| File name: | 1 (530) |
| Full analysis: | https://app.any.run/tasks/650360e1-9105-405b-bdde-f4bbcec01cc8 |
| Verdict: | Malicious activity |
| Analysis date: | March 25, 2025, 00:18:40 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, 3 sections |
| MD5: | 29ACEA1FA5A586CE53F01F9E0F6AAC60 |
| SHA1: | 35A17C4914F9119A569EB38BD9577724B7890C41 |
| SHA256: | 2E13C5CFCB978B1F8A618D7D55362699919EC36D28F663B7CE8E32826721C026 |
| SSDEEP: | 6144:y7KpOTIPvDoLE5XNI4evUofx/tWqlvJGBK/WyeG3Tk/8xwjwpyAvEhGKy4L0s1Ra:y+YEsLE5dIzJWMhaKOyeG30x4DxmDsR |
| .exe | | | Win32 Executable Microsoft Visual Basic 6 (90.6) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (4.9) |
| .exe | | | Generic Win/DOS Executable (2.2) |
| .exe | | | DOS Executable Generic (2.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:01:19 13:34:56+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit, No debug, Removable run from swap, Net run from swap, Uniprocessor only, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 299008 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13d4 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | UEFI |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 664 | C:\Users\admin\AppData\Local\Temp\Unicorn-45892.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-45892.exe | Unicorn-41176.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 672 | C:\Users\admin\AppData\Local\Temp\Unicorn-24138.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-24138.exe | Unicorn-38841.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 728 | C:\Users\admin\AppData\Local\Temp\Unicorn-85.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-85.exe | Unicorn-21593.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 732 | C:\Users\admin\AppData\Local\Temp\Unicorn-18835.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-18835.exe | — | Unicorn-21296.exe | |||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 1012 | C:\Users\admin\AppData\Local\Temp\Unicorn-39117.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-39117.exe | Unicorn-23614.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 1052 | C:\Users\admin\AppData\Local\Temp\Unicorn-33878.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-33878.exe | Unicorn-36132.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 1056 | C:\Users\admin\AppData\Local\Temp\Unicorn-12887.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-12887.exe | Unicorn-12236.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 1096 | C:\Users\admin\AppData\Local\Temp\Unicorn-32986.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-32986.exe | Unicorn-33744.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 1180 | C:\Users\admin\AppData\Local\Temp\Unicorn-34784.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-34784.exe | Unicorn-54364.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 1280 | C:\Users\admin\AppData\Local\Temp\Unicorn-21853.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-21853.exe | Unicorn-46296.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 8024 | Unicorn-48049.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-54364.exe | executable | |
MD5:F49A9F372CA95FBA2F42C91DF721C067 | SHA256:C1341ABAF5E9FBEA68B173DDFE991483A51BAEA5BD956388149B4DE23AB7DDDF | |||
| 7348 | Unicorn-16714.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-34498.exe | executable | |
MD5:F6919D1FD5D1467C225F8B7CC297C832 | SHA256:FAB351CEF14B45507C02E07E190C4BC208C8E06655EC794D9617C36D4B75C43B | |||
| 7304 | 1 (530).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-48049.exe | executable | |
MD5:FE439C1F8877F6406F527D8DA105E03E | SHA256:AE2ABDFC41C338675F6DA7C1535F1B31CA297869D447C5E707988F864BE10CC5 | |||
| 8012 | Unicorn-44100.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-12236.exe | executable | |
MD5:F4FA33C9E7AD708D215986CA29B6082B | SHA256:F6F1DE0EAAB0FDD68C2A0DE5D7763C2642BB900D429857541BC701776D1235D8 | |||
| 7348 | Unicorn-16714.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-44100.exe | executable | |
MD5:E38F93F49796A211082E0CC8D71F785F | SHA256:BAD354187A90482347A555DD14208CF379ABBF76646440F204C9C0DB54EC1ADD | |||
| 7304 | 1 (530).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-16714.exe | executable | |
MD5:3F1433EF3AEAB227BCE4C93B74427B03 | SHA256:8E22911D84E346C6C083061A0BCE1E4A67D9F656D6BC238CCD35389780132E5D | |||
| 7348 | Unicorn-16714.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-33757.exe | executable | |
MD5:642D15FC2CEC0FC3E93D9E248DC561BE | SHA256:68A7CDEF6FB6F4513AC5C7F11C0479A1B3F761ACC241DD8FCB301061A8D1CF08 | |||
| 7304 | 1 (530).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-46296.exe | executable | |
MD5:98FD249F5113EBCFC69BE7A811F4B4A0 | SHA256:694482CCCDDFD4A773D465542D13C8FD4C390781971165E8B18965BD42CC6BC2 | |||
| 8128 | Unicorn-34498.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-56909.exe | executable | |
MD5:402E5D42C33C51C7BF220D4E0CD2B5B0 | SHA256:2A23473E219B3F6544EA65DBE1059DA08E86846B83775145B439C31B69596FDB | |||
| 8136 | Unicorn-12236.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-13650.exe | executable | |
MD5:C4E471874C8DCC6D3944978773867272 | SHA256:BCDF37FE3F093D907AF0C36EFDD15C4EBBA42EFDCC1E356CF57599199362E6EE | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 88.221.110.122:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7628 | backgroundTaskHost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
5936 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
5936 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2104 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 88.221.110.122:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2112 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3216 | svchost.exe | 40.113.110.67:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 20.190.159.0:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6544 | svchost.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
7628 | backgroundTaskHost.exe | 20.103.156.88:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |