Unicorn-32770.exe (PID: 7960)
      • 1 (1278).exe (PID: 7652)
      • Unicorn-35951.exe (PID: 7444)
      • Unicorn-36174.exe (PID: 7600)
      • Unicorn-34136.exe (PID: 7576)
      • Unicorn-59683.exe (PID: 1328)
      • Unicorn-9840.exe (PID: 1128)
      • Unicorn-38337.exe (PID: 3008)
      • Unicorn-9556.exe (PID: 1096)
      • Unicorn-55228.exe (PID: 5360)
      • Unicorn-13375.exe (PID: 6592)
      • Unicorn-3370.exe (PID: 5380)
      • Unicorn-23895.exe (PID: 5344)
      • Unicorn-35882.exe (PID: 3140)
      • Unicorn-8435.exe (PID: 6424)
      • Unicorn-3282.exe (PID: 4652)
      • Unicorn-33193.exe (PID: 7228)
      • Unicorn-31469.exe (PID: 5308)
      • Unicorn-45768.exe (PID: 7244)
      • Unicorn-47445.exe (PID: 1276)
      • Unicorn-26360.exe (PID: 8084)
      • Unicorn-44018.exe (PID: 1188)
      • Unicorn-41975.exe (PID: 872)
      • Unicorn-47595.exe (PID: 8684)
      • Unicorn-40683.exe (PID: 9540)
    • Checks supported languages

      • Unicorn-46886.exe (PID: 7716)
      • Unicorn-32770.exe (PID: 7960)
      • Unicorn-35951.exe (PID: 7444)
      • Unicorn-34136.exe (PID: 7576)
      • Unicorn-36174.exe (PID: 7600)
      • Unicorn-59683.exe (PID: 1328)
      • Unicorn-9840.exe (PID: 1128)
      • 1 (1278).exe (PID: 7652)
      • Unicorn-3370.exe (PID: 5380)
      • Unicorn-55228.exe (PID: 5360)
      • Unicorn-13375.exe (PID: 6592)
      • Unicorn-14190.exe (PID: 1132)
      • Unicorn-9556.exe (PID: 1096)
      • Unicorn-23895.exe (PID: 5344)
      • Unicorn-8435.exe (PID: 6424)
      • Unicorn-26395.exe (PID: 6272)
      • Unicorn-41108.exe (PID: 3096)
      • Unicorn-50245.exe (PID: 3888)
      • Unicorn-47445.exe (PID: 1276)
      • Unicorn-26718.exe (PID: 2564)
      • Unicorn-6852.exe (PID: 5164)
      • Unicorn-33193.exe (PID: 7228)
      • Unicorn-31469.exe (PID: 5308)
      • Unicorn-2597.exe (PID: 8044)
      • Unicorn-3941.exe (PID: 3240)
      • Unicorn-65031.exe (PID: 5548)
      • Unicorn-34004.exe (PID: 6148)
      • Unicorn-50148.exe (PID: 7360)
      • Unicorn-29134.exe (PID: 5008)
      • Unicorn-44018.exe (PID: 1188)
      • Unicorn-41700.exe (PID: 6040)
      • Unicorn-45675.exe (PID: 8264)
      • Unicorn-37699.exe (PID: 8216)
      • Unicorn-43812.exe (PID: 8364)
      • Unicorn-43297.exe (PID: 8396)
      • Unicorn-43511.exe (PID: 8668)
      • Unicorn-38550.exe (PID: 8624)
      • Unicorn-10189.exe (PID: 8852)
      • Unicorn-64424.exe (PID: 8920)
      • Unicorn-65171.exe (PID: 8888)
      • Unicorn-3822.exe (PID: 9220)
      • Unicorn-9982.exe (PID: 9456)
      • Unicorn-53351.exe (PID: 9484)
      • Unicorn-50771.exe (PID: 10000)
      • Unicorn-61745.exe (PID: 10148)
      • Unicorn-15514.exe (PID: 9480)
      • Unicorn-15322.exe (PID: 10080)
      • Unicorn-18591.exe (PID: 10220)
      • Unicorn-11357.exe (PID: 9092)
      • Unicorn-9375.exe (PID: 10428)
      • Unicorn-21990.exe (PID: 10528)
      • Unicorn-39125.exe (PID: 10380)
      • Unicorn-38047.exe (PID: 10744)
      • Unicorn-9821.exe (PID: 10792)
      • Unicorn-49832.exe (PID: 10636)
      • Unicorn-37471.exe (PID: 10980)
      • Unicorn-4416.exe (PID: 11088)
      • Unicorn-15441.exe (PID: 10680)
      • Unicorn-13542.exe (PID: 11176)
      • Unicorn-26947.exe (PID: 11028)
      • Unicorn-42297.exe (PID: 11388)
      • Unicorn-1740.exe (PID: 11660)
      • Unicorn-18260.exe (PID: 11704)
      • Unicorn-33081.exe (PID: 11940)
      • Unicorn-50226.exe (PID: 11772)
      • Unicorn-37890.exe (PID: 12836)
      • Unicorn-47590.exe (PID: 12876)
      • Unicorn-63095.exe (PID: 13076)
      • Unicorn-35011.exe (PID: 13160)
      • Unicorn-61871.exe (PID: 13196)
      • Unicorn-12425.exe (PID: 12500)
      • Unicorn-12909.exe (PID: 13880)
      • Unicorn-49474.exe (PID: 14048)
      • Unicorn-49474.exe (PID: 14040)
      • Unicorn-45722.exe (PID: 14152)
      • Unicorn-2524.exe (PID: 14284)
      • Unicorn-12094.exe (PID: 13416)
      • Unicorn-53366.exe (PID: 13596)
      • Unicorn-63046.exe (PID: 13848)
      • Unicorn-59894.exe (PID: 14748)
      • Unicorn-48099.exe (PID: 14680)
      • Unicorn-15488.exe (PID: 14880)
      • Unicorn-34865.exe (PID: 14412)
      • Unicorn-23631.exe (PID: 14496)
      • Unicorn-32509.exe (PID: 14652)
      • Unicorn-48130.exe (PID: 15432)
      • Unicorn-33906.exe (PID: 16008)
      • Unicorn-20501.exe (PID: 15688)
      • Unicorn-32787.exe (PID: 15792)
      • Unicorn-61334.exe (PID: 15840)
      • Unicorn-16258.exe (PID: 15888)
    • Create files in a temporary directory

      • Unicorn-46886.exe (PID: 7716)
      • 1 (1278).exe (PID: 7652)
      • Unicorn-32770.exe (PID: 7960)
      • Unicorn-34136.exe (PID: 7576)
      • Unicorn-36174.exe (PID: 7600)
      • Unicorn-35951.exe (PID: 7444)
      • Unicorn-59683.exe (PID: 1328)
      • Unicorn-13375.exe (PID: 6592)
      • Unicorn-38337.exe (PID: 3008)
      • Unicorn-9556.exe (PID: 1096)
      • Unicorn-3370.exe (PID: 5380)
      • Unicorn-14190.exe (PID: 1132)
      • Unicorn-9840.exe (PID: 1128)
      • Unicorn-35882.exe (PID: 3140)
      • Unicorn-26718.exe (PID: 2564)
      • Unicorn-41108.exe (PID: 3096)
      • Unicorn-8435.exe (PID: 6424)
      • Unicorn-45768.exe (PID: 7244)
      • Unicorn-20024.exe (PID: 8156)
      • Unicorn-2597.exe (PID: 8044)
      • Unicorn-47818.exe (PID: 2560)
      • Unicorn-29344.exe (PID: 3884)
      • Unicorn-43027.exe (PID: 6388)
      • Unicorn-65031.exe (PID: 5548)
      • Unicorn-47445.exe (PID: 1276)
      • Unicorn-41487.exe (PID: 6644)
      • Unicorn-41487.exe (PID: 2800)
      • Unicorn-29134.exe (PID: 5008)
      • Unicorn-33893.exe (PID: 7300)
      • Unicorn-6074.exe (PID: 7152)
      • Unicorn-29344.exe (PID: 6392)
      • Unicorn-53848.exe (PID: 3676)
      • Unicorn-50245.exe (PID: 3888)
      • Unicorn-55228.exe (PID: 5360)
      • Unicorn-33193.exe (PID: 7228)
      • Unicorn-23895.exe (PID: 5344)
      • Unicorn-43511.exe (PID: 8668)
      • Unicorn-15146.exe (PID: 8476)
      • Unicorn-47595.exe (PID: 8684)
      • Unicorn-65171.exe (PID: 8888)
      • Unicorn-53194.exe (PID: 8964)
      • Unicorn-47818.exe (PID: 896)
      • Unicorn-7667.exe (PID: 9272)
      • Unicorn-5202.exe (PID: 2140)
      • Unicorn-46806.exe (PID: 2980)
      • Unicorn-39789.exe (PID: 8812)
      • Unicorn-14922.exe (PID: 8632)
      • Unicorn-58814.exe (PID: 8388)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 7152)
      • BackgroundTransferHost.exe (PID: 6108)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 7152)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Microsoft Visual Basic 6 (90.6)
.exe | Win32 Executable (generic) (4.9)
.exe | Generic Win/DOS Executable (2.2)
.exe | DOS Executable Generic (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:01:19 13:34:56+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 176128
InitializedDataSize: 299008
UninitializedDataSize: -
EntryPoint: 0x13d4
OSVersion: 4
ImageVersion: 1
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: UEFI
ProductName: Kawaii-Unicorn
FileVersion: 1
ProductVersion: 1
InternalName: Kawaii-Unicorn
OriginalFileName: Kawaii-Unicorn.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
616
Monitored processes
480
Malicious processes
66
Suspicious processes
62

Behavior graph

Click at the process to see the details
start 1 (1278).exe unicorn-46886.exe sppextcomobj.exe no specs slui.exe unicorn-29611.exe no specs unicorn-32770.exe unicorn-35951.exe unicorn-34136.exe unicorn-36174.exe unicorn-59683.exe unicorn-9840.exe unicorn-38337.exe unicorn-55228.exe unicorn-9556.exe unicorn-13375.exe unicorn-14190.exe unicorn-3370.exe backgroundtransferhost.exe no specs unicorn-23895.exe unicorn-35882.exe unicorn-8435.exe unicorn-26395.exe unicorn-3282.exe unicorn-41108.exe unicorn-26718.exe unicorn-6852.exe unicorn-50245.exe unicorn-47445.exe unicorn-20387.exe unicorn-33193.exe unicorn-45768.exe unicorn-31469.exe backgroundtransferhost.exe unicorn-58534.exe unicorn-2597.exe backgroundtransferhost.exe no specs unicorn-20024.exe unicorn-26360.exe unicorn-52971.exe unicorn-47818.exe unicorn-47818.exe unicorn-53848.exe unicorn-29344.exe unicorn-29344.exe unicorn-58901.exe unicorn-45166.exe unicorn-65031.exe unicorn-5202.exe unicorn-43027.exe unicorn-20526.exe unicorn-54625.exe unicorn-60755.exe unicorn-40889.exe unicorn-11662.exe unicorn-3941.exe unicorn-37403.exe unicorn-29134.exe unicorn-41487.exe unicorn-41487.exe unicorn-35000.exe unicorn-62462.exe unicorn-34004.exe unicorn-5970.exe unicorn-44018.exe unicorn-50148.exe backgroundtransferhost.exe no specs unicorn-10350.exe unicorn-32394.exe unicorn-6074.exe unicorn-33893.exe unicorn-49608.exe unicorn-15010.exe unicorn-14304.exe unicorn-49183.exe unicorn-12234.exe unicorn-50615.exe unicorn-50615.exe unicorn-41700.exe unicorn-14455.exe unicorn-46806.exe unicorn-41975.exe unicorn-41975.exe unicorn-7719.exe unicorn-62950.exe unicorn-11148.exe unicorn-37699.exe unicorn-13002.exe unicorn-39545.exe unicorn-62011.exe unicorn-45675.exe unicorn-13647.exe unicorn-22048.exe unicorn-925.exe unicorn-7055.exe unicorn-43812.exe unicorn-46827.exe unicorn-21254.exe unicorn-58814.exe unicorn-43297.exe unicorn-24168.exe unicorn-18047.exe unicorn-46635.exe unicorn-17946.exe unicorn-15146.exe unicorn-23812.exe unicorn-36883.exe unicorn-62779.exe unicorn-55166.exe unicorn-38550.exe unicorn-14922.exe unicorn-14922.exe unicorn-30281.exe unicorn-36412.exe unicorn-43511.exe unicorn-47595.exe unicorn-63931.exe unicorn-31813.exe unicorn-18052.exe unicorn-7117.exe unicorn-34886.exe unicorn-39789.exe unicorn-49441.exe unicorn-10189.exe unicorn-2286.exe unicorn-65171.exe unicorn-64424.exe unicorn-53194.exe unicorn-52447.exe unicorn-54393.exe werfault.exe no specs unicorn-11222.exe unicorn-41434.exe backgroundtransferhost.exe no specs unicorn-6946.exe unicorn-18966.exe unicorn-11397.exe unicorn-9944.exe unicorn-3822.exe unicorn-7667.exe unicorn-28903.exe unicorn-36141.exe unicorn-9982.exe unicorn-53351.exe unicorn-314.exe unicorn-40683.exe unicorn-42437.exe unicorn-44383.exe unicorn-24517.exe unicorn-22654.exe unicorn-32113.exe unicorn-29884.exe unicorn-54196.exe unicorn-39789.exe unicorn-62810.exe unicorn-14398.exe unicorn-50771.exe unicorn-48394.exe unicorn-26057.exe unicorn-31673.exe unicorn-61745.exe unicorn-52582.exe unicorn-46717.exe unicorn-18591.exe unicorn-57294.exe unicorn-11357.exe unicorn-54279.exe unicorn-54279.exe unicorn-55396.exe unicorn-65462.exe unicorn-32597.exe unicorn-52198.exe unicorn-15514.exe unicorn-15514.exe unicorn-41642.exe unicorn-16069.exe unicorn-47425.exe unicorn-36489.exe unicorn-5108.exe unicorn-15322.exe unicorn-44980.exe unicorn-65078.exe unicorn-19141.exe unicorn-34818.exe unicorn-57434.exe unicorn-32233.exe unicorn-11820.exe unicorn-39125.exe unicorn-49339.exe unicorn-50963.exe unicorn-9375.exe unicorn-63629.exe unicorn-61954.exe unicorn-61954.exe unicorn-21990.exe unicorn-41591.exe unicorn-16837.exe unicorn-16837.exe unicorn-45426.exe unicorn-59161.exe unicorn-63245.exe unicorn-49832.exe unicorn-49832.exe unicorn-24366.exe unicorn-46215.exe unicorn-46215.exe unicorn-37284.exe unicorn-31916.exe unicorn-38047.exe unicorn-833.exe unicorn-9821.exe unicorn-62359.exe no specs unicorn-30564.exe unicorn-11112.exe unicorn-42301.exe no specs unicorn-53999.exe no specs unicorn-23172.exe unicorn-29303.exe no specs unicorn-25219.exe no specs unicorn-38025.exe no specs unicorn-57891.exe no specs unicorn-37471.exe no specs unicorn-59790.exe no specs unicorn-32492.exe no specs unicorn-1866.exe no specs unicorn-14481.exe no specs unicorn-34347.exe no specs unicorn-4416.exe no specs unicorn-46599.exe no specs unicorn-27117.exe no specs unicorn-42707.exe no specs unicorn-5301.exe no specs unicorn-9650.exe no specs unicorn-13542.exe no specs unicorn-47751.exe no specs unicorn-23859.exe no specs unicorn-24124.exe no specs unicorn-24124.exe no specs unicorn-15441.exe no specs unicorn-47559.exe no specs unicorn-59811.exe no specs unicorn-26947.exe no specs unicorn-63703.exe no specs unicorn-63703.exe no specs unicorn-2250.exe no specs unicorn-17609.exe no specs unicorn-36961.exe no specs unicorn-26563.exe no specs unicorn-48519.exe no specs unicorn-42297.exe no specs unicorn-31991.exe no specs unicorn-40159.exe no specs unicorn-48690.exe no specs unicorn-60387.exe no specs unicorn-23439.exe no specs unicorn-6910.exe no specs unicorn-32494.exe no specs unicorn-57071.exe no specs unicorn-1740.exe no specs unicorn-45182.exe no specs unicorn-18260.exe no specs unicorn-34404.exe no specs unicorn-50226.exe no specs unicorn-61923.exe no specs unicorn-28867.exe no specs unicorn-25321.exe no specs unicorn-19960.exe no specs unicorn-33875.exe no specs unicorn-33875.exe no specs unicorn-2634.exe no specs unicorn-33081.exe no specs unicorn-23329.exe no specs unicorn-4200.exe no specs unicorn-56002.exe no specs unicorn-32697.exe no specs unicorn-53017.exe no specs unicorn-59147.exe no specs unicorn-12094.exe no specs unicorn-20013.exe no specs unicorn-49479.exe no specs unicorn-64886.exe no specs unicorn-47454.exe no specs unicorn-35110.exe no specs unicorn-53584.exe no specs unicorn-35062.exe no specs unicorn-46054.exe no specs unicorn-7464.exe no specs unicorn-13594.exe no specs unicorn-10122.exe no specs unicorn-12425.exe no specs unicorn-18290.exe no specs unicorn-4088.exe no specs unicorn-60173.exe no specs unicorn-501.exe no specs unicorn-49480.exe no specs unicorn-8754.exe no specs unicorn-52280.exe no specs unicorn-3294.exe no specs unicorn-37890.exe no specs unicorn-37890.exe no specs unicorn-21361.exe no specs unicorn-47590.exe no specs unicorn-47590.exe no specs unicorn-37698.exe no specs unicorn-37698.exe no specs unicorn-43371.exe no specs unicorn-37506.exe no specs unicorn-18170.exe no specs unicorn-47488.exe no specs unicorn-23770.exe no specs unicorn-23770.exe no specs unicorn-49758.exe no specs unicorn-11932.exe no specs unicorn-63095.exe no specs unicorn-46958.exe no specs unicorn-35011.exe no specs unicorn-10069.exe no specs unicorn-51814.exe no specs unicorn-61871.exe no specs unicorn-61871.exe no specs unicorn-59078.exe no specs unicorn-59078.exe no specs unicorn-49841.exe no specs unicorn-28566.exe no specs unicorn-31366.exe no specs unicorn-31366.exe no specs unicorn-15583.exe no specs unicorn-17853.exe no specs unicorn-23719.exe no specs unicorn-23719.exe no specs unicorn-4118.exe no specs unicorn-12094.exe no specs unicorn-12094.exe no specs unicorn-6494.exe no specs unicorn-12094.exe no specs unicorn-23029.exe no specs unicorn-31695.exe no specs unicorn-61709.exe no specs unicorn-32945.exe no specs unicorn-7429.exe no specs unicorn-53366.exe no specs unicorn-21600.exe no specs unicorn-27466.exe no specs unicorn-7865.exe no specs unicorn-7865.exe no specs unicorn-41606.exe no specs unicorn-22063.exe no specs unicorn-6002.exe no specs unicorn-19737.exe no specs unicorn-13158.exe no specs unicorn-13158.exe no specs unicorn-59095.exe no specs unicorn-63046.exe no specs unicorn-26644.exe no specs unicorn-12909.exe no specs unicorn-34812.exe no specs unicorn-21077.exe no specs unicorn-38805.exe no specs unicorn-57834.exe no specs unicorn-3232.exe no specs unicorn-63209.exe no specs unicorn-60409.exe no specs unicorn-49474.exe no specs unicorn-49474.exe no specs unicorn-49474.exe no specs unicorn-49474.exe no specs unicorn-14061.exe no specs unicorn-8461.exe no specs unicorn-5701.exe no specs unicorn-45722.exe no specs unicorn-26121.exe no specs unicorn-26121.exe no specs unicorn-26121.exe no specs unicorn-12857.exe no specs unicorn-55587.exe no specs unicorn-47227.exe no specs unicorn-2524.exe no specs unicorn-54326.exe no specs unicorn-54326.exe no specs unicorn-58410.exe no specs unicorn-20204.exe no specs unicorn-10553.exe no specs unicorn-39141.exe no specs unicorn-34865.exe no specs unicorn-1561.exe no specs unicorn-8306.exe no specs unicorn-23631.exe no specs unicorn-4444.exe no specs unicorn-19105.exe no specs unicorn-65513.exe no specs unicorn-53261.exe no specs unicorn-44954.exe no specs unicorn-46245.exe no specs unicorn-32509.exe no specs unicorn-48099.exe no specs unicorn-64990.exe no specs unicorn-8780.exe no specs slui.exe no specs unicorn-59894.exe no specs unicorn-61866.exe no specs unicorn-61866.exe no specs unicorn-51974.exe no specs unicorn-15488.exe no specs unicorn-1512.exe no specs unicorn-57922.exe no specs unicorn-56141.exe no specs unicorn-13625.exe no specs unicorn-58550.exe no specs unicorn-37118.exe no specs unicorn-57803.exe no specs unicorn-24176.exe no specs unicorn-33437.exe no specs unicorn-56681.exe no specs unicorn-974.exe no specs unicorn-44420.exe no specs unicorn-18961.exe no specs unicorn-42702.exe no specs unicorn-19017.exe no specs unicorn-16224.exe no specs unicorn-2489.exe no specs unicorn-5124.exe no specs unicorn-32370.exe no specs unicorn-16853.exe no specs unicorn-23512.exe no specs unicorn-32443.exe no specs unicorn-24010.exe no specs unicorn-39849.exe no specs unicorn-28167.exe no specs unicorn-51710.exe no specs unicorn-39465.exe no specs unicorn-48130.exe no specs unicorn-3853.exe no specs unicorn-6421.exe no specs unicorn-54435.exe no specs unicorn-61799.exe no specs unicorn-53366.exe no specs unicorn-346.exe no specs unicorn-28165.exe no specs unicorn-20501.exe no specs unicorn-14636.exe no specs unicorn-14636.exe no specs unicorn-20501.exe no specs unicorn-20501.exe no specs unicorn-20501.exe no specs unicorn-15920.exe no specs unicorn-40922.exe no specs unicorn-32787.exe no specs unicorn-19597.exe no specs unicorn-19597.exe no specs unicorn-61334.exe no specs unicorn-24394.exe no specs unicorn-24394.exe no specs unicorn-16258.exe no specs unicorn-59369.exe no specs unicorn-65234.exe no specs unicorn-56569.exe no specs unicorn-56569.exe no specs unicorn-40033.exe no specs unicorn-64165.exe no specs unicorn-29822.exe no specs unicorn-33906.exe no specs unicorn-55395.exe no specs unicorn-55395.exe no specs unicorn-30194.exe no specs unicorn-4925.exe no specs unicorn-13134.exe no specs unicorn-15404.exe no specs unicorn-15404.exe no specs unicorn-15404.exe no specs unicorn-12604.exe no specs unicorn-12604.exe no specs unicorn-45774.exe no specs unicorn-24657.exe no specs unicorn-15404.exe no specs unicorn-21535.exe no specs unicorn-8328.exe no specs unicorn-16993.exe no specs unicorn-39717.exe no specs unicorn-39330.exe no specs unicorn-42130.exe no specs unicorn-25510.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
516C:\Users\admin\AppData\Local\Temp\Unicorn-11662.exeC:\Users\admin\AppData\Local\Temp\Unicorn-11662.exe
1 (1278).exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-11662.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
536C:\Users\admin\AppData\Local\Temp\Unicorn-52971.exeC:\Users\admin\AppData\Local\Temp\Unicorn-52971.exe
Unicorn-8435.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-52971.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
872C:\Users\admin\AppData\Local\Temp\Unicorn-41975.exeC:\Users\admin\AppData\Local\Temp\Unicorn-41975.exe
Unicorn-29344.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-41975.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
896C:\Users\admin\AppData\Local\Temp\Unicorn-47818.exeC:\Users\admin\AppData\Local\Temp\Unicorn-47818.exe
Unicorn-26395.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-47818.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
968C:\Users\admin\AppData\Local\Temp\Unicorn-58901.exeC:\Users\admin\AppData\Local\Temp\Unicorn-58901.exe
Unicorn-34136.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-58901.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1096C:\Users\admin\AppData\Local\Temp\Unicorn-9556.exeC:\Users\admin\AppData\Local\Temp\Unicorn-9556.exe
Unicorn-36174.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-9556.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1128C:\Users\admin\AppData\Local\Temp\Unicorn-9840.exeC:\Users\admin\AppData\Local\Temp\Unicorn-9840.exe
Unicorn-46886.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-9840.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1132C:\Users\admin\AppData\Local\Temp\Unicorn-14190.exeC:\Users\admin\AppData\Local\Temp\Unicorn-14190.exe
Unicorn-59683.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-14190.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1184C:\Users\admin\AppData\Local\Temp\Unicorn-35000.exeC:\Users\admin\AppData\Local\Temp\Unicorn-35000.exe
Unicorn-35951.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-35000.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1188C:\Users\admin\AppData\Local\Temp\Unicorn-44018.exeC:\Users\admin\AppData\Local\Temp\Unicorn-44018.exe
Unicorn-9840.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-44018.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
Total events
13 099
Read events
13 084
Write events
15
Delete events
0

Modification events

(PID) Process:(2800) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(2800) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2800) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7152) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7152) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7152) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(8000) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(8000) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(8000) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6108) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
Executable files
892
Suspicious files
7
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
76521 (1278).exeC:\Users\admin\AppData\Local\Temp\Unicorn-36174.exeexecutable
MD5:
SHA256:
76521 (1278).exeC:\Users\admin\AppData\Local\Temp\Unicorn-46886.exeexecutable
MD5:01B4F8E2D89C714368C83AD38D1B3BB2
SHA256:AC23C4D20B56026F03B699B51ACE6C095308E29D4ECE8280FE97E3B85D27C26F
7716Unicorn-46886.exeC:\Users\admin\AppData\Local\Temp\Unicorn-9840.exeexecutable
MD5:6786D05B54EC63ADDE0A47AC17DA81D0
SHA256:F6E8423957B01CCB06F8E1B99D21F7B7D571D9532167E407462E94F4537CC8BF
7600Unicorn-36174.exeC:\Users\admin\AppData\Local\Temp\Unicorn-9556.exeexecutable
MD5:867F03BC56C8C52190352413B57C9331
SHA256:5630E93E387524D4FA8F5C6F8CA17ED254E8E8B943DB046214DF5D601E9846DD
7960Unicorn-32770.exeC:\Users\admin\AppData\Local\Temp\Unicorn-34136.exeexecutable
MD5:28E20354A58B94BAC3A096F25379EDBD
SHA256:6144B404E101DDA940E2C76B2436A97663EF5EE8A1C8E4D47EE6FB26065C20BB
7716Unicorn-46886.exeC:\Users\admin\AppData\Local\Temp\Unicorn-35951.exeexecutable
MD5:861A2E540EBE12B6C27B41C57E7CD873
SHA256:8A3BF5D217F56BA1A6F14289FD758CD5EFFEFC1E5AC36486EC4A804E09D313C1
7444Unicorn-35951.exeC:\Users\admin\AppData\Local\Temp\Unicorn-59683.exeexecutable
MD5:17E8DF664969F0781ABAD878D3E48907
SHA256:B42A35A2D462D9BC2AF953A2F6B6E6C1CC291B4DC3E37B0D6AC3C6808A6F4F97
7576Unicorn-34136.exeC:\Users\admin\AppData\Local\Temp\Unicorn-38337.exeexecutable
MD5:CBADC2C54E707311C27475F5644C2D2F
SHA256:444EF45D5CE2BC86786F74574F4237E481E6DBBE0604B1F28BCA203121016E97
76521 (1278).exeC:\Users\admin\AppData\Local\Temp\Unicorn-13375.exeexecutable
MD5:4363C26B0C886E7EF67D7B4A706179A8
SHA256:1C10FED7B489ECCB909C232BD81DD4C60B221E37DA8F46BE86C0EBD69B56382C
7960Unicorn-32770.exeC:\Users\admin\AppData\Local\Temp\Unicorn-55228.exeexecutable
MD5:8A555BCECE4CD7D687CCF809964E7186
SHA256:07AC8C1C882C0317E99D976B6596387EEA0CF0ACB6D688E09163DF3CB4C112A8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
29
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2104
svchost.exe
GET
200
2.16.164.18:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2108
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
7696
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7152
BackgroundTransferHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
7696
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
2.16.164.18:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.190.160.5:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
976
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
20.190.160.5:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 2.16.164.18
  • 2.16.164.40
  • 2.16.164.106
  • 2.16.164.120
  • 2.16.164.81
  • 2.16.164.17
  • 2.16.164.99
  • 2.16.164.34
  • 2.16.164.32
whitelisted
google.com
  • 142.250.185.78
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
login.live.com
  • 20.190.160.5
  • 20.190.160.64
  • 40.126.32.140
  • 40.126.32.72
  • 40.126.32.76
  • 20.190.160.132
  • 40.126.32.138
  • 40.126.32.68
whitelisted
ocsp.digicert.com
  • 184.30.131.245
  • 2.23.77.188
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
www.bing.com
  • 2.23.227.215
  • 2.23.227.221
  • 2.23.227.208
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted

Threats

No threats detected
No debug info