| File name: | 1 (1204) |
| Full analysis: | https://app.any.run/tasks/1542b104-13a5-4b1a-b9b6-b1b6383380ec |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2025, 11:24:55 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, 3 sections |
| MD5: | A51D3750F1A48E83E1DABAEBCC7A6EE0 |
| SHA1: | 82FFE4D346DF49D949F137A3334F6F3CE496A44E |
| SHA256: | 3478AA4215E76162FB55D532923DE1EE99DF68DA632366C40E15C61B2082773D |
| SSDEEP: | 6144:PTLglnIJoDlWQ5AN6/e/RpoxGtBqcvJGBc/6yeOKgk/8SwjwpyAvEheADb+nUPpa:P/MIEWQ5W62BBdhaciyeOK6x4DxmDsR |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:01:19 13:34:56+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit, No debug, Removable run from swap, Net run from swap, Uniprocessor only, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 299008 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13d4 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | UEFI |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 644 | C:\Users\admin\AppData\Local\Temp\Unicorn-60706.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-60706.exe | Unicorn-49829.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 856 | C:\Users\admin\AppData\Local\Temp\Unicorn-48070.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-48070.exe | Unicorn-13477.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 872 | C:\Users\admin\AppData\Local\Temp\Unicorn-10945.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-10945.exe | — | Unicorn-45154.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1012 | C:\Users\admin\AppData\Local\Temp\Unicorn-5567.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-5567.exe | Unicorn-24474.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1020 | C:\Users\admin\AppData\Local\Temp\Unicorn-45650.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-45650.exe | — | Unicorn-12258.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1052 | C:\Users\admin\AppData\Local\Temp\Unicorn-24474.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-24474.exe | Unicorn-1593.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1096 | C:\Users\admin\AppData\Local\Temp\Unicorn-11697.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-11697.exe | Unicorn-40212.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1116 | C:\Users\admin\AppData\Local\Temp\Unicorn-2305.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-2305.exe | Unicorn-16898.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1128 | C:\Users\admin\AppData\Local\Temp\Unicorn-24696.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-24696.exe | Unicorn-55921.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1188 | C:\Users\admin\AppData\Local\Temp\Unicorn-20752.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-20752.exe | 1 (1204).exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1052 | Unicorn-24474.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-1889.exe | executable | |
MD5:3A5676914B19B4E78640B8454A7F7CB7 | SHA256:9085E117FC95634647DEA2B57387EA7AF60BDE679AE7A8058D9D8CBE3E032ABB | |||
| 1188 | Unicorn-20752.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-22502.exe | executable | |
MD5:84B59BCDDB3ED0781B6F8CD8C1CE008A | SHA256:376AE660F86FEB0C3E694D0E5268D1C3924544412FDD50B046E7CC74F349FDA9 | |||
| 6032 | 1 (1204).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-20752.exe | executable | |
MD5:8CBC1E9863EB98835A0EC9BF902AF091 | SHA256:213261A33EC6CEB7FD1B0AF412390014688B659CC4B4185462E9156F4B724E76 | |||
| 6404 | Unicorn-1593.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-24474.exe | executable | |
MD5:94344AB1E605583EE530C52D77D3B224 | SHA256:249F5516794FA694B3A7E8978672D30D09DD561645AC7EC395FB6833746FFE24 | |||
| 6032 | 1 (1204).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-1593.exe | executable | |
MD5:AE844FBBCDF372C3D50D3437C2081CAF | SHA256:82DB66C70321D0CA4F7DF738593426E002D4F7553A87F21984A32C4ED015FAA9 | |||
| 6564 | Unicorn-1889.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-57250.exe | executable | |
MD5:08A79A5AC579A66062731BB4D7EED998 | SHA256:6D90E0350B9741B71DDB93218B47210BDBFF94A0FDDA5F6AE89F77241ABA7401 | |||
| 6032 | 1 (1204).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-20455.exe | executable | |
MD5:16265CB0F154C2F68B3C0365C18FEE50 | SHA256:431463A6D39BBD7147B17F4B4BF19FF1A885FD615985076711EA71742E272C2B | |||
| 6404 | Unicorn-1593.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-55921.exe | executable | |
MD5:67A83F075ECC9E6C18C184F7FA4BB174 | SHA256:DD6E8AB687DBE3E93E96DEEA0A9C2606C1B5D33B8D7F723178A508E72AF856A5 | |||
| 3900 | Unicorn-57250.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-44562.exe | executable | |
MD5:87A771B662A90C90F8C3CC52DB5D8165 | SHA256:2FF7C2D4F31E995C957E184C4A99E3143C075B824C3305D63671C81D6334B2DD | |||
| 6068 | Unicorn-49829.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-60706.exe | executable | |
MD5:E520561AB7BB6B86D6A8C5D10666B6D0 | SHA256:88D5BF7F978F083B7A36CB5ABEB092D53461BCA2D31D56FD471934323186CC61 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 104.124.11.58:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6240 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
8200 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
8200 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 104.124.11.58:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
2104 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2112 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3216 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 40.126.32.140:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
6240 | backgroundTaskHost.exe | 20.223.35.26:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |