| File name: | 1 (1204) |
| Full analysis: | https://app.any.run/tasks/1542b104-13a5-4b1a-b9b6-b1b6383380ec |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2025, 11:24:55 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, 3 sections |
| MD5: | A51D3750F1A48E83E1DABAEBCC7A6EE0 |
| SHA1: | 82FFE4D346DF49D949F137A3334F6F3CE496A44E |
| SHA256: | 3478AA4215E76162FB55D532923DE1EE99DF68DA632366C40E15C61B2082773D |
| SSDEEP: | 6144:PTLglnIJoDlWQ5AN6/e/RpoxGtBqcvJGBc/6yeOKgk/8SwjwpyAvEheADb+nUPpa:P/MIEWQ5W62BBdhaciyeOK6x4DxmDsR |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:01:19 13:34:56+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit, No debug, Removable run from swap, Net run from swap, Uniprocessor only, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 299008 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13d4 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | UEFI |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 644 | C:\Users\admin\AppData\Local\Temp\Unicorn-60706.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-60706.exe | Unicorn-49829.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 856 | C:\Users\admin\AppData\Local\Temp\Unicorn-48070.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-48070.exe | Unicorn-13477.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 872 | C:\Users\admin\AppData\Local\Temp\Unicorn-10945.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-10945.exe | — | Unicorn-45154.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1012 | C:\Users\admin\AppData\Local\Temp\Unicorn-5567.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-5567.exe | Unicorn-24474.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1020 | C:\Users\admin\AppData\Local\Temp\Unicorn-45650.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-45650.exe | — | Unicorn-12258.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1052 | C:\Users\admin\AppData\Local\Temp\Unicorn-24474.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-24474.exe | Unicorn-1593.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1096 | C:\Users\admin\AppData\Local\Temp\Unicorn-11697.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-11697.exe | Unicorn-40212.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1116 | C:\Users\admin\AppData\Local\Temp\Unicorn-2305.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-2305.exe | Unicorn-16898.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1128 | C:\Users\admin\AppData\Local\Temp\Unicorn-24696.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-24696.exe | Unicorn-55921.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1188 | C:\Users\admin\AppData\Local\Temp\Unicorn-20752.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-20752.exe | 1 (1204).exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6032 | 1 (1204).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-20455.exe | executable | |
MD5:16265CB0F154C2F68B3C0365C18FEE50 | SHA256:431463A6D39BBD7147B17F4B4BF19FF1A885FD615985076711EA71742E272C2B | |||
| 1052 | Unicorn-24474.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-49829.exe | executable | |
MD5:7F3DD368802E53185B30DD1AEE1FA555 | SHA256:F4A461A2235E35D9736CC916947C8C2A44762B076F478B48526394237D866E48 | |||
| 1188 | Unicorn-20752.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-22502.exe | executable | |
MD5:84B59BCDDB3ED0781B6F8CD8C1CE008A | SHA256:376AE660F86FEB0C3E694D0E5268D1C3924544412FDD50B046E7CC74F349FDA9 | |||
| 6032 | 1 (1204).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-20752.exe | executable | |
MD5:8CBC1E9863EB98835A0EC9BF902AF091 | SHA256:213261A33EC6CEB7FD1B0AF412390014688B659CC4B4185462E9156F4B724E76 | |||
| 6404 | Unicorn-1593.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-55921.exe | executable | |
MD5:67A83F075ECC9E6C18C184F7FA4BB174 | SHA256:DD6E8AB687DBE3E93E96DEEA0A9C2606C1B5D33B8D7F723178A508E72AF856A5 | |||
| 1812 | Unicorn-55921.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-38174.exe | executable | |
MD5:655A4FE5D023D493EB9DF6D177F80F9B | SHA256:5E913ECAF2A46FD7EE1617BC5884ED139F2D8433FC2130C3C5520BEC3E815196 | |||
| 5164 | Unicorn-20455.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-13477.exe | executable | |
MD5:FAB7F9ECA3EC4E7B62C7B1E1769B45D8 | SHA256:A537F334D86369461B77428D47EA5864F213C27F1A80FD492CBC5008BA3B0A92 | |||
| 6404 | Unicorn-1593.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-40212.exe | executable | |
MD5:DF3F4C827CD67449E5510FB67EA2A433 | SHA256:9430A7D83B1C693004CF9F3B44C9E6E06B714B8B936FE2AB4324FF5981B45E15 | |||
| 6032 | 1 (1204).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-21380.exe | executable | |
MD5:AA42D5953BAC5C18C4A8BDA2D3CCFFE6 | SHA256:07A607E472AEA5030C6ABE4700D819F818CE6C840F378A55B9EF51573DB77950 | |||
| 1188 | Unicorn-20752.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-26476.exe | executable | |
MD5:A0C441DCF729B618BBE72B07D80515DC | SHA256:43559C33702AC4644DC0BB5947DAFFA1FADD216765A257A401B595592334CCDA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 104.124.11.58:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
8200 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
8200 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
6240 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 104.124.11.58:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
2104 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2112 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3216 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 40.126.32.140:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
6240 | backgroundTaskHost.exe | 20.223.35.26:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |