| File name: | 1 (450) |
| Full analysis: | https://app.any.run/tasks/ee52b23b-50ff-40fb-a0cb-625e4db04666 |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2025, 22:29:29 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections |
| MD5: | 9D9E7DC6E98111295D976B57E9535950 |
| SHA1: | 8A04DE0426BE4592A1907460796A6808C0C55D5A |
| SHA256: | 333CA3C40DD7E75C197E175659490D8BF68B503A67D7C62AB667CF6374BBA5E9 |
| SSDEEP: | 6144:V7agl6NQND0tO54/RNooM9eAD3qUp8GBC/+peOAuk/vSwjwpyAvEh2rq+PNSMqxM:VuYMntO5sRuN3d+aCGpeOAPx4DxmDsR |
| .exe | | | DOS Executable Generic (100) |
|---|
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:01:19 13:34:56+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 299008 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13d4 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | UEFI |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 208 | C:\Users\admin\AppData\Local\Temp\Unicorn-40320.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-40320.exe | Unicorn-7865.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 516 | C:\Users\admin\AppData\Local\Temp\Unicorn-7865.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-7865.exe | Unicorn-9598.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 968 | C:\Users\admin\AppData\Local\Temp\Unicorn-27212.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-27212.exe | Unicorn-56765.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1020 | C:\Users\admin\AppData\Local\Temp\Unicorn-45665.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-45665.exe | Unicorn-30206.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1052 | C:\Users\admin\AppData\Local\Temp\Unicorn-8161.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-8161.exe | Unicorn-25100.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1116 | C:\Users\admin\AppData\Local\Temp\Unicorn-14642.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-14642.exe | Unicorn-33142.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1128 | C:\Users\admin\AppData\Local\Temp\Unicorn-28377.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-28377.exe | Unicorn-14331.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1188 | C:\Users\admin\AppData\Local\Temp\Unicorn-33548.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-33548.exe | Unicorn-57092.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1228 | C:\Users\admin\AppData\Local\Temp\Unicorn-3781.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-3781.exe | Unicorn-60190.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1348 | "C:\Users\admin\AppData\Local\Temp\1 (450).exe" | C:\Users\admin\AppData\Local\Temp\1 (450).exe | explorer.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4120 | Unicorn-33142.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-14642.exe | executable | |
MD5:5A6CCF4FE9A257B35E68F36ACFAD887B | SHA256:BCE562568B8B70247761BB90D4E25A14C7C24ABE4587D344199F96F40390DDCC | |||
| 2244 | Unicorn-49976.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-3781.exe | executable | |
MD5:F447D2302095AA9203FCBC41879F6DE2 | SHA256:9B85E8E219C190298597237FF15ACAE99C78C8D24665349B2C8B553B2A9F24DC | |||
| 1188 | Unicorn-33548.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-24394.exe | executable | |
MD5:579EE89A096C45276576308898C2F503 | SHA256:EB39E24CED5F4DA99694FECB4A98368F16BF5CA62AF72B7B1E853A6DE311ED59 | |||
| 1348 | 1 (450).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-14331.exe | executable | |
MD5:8797022DC5101795FA18F4D395F4F734 | SHA256:B05535FD07D6AE4E3CEC12BA02BA5EDB97097451D6FF85337A8067972A9B23F0 | |||
| 4120 | Unicorn-33142.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-60190.exe | executable | |
MD5:D8953A292E69BE24DAE3CCA46C641A02 | SHA256:C56BE376011F8F16E5A667CE63B985A1B97183E10B736EFF83D84EF79363A72E | |||
| 6036 | Unicorn-14331.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-57092.exe | executable | |
MD5:CBA10F1A1090D61375082FA5527393C2 | SHA256:7C535DCA372275ED0FB7AFBC3D9C759DDCD55C48D655D55054F9A19B6A28C54C | |||
| 5892 | Unicorn-57092.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-61705.exe | executable | |
MD5:D66B5F6CB2516AE7AAA6E4A59E620D5F | SHA256:9756877E809D7C2C0EF60E5D215652AED43D7901D6F1192B26ABD1B93E362D1E | |||
| 6036 | Unicorn-14331.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-28377.exe | executable | |
MD5:8B647117E8BB84D31B6620E0CFD62C66 | SHA256:F68796A56C9C25E4FBCF728A760EF1B9DC41022D00DA6B180A90CCFA7202E464 | |||
| 1188 | Unicorn-33548.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-34268.exe | executable | |
MD5:2F8918E931C652D672A56EC4CBA6440C | SHA256:3D7D1B989EA622EB9A5AE73AD16257E299D1A5928B37ED40F653E4EF9EBAA08B | |||
| 7144 | Unicorn-61705.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-30206.exe | executable | |
MD5:3B8AB571357D03B4B7C046873DD439F0 | SHA256:1D19777B581CA88A620AA7A3E9BB3DF28E69FAFC836B4647F636C86AFCDF96E5 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.48.23.176:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
8904 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
3240 | backgroundTaskHost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
8904 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2104 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 23.48.23.176:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2112 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3216 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 20.190.160.5:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
3240 | backgroundTaskHost.exe | 20.105.99.58:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |