File name:

1 (589)

Full analysis: https://app.any.run/tasks/5782f4d4-e458-4ae0-8337-889f96f1f205
Verdict: Malicious activity
Analysis date: March 25, 2025, 03:14:26
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections
MD5:

48E83D0FEADFBA831DB8F45166D3E8B0

SHA1:

5DC523ADF710F5075C1598CD26E080756471CF32

SHA256:

3B30BABACDC99EC999E04095F1579641B1EA87D0717A10037ADB1518700A57A4

SSDEEP:

6144:t70gAKIBvDpHAk+XTZeMJvfC4KBqlvJGBCIW2erdak/8SwjwpyivEhyy5LSAslXa:tIZxXHAkeTY5BMhaCz2erdhx4DxmDsR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts itself from another location

      • Unicorn-49727.exe (PID: 4688)
      • 1 (589).exe (PID: 2564)
      • Unicorn-15508.exe (PID: 2244)
      • Unicorn-28507.exe (PID: 6476)
      • Unicorn-47509.exe (PID: 4244)
      • Unicorn-1323.exe (PID: 6708)
      • Unicorn-27451.exe (PID: 5392)
      • Unicorn-57331.exe (PID: 2692)
      • Unicorn-34588.exe (PID: 616)
      • Unicorn-53420.exe (PID: 1228)
      • Unicorn-53420.exe (PID: 2600)
      • Unicorn-30866.exe (PID: 2096)
      • Unicorn-33685.exe (PID: 3096)
      • Unicorn-17083.exe (PID: 728)
      • Unicorn-13819.exe (PID: 3100)
      • Unicorn-43891.exe (PID: 680)
      • Unicorn-38060.exe (PID: 5984)
      • Unicorn-34469.exe (PID: 5360)
      • Unicorn-28146.exe (PID: 5260)
      • Unicorn-14603.exe (PID: 6068)
      • Unicorn-39212.exe (PID: 1040)
      • Unicorn-39212.exe (PID: 6592)
      • Unicorn-32697.exe (PID: 7272)
      • Unicorn-35356.exe (PID: 7240)
      • Unicorn-15947.exe (PID: 2040)
      • Unicorn-19477.exe (PID: 7184)
      • Unicorn-35813.exe (PID: 856)
      • Unicorn-3140.exe (PID: 7196)
      • Unicorn-29897.exe (PID: 7260)
      • Unicorn-60540.exe (PID: 7716)
      • Unicorn-17173.exe (PID: 7812)
      • Unicorn-836.exe (PID: 7824)
      • Unicorn-34604.exe (PID: 7684)
      • Unicorn-836.exe (PID: 7832)
      • Unicorn-36259.exe (PID: 7880)
      • Unicorn-27186.exe (PID: 7864)
      • Unicorn-24101.exe (PID: 8056)
      • Unicorn-24101.exe (PID: 8048)
      • Unicorn-15755.exe (PID: 7248)
      • Unicorn-13088.exe (PID: 8104)
      • Unicorn-13088.exe (PID: 8096)
      • Unicorn-866.exe (PID: 8180)
      • Unicorn-51407.exe (PID: 7380)
      • Unicorn-52305.exe (PID: 8160)
      • Unicorn-40245.exe (PID: 8136)
      • Unicorn-57951.exe (PID: 7444)
      • Unicorn-61708.exe (PID: 7464)
      • Unicorn-57951.exe (PID: 7452)
      • Unicorn-13451.exe (PID: 7856)
      • Unicorn-61708.exe (PID: 7472)
      • Unicorn-6612.exe (PID: 7424)
      • Unicorn-15422.exe (PID: 7528)
      • Unicorn-15422.exe (PID: 7316)
      • Unicorn-19913.exe (PID: 7348)
      • Unicorn-1687.exe (PID: 7520)
      • Unicorn-8978.exe (PID: 7544)
      • Unicorn-35813.exe (PID: 5228)
      • Unicorn-61708.exe (PID: 7484)
      • Unicorn-65148.exe (PID: 7172)
      • Unicorn-3378.exe (PID: 7536)
      • Unicorn-8978.exe (PID: 7340)
      • Unicorn-64147.exe (PID: 7552)
      • Unicorn-48325.exe (PID: 6228)
      • Unicorn-11826.exe (PID: 3300)
      • Unicorn-1812.exe (PID: 7772)
      • Unicorn-12594.exe (PID: 8020)
      • Unicorn-15579.exe (PID: 7972)
      • Unicorn-2964.exe (PID: 7948)
      • Unicorn-19109.exe (PID: 780)
      • Unicorn-15771.exe (PID: 2148)
      • Unicorn-9794.exe (PID: 8016)
      • Unicorn-15771.exe (PID: 6112)
      • Unicorn-2580.exe (PID: 7996)
      • Unicorn-35637.exe (PID: 8028)
      • Unicorn-18459.exe (PID: 8036)
      • Unicorn-2964.exe (PID: 7944)
      • Unicorn-59251.exe (PID: 5084)
      • Unicorn-29724.exe (PID: 7592)
      • Unicorn-29724.exe (PID: 7620)
      • Unicorn-24907.exe (PID: 4652)
      • Unicorn-5883.exe (PID: 7924)
      • Unicorn-28821.exe (PID: 8204)
      • Unicorn-45349.exe (PID: 7752)
      • Unicorn-42042.exe (PID: 8224)
      • Unicorn-46885.exe (PID: 8272)
      • Unicorn-49324.exe (PID: 8384)
      • Unicorn-23240.exe (PID: 8248)
      • Unicorn-53045.exe (PID: 8372)
      • Unicorn-11882.exe (PID: 8296)
      • Unicorn-21333.exe (PID: 8528)
      • Unicorn-20491.exe (PID: 8340)
      • Unicorn-51300.exe (PID: 8424)
      • Unicorn-36709.exe (PID: 8348)
      • Unicorn-2235.exe (PID: 8448)
      • Unicorn-55795.exe (PID: 8692)
      • Unicorn-40165.exe (PID: 8652)
      • Unicorn-37669.exe (PID: 8520)
      • Unicorn-4804.exe (PID: 8592)
      • Unicorn-4804.exe (PID: 8584)
      • Unicorn-6612.exe (PID: 7416)
      • Unicorn-7170.exe (PID: 8676)
      • Unicorn-53813.exe (PID: 8636)
      • Unicorn-35867.exe (PID: 8804)
      • Unicorn-23445.exe (PID: 8704)
      • Unicorn-18274.exe (PID: 8988)
      • Unicorn-35867.exe (PID: 8796)
      • Unicorn-23445.exe (PID: 8700)
      • Unicorn-24524.exe (PID: 8900)
      • Unicorn-57715.exe (PID: 8840)
      • Unicorn-98.exe (PID: 8856)
      • Unicorn-25564.exe (PID: 9084)
      • Unicorn-39205.exe (PID: 8784)
      • Unicorn-5499.exe (PID: 8848)
      • Unicorn-18274.exe (PID: 8992)
      • Unicorn-39397.exe (PID: 8752)
      • Unicorn-8763.exe (PID: 8864)
      • Unicorn-17890.exe (PID: 9036)
      • Unicorn-4539.exe (PID: 9004)
      • Unicorn-28188.exe (PID: 8888)
      • Unicorn-64860.exe (PID: 8908)
      • Unicorn-39205.exe (PID: 8820)
      • Unicorn-31141.exe (PID: 9212)
      • Unicorn-34732.exe (PID: 9180)
      • Unicorn-36003.exe (PID: 7580)
      • Unicorn-20124.exe (PID: 8308)
      • Unicorn-59987.exe (PID: 8288)
      • Unicorn-48172.exe (PID: 9228)
      • Unicorn-57669.exe (PID: 9284)
      • Unicorn-23845.exe (PID: 9332)
      • Unicorn-23845.exe (PID: 9340)
      • Unicorn-41141.exe (PID: 9300)
      • Unicorn-9044.exe (PID: 9420)
      • Unicorn-53184.exe (PID: 9444)
      • Unicorn-9044.exe (PID: 9428)
      • Unicorn-9044.exe (PID: 9412)
      • Unicorn-9044.exe (PID: 9404)
      • Unicorn-57020.exe (PID: 9584)
      • Unicorn-7284.exe (PID: 8324)
      • Unicorn-53148.exe (PID: 9664)
      • Unicorn-58748.exe (PID: 9692)
      • Unicorn-43122.exe (PID: 9640)
      • Unicorn-30508.exe (PID: 9624)
      • Unicorn-6946.exe (PID: 9680)
    • Executable content was dropped or overwritten

      • 1 (589).exe (PID: 2564)
      • Unicorn-49727.exe (PID: 4688)
      • Unicorn-15508.exe (PID: 2244)
      • Unicorn-28507.exe (PID: 6476)
      • Unicorn-1323.exe (PID: 6708)
      • Unicorn-47509.exe (PID: 4244)
      • Unicorn-34588.exe (PID: 616)
      • Unicorn-57331.exe (PID: 2692)
      • Unicorn-53420.exe (PID: 2600)
      • Unicorn-43891.exe (PID: 680)
      • Unicorn-27451.exe (PID: 5392)
      • Unicorn-13819.exe (PID: 3100)
      • Unicorn-17083.exe (PID: 728)
      • Unicorn-38060.exe (PID: 5984)
      • Unicorn-34469.exe (PID: 5360)
      • Unicorn-14603.exe (PID: 6068)
      • Unicorn-30866.exe (PID: 2096)
      • Unicorn-39212.exe (PID: 6592)
      • Unicorn-32697.exe (PID: 7272)
      • Unicorn-15755.exe (PID: 7248)
      • Unicorn-35813.exe (PID: 856)
      • Unicorn-15947.exe (PID: 2040)
      • Unicorn-19477.exe (PID: 7184)
      • Unicorn-34604.exe (PID: 7684)
      • Unicorn-60540.exe (PID: 7716)
      • Unicorn-17173.exe (PID: 7812)
      • Unicorn-836.exe (PID: 7832)
      • Unicorn-36259.exe (PID: 7880)
      • Unicorn-27186.exe (PID: 7864)
      • Unicorn-24101.exe (PID: 8056)
      • Unicorn-13088.exe (PID: 8096)
      • Unicorn-53420.exe (PID: 1228)
      • Unicorn-39212.exe (PID: 1040)
      • Unicorn-13088.exe (PID: 8104)
      • Unicorn-866.exe (PID: 8180)
      • Unicorn-51407.exe (PID: 7380)
      • Unicorn-52305.exe (PID: 8160)
      • Unicorn-13451.exe (PID: 7856)
      • Unicorn-40245.exe (PID: 8136)
      • Unicorn-61708.exe (PID: 7464)
      • Unicorn-57951.exe (PID: 7444)
      • Unicorn-6612.exe (PID: 7416)
      • Unicorn-15422.exe (PID: 7528)
      • Unicorn-3140.exe (PID: 7196)
      • Unicorn-28579.exe (PID: 7344)
      • Unicorn-61708.exe (PID: 7472)
      • Unicorn-15422.exe (PID: 7316)
      • Unicorn-19913.exe (PID: 7348)
      • Unicorn-8978.exe (PID: 7544)
      • Unicorn-35356.exe (PID: 7240)
      • Unicorn-29897.exe (PID: 7260)
      • Unicorn-8978.exe (PID: 7340)
      • Unicorn-3378.exe (PID: 7536)
      • Unicorn-65148.exe (PID: 7172)
      • Unicorn-48325.exe (PID: 6228)
      • Unicorn-64147.exe (PID: 7552)
      • Unicorn-1812.exe (PID: 7772)
      • Unicorn-11826.exe (PID: 3300)
      • Unicorn-12594.exe (PID: 8020)
      • Unicorn-15579.exe (PID: 7972)
      • Unicorn-35637.exe (PID: 8028)
      • Unicorn-15771.exe (PID: 2148)
      • Unicorn-18459.exe (PID: 8036)
      • Unicorn-2964.exe (PID: 7944)
      • Unicorn-28146.exe (PID: 5260)
      • Unicorn-836.exe (PID: 7824)
      • Unicorn-59251.exe (PID: 5084)
      • Unicorn-5883.exe (PID: 7924)
      • Unicorn-29724.exe (PID: 7592)
      • Unicorn-29724.exe (PID: 7620)
      • Unicorn-24907.exe (PID: 4652)
      • Unicorn-24101.exe (PID: 8048)
      • Unicorn-28821.exe (PID: 8204)
      • Unicorn-42042.exe (PID: 8224)
      • Unicorn-45349.exe (PID: 7752)
      • Unicorn-46885.exe (PID: 8272)
      • Unicorn-49324.exe (PID: 8384)
      • Unicorn-7284.exe (PID: 8324)
      • Unicorn-23240.exe (PID: 8248)
      • Unicorn-11882.exe (PID: 8296)
      • Unicorn-53045.exe (PID: 8372)
      • Unicorn-21333.exe (PID: 8528)
      • Unicorn-51300.exe (PID: 8424)
      • Unicorn-20491.exe (PID: 8340)
      • Unicorn-36709.exe (PID: 8348)
      • Unicorn-2235.exe (PID: 8448)
      • Unicorn-55795.exe (PID: 8692)
      • Unicorn-40165.exe (PID: 8652)
      • Unicorn-37669.exe (PID: 8520)
      • Unicorn-4804.exe (PID: 8592)
      • Unicorn-4804.exe (PID: 8584)
      • Unicorn-7170.exe (PID: 8676)
      • Unicorn-53813.exe (PID: 8636)
      • Unicorn-35867.exe (PID: 8804)
      • Unicorn-23445.exe (PID: 8704)
      • Unicorn-23253.exe (PID: 8720)
      • Unicorn-57951.exe (PID: 7452)
      • Unicorn-18274.exe (PID: 8988)
      • Unicorn-35867.exe (PID: 8796)
      • Unicorn-98.exe (PID: 8856)
      • Unicorn-23445.exe (PID: 8700)
      • Unicorn-24524.exe (PID: 8900)
      • Unicorn-40741.exe (PID: 8980)
      • Unicorn-57715.exe (PID: 8840)
      • Unicorn-39205.exe (PID: 8784)
      • Unicorn-1687.exe (PID: 7520)
      • Unicorn-5499.exe (PID: 8848)
      • Unicorn-61708.exe (PID: 7484)
      • Unicorn-18274.exe (PID: 8992)
      • Unicorn-4539.exe (PID: 9004)
      • Unicorn-28188.exe (PID: 8888)
      • Unicorn-17890.exe (PID: 9036)
      • Unicorn-33685.exe (PID: 3096)
      • Unicorn-64860.exe (PID: 8908)
      • Unicorn-39205.exe (PID: 8820)
      • Unicorn-31141.exe (PID: 9212)
      • Unicorn-2964.exe (PID: 7948)
      • Unicorn-34732.exe (PID: 9180)
      • Unicorn-15771.exe (PID: 6112)
      • Unicorn-2580.exe (PID: 7996)
      • Unicorn-20124.exe (PID: 8308)
      • Unicorn-36003.exe (PID: 7580)
      • Unicorn-48172.exe (PID: 9228)
      • Unicorn-57669.exe (PID: 9284)
      • Unicorn-23845.exe (PID: 9332)
      • Unicorn-23845.exe (PID: 9340)
      • Unicorn-41141.exe (PID: 9300)
      • Unicorn-9044.exe (PID: 9428)
      • Unicorn-60741.exe (PID: 9552)
      • Unicorn-53184.exe (PID: 9444)
      • Unicorn-9044.exe (PID: 9420)
      • Unicorn-9044.exe (PID: 9412)
      • Unicorn-9044.exe (PID: 9404)
      • Unicorn-57020.exe (PID: 9584)
      • Unicorn-30508.exe (PID: 9624)
      • Unicorn-53148.exe (PID: 9664)
      • Unicorn-58748.exe (PID: 9692)
      • Unicorn-6946.exe (PID: 9680)
      • Unicorn-36626.exe (PID: 9740)
      • Unicorn-57024.exe (PID: 9732)
      • Unicorn-6833.exe (PID: 9764)
      • Unicorn-58748.exe (PID: 9672)
      • Unicorn-18085.exe (PID: 9796)
      • Unicorn-34395.exe (PID: 9836)
      • Unicorn-14996.exe (PID: 9192)
      • Unicorn-19813.exe (PID: 9872)
      • Unicorn-59987.exe (PID: 8288)
      • Unicorn-19109.exe (PID: 780)
      • Unicorn-9794.exe (PID: 8016)
      • Unicorn-64524.exe (PID: 9952)
      • Unicorn-36149.exe (PID: 9892)
      • Unicorn-30402.exe (PID: 9856)
      • Unicorn-22444.exe (PID: 9928)
      • Unicorn-6612.exe (PID: 7424)
      • Unicorn-16313.exe (PID: 9920)
      • Unicorn-25564.exe (PID: 9084)
      • Unicorn-8763.exe (PID: 8864)
      • Unicorn-35813.exe (PID: 5228)
      • Unicorn-38645.exe (PID: 10080)
      • Unicorn-43387.exe (PID: 10156)
      • Unicorn-17068.exe (PID: 10180)
      • Unicorn-13476.exe (PID: 10200)
      • Unicorn-44348.exe (PID: 9320)
      • Unicorn-64332.exe (PID: 10228)
      • Unicorn-16357.exe (PID: 8816)
      • Unicorn-43122.exe (PID: 9640)
      • Unicorn-15287.exe (PID: 7624)
      • Unicorn-18395.exe (PID: 9976)
      • Unicorn-15026.exe (PID: 10000)
      • Unicorn-9044.exe (PID: 9396)
      • Unicorn-2242.exe (PID: 10132)
      • Unicorn-1883.exe (PID: 8440)
      • Unicorn-40389.exe (PID: 10124)
      • Unicorn-7332.exe (PID: 9792)
      • Unicorn-61084.exe (PID: 10352)
      • Unicorn-58069.exe (PID: 10332)
      • Unicorn-54732.exe (PID: 10276)
      • Unicorn-9361.exe (PID: 10384)
      • Unicorn-60181.exe (PID: 10420)
      • Unicorn-39205.exe (PID: 8776)
      • Unicorn-25179.exe (PID: 10432)
      • Unicorn-19650.exe (PID: 10268)
      • Unicorn-6329.exe (PID: 10260)
      • Unicorn-7451.exe (PID: 10444)
      • Unicorn-52371.exe (PID: 10556)
      • Unicorn-39397.exe (PID: 8752)
      • Unicorn-54348.exe (PID: 8444)
      • Unicorn-43404.exe (PID: 10100)
      • Unicorn-51484.exe (PID: 10640)
      • Unicorn-54172.exe (PID: 10684)
      • Unicorn-1764.exe (PID: 10668)
      • Unicorn-34245.exe (PID: 10704)
      • Unicorn-65500.exe (PID: 10764)
      • Unicorn-59827.exe (PID: 10744)
      • Unicorn-6315.exe (PID: 10784)
      • Unicorn-27317.exe (PID: 10452)
      • Unicorn-48012.exe (PID: 10824)
      • Unicorn-32251.exe (PID: 10800)
      • Unicorn-37125.exe (PID: 10892)
      • Unicorn-22827.exe (PID: 10532)
      • Unicorn-40307.exe (PID: 10568)
      • Unicorn-59059.exe (PID: 10592)
      • Unicorn-23403.exe (PID: 10480)
    • Executes application which crashes

      • Unicorn-63164.exe (PID: 6300)
  • INFO

    • Reads the computer name

      • 1 (589).exe (PID: 2564)
      • Unicorn-49727.exe (PID: 4688)
      • Unicorn-15508.exe (PID: 2244)
      • Unicorn-28507.exe (PID: 6476)
      • Unicorn-47509.exe (PID: 4244)
      • Unicorn-27451.exe (PID: 5392)
      • Unicorn-1323.exe (PID: 6708)
      • Unicorn-57331.exe (PID: 2692)
      • Unicorn-34588.exe (PID: 616)
      • Unicorn-30866.exe (PID: 2096)
      • Unicorn-53420.exe (PID: 1228)
      • Unicorn-53420.exe (PID: 2600)
      • Unicorn-43891.exe (PID: 680)
      • Unicorn-33685.exe (PID: 3096)
      • Unicorn-17083.exe (PID: 728)
      • Unicorn-13819.exe (PID: 3100)
      • Unicorn-34469.exe (PID: 5360)
      • Unicorn-28146.exe (PID: 5260)
      • Unicorn-38060.exe (PID: 5984)
      • Unicorn-14603.exe (PID: 6068)
      • Unicorn-39212.exe (PID: 6592)
      • Unicorn-39212.exe (PID: 1040)
      • Unicorn-19477.exe (PID: 7184)
      • Unicorn-65148.exe (PID: 7172)
      • Unicorn-15947.exe (PID: 2040)
      • Unicorn-35813.exe (PID: 5228)
      • Unicorn-3140.exe (PID: 7196)
      • Unicorn-15755.exe (PID: 7248)
      • Unicorn-35356.exe (PID: 7240)
      • Unicorn-32697.exe (PID: 7272)
      • Unicorn-35813.exe (PID: 856)
      • Unicorn-29897.exe (PID: 7260)
      • Unicorn-34604.exe (PID: 7684)
      • Unicorn-60540.exe (PID: 7716)
      • Unicorn-17173.exe (PID: 7812)
      • Unicorn-836.exe (PID: 7832)
      • Unicorn-836.exe (PID: 7824)
      • Unicorn-27186.exe (PID: 7864)
      • Unicorn-13451.exe (PID: 7856)
      • Unicorn-36259.exe (PID: 7880)
      • Unicorn-13088.exe (PID: 8104)
      • Unicorn-24101.exe (PID: 8056)
      • Unicorn-24101.exe (PID: 8048)
      • Unicorn-40245.exe (PID: 8136)
      • Unicorn-866.exe (PID: 8180)
      • Unicorn-51407.exe (PID: 7380)
      • Unicorn-13088.exe (PID: 8096)
      • Unicorn-61708.exe (PID: 7464)
      • Unicorn-57951.exe (PID: 7444)
      • Unicorn-57951.exe (PID: 7452)
      • Unicorn-6612.exe (PID: 7416)
      • Unicorn-52305.exe (PID: 8160)
      • Unicorn-15422.exe (PID: 7528)
      • Unicorn-6612.exe (PID: 7424)
      • Unicorn-28579.exe (PID: 7344)
      • Unicorn-15422.exe (PID: 7316)
      • Unicorn-19913.exe (PID: 7348)
      • Unicorn-1687.exe (PID: 7520)
      • Unicorn-61708.exe (PID: 7484)
      • Unicorn-8978.exe (PID: 7544)
      • Unicorn-61708.exe (PID: 7472)
      • Unicorn-8978.exe (PID: 7340)
      • Unicorn-3378.exe (PID: 7536)
      • Unicorn-48325.exe (PID: 6228)
      • Unicorn-11826.exe (PID: 3300)
      • Unicorn-64147.exe (PID: 7552)
      • Unicorn-1812.exe (PID: 7772)
      • Unicorn-12594.exe (PID: 8020)
      • Unicorn-15579.exe (PID: 7972)
      • Unicorn-2964.exe (PID: 7948)
      • Unicorn-35637.exe (PID: 8028)
      • Unicorn-15771.exe (PID: 6112)
      • Unicorn-15771.exe (PID: 2148)
      • Unicorn-19109.exe (PID: 780)
      • Unicorn-9794.exe (PID: 8016)
      • Unicorn-2580.exe (PID: 7996)
      • Unicorn-2964.exe (PID: 7944)
      • Unicorn-18459.exe (PID: 8036)
      • Unicorn-59251.exe (PID: 5084)
      • Unicorn-29724.exe (PID: 7620)
      • Unicorn-24907.exe (PID: 4652)
      • Unicorn-5883.exe (PID: 7924)
      • Unicorn-29724.exe (PID: 7592)
      • Unicorn-28821.exe (PID: 8204)
      • Unicorn-42042.exe (PID: 8224)
      • Unicorn-45349.exe (PID: 7752)
      • Unicorn-55650.exe (PID: 9452)
      • Unicorn-23240.exe (PID: 8248)
      • Unicorn-46885.exe (PID: 8272)
      • Unicorn-49324.exe (PID: 8384)
      • Unicorn-7284.exe (PID: 8324)
      • Unicorn-11882.exe (PID: 8296)
      • Unicorn-53045.exe (PID: 8372)
      • Unicorn-36709.exe (PID: 8348)
      • Unicorn-21333.exe (PID: 8528)
      • Unicorn-20491.exe (PID: 8340)
      • Unicorn-2235.exe (PID: 8448)
      • Unicorn-40165.exe (PID: 8652)
      • Unicorn-55795.exe (PID: 8692)
      • Unicorn-37669.exe (PID: 8520)
      • Unicorn-51300.exe (PID: 8424)
      • Unicorn-4804.exe (PID: 8584)
      • Unicorn-4804.exe (PID: 8592)
      • Unicorn-7170.exe (PID: 8676)
      • Unicorn-23445.exe (PID: 8704)
      • Unicorn-23253.exe (PID: 8720)
      • Unicorn-53813.exe (PID: 8636)
      • Unicorn-35867.exe (PID: 8804)
      • Unicorn-23445.exe (PID: 8700)
      • Unicorn-18274.exe (PID: 8988)
      • Unicorn-35867.exe (PID: 8796)
      • Unicorn-98.exe (PID: 8856)
      • Unicorn-39205.exe (PID: 8784)
      • Unicorn-24524.exe (PID: 8900)
      • Unicorn-8763.exe (PID: 8864)
      • Unicorn-5499.exe (PID: 8848)
      • Unicorn-39397.exe (PID: 8752)
      • Unicorn-18274.exe (PID: 8992)
      • Unicorn-4539.exe (PID: 9004)
      • Unicorn-25564.exe (PID: 9084)
      • Unicorn-39205.exe (PID: 8776)
      • Unicorn-40741.exe (PID: 8980)
      • Unicorn-57715.exe (PID: 8840)
      • Unicorn-64860.exe (PID: 8908)
      • Unicorn-17890.exe (PID: 9036)
      • Unicorn-28188.exe (PID: 8888)
      • Unicorn-39205.exe (PID: 8820)
      • Unicorn-34732.exe (PID: 9180)
      • Unicorn-14996.exe (PID: 9192)
      • Unicorn-31141.exe (PID: 9212)
      • Unicorn-59987.exe (PID: 8288)
      • Unicorn-36003.exe (PID: 7580)
      • Unicorn-20124.exe (PID: 8308)
      • Unicorn-48172.exe (PID: 9228)
      • Unicorn-57669.exe (PID: 9284)
      • Unicorn-41141.exe (PID: 9300)
      • Unicorn-23845.exe (PID: 9340)
      • Unicorn-23845.exe (PID: 9332)
      • Unicorn-9044.exe (PID: 9428)
      • Unicorn-9044.exe (PID: 9420)
      • Unicorn-9044.exe (PID: 9396)
      • Unicorn-53184.exe (PID: 9444)
      • Unicorn-60741.exe (PID: 9552)
      • Unicorn-57020.exe (PID: 9584)
      • Unicorn-9044.exe (PID: 9412)
      • Unicorn-9044.exe (PID: 9404)
      • Unicorn-30508.exe (PID: 9624)
      • Unicorn-53148.exe (PID: 9664)
      • Unicorn-58748.exe (PID: 9692)
      • Unicorn-43122.exe (PID: 9640)
      • Unicorn-6946.exe (PID: 9680)
      • Unicorn-36626.exe (PID: 9740)
      • Unicorn-57024.exe (PID: 9732)
      • Unicorn-58748.exe (PID: 9672)
      • Unicorn-6833.exe (PID: 9764)
    • The sample compiled with chinese language support

      • 1 (589).exe (PID: 2564)
      • Unicorn-42042.exe (PID: 8224)
      • Unicorn-45349.exe (PID: 7752)
      • Unicorn-53420.exe (PID: 2600)
      • Unicorn-13088.exe (PID: 8104)
      • Unicorn-9044.exe (PID: 9428)
      • Unicorn-23240.exe (PID: 8248)
      • Unicorn-9044.exe (PID: 9420)
      • Unicorn-46885.exe (PID: 8272)
      • Unicorn-9044.exe (PID: 9404)
      • Unicorn-40245.exe (PID: 8136)
      • Unicorn-30508.exe (PID: 9624)
      • Unicorn-58748.exe (PID: 9692)
      • Unicorn-52305.exe (PID: 8160)
      • Unicorn-2235.exe (PID: 8448)
      • Unicorn-23845.exe (PID: 9332)
      • Unicorn-21333.exe (PID: 8528)
      • Unicorn-51300.exe (PID: 8424)
      • Unicorn-19477.exe (PID: 7184)
      • Unicorn-55795.exe (PID: 8692)
      • Unicorn-32697.exe (PID: 7272)
      • Unicorn-4804.exe (PID: 8592)
      • Unicorn-58748.exe (PID: 9672)
      • Unicorn-23445.exe (PID: 8700)
      • Unicorn-18274.exe (PID: 8988)
      • Unicorn-51407.exe (PID: 7380)
      • Unicorn-57951.exe (PID: 7444)
      • Unicorn-17083.exe (PID: 728)
      • Unicorn-1323.exe (PID: 6708)
      • Unicorn-98.exe (PID: 8856)
      • Unicorn-13451.exe (PID: 7856)
      • Unicorn-53148.exe (PID: 9664)
      • Unicorn-5883.exe (PID: 7924)
      • Unicorn-24907.exe (PID: 4652)
      • Unicorn-4539.exe (PID: 9004)
    • Checks supported languages

      • 1 (589).exe (PID: 2564)
      • Unicorn-49727.exe (PID: 4688)
      • Unicorn-15508.exe (PID: 2244)
      • Unicorn-28507.exe (PID: 6476)
      • Unicorn-47509.exe (PID: 4244)
      • Unicorn-27451.exe (PID: 5392)
      • Unicorn-1323.exe (PID: 6708)
      • Unicorn-34588.exe (PID: 616)
      • Unicorn-30866.exe (PID: 2096)
      • Unicorn-53420.exe (PID: 1228)
      • Unicorn-57331.exe (PID: 2692)
      • Unicorn-53420.exe (PID: 2600)
      • Unicorn-43891.exe (PID: 680)
      • Unicorn-33685.exe (PID: 3096)
      • Unicorn-13819.exe (PID: 3100)
      • Unicorn-17083.exe (PID: 728)
      • Unicorn-34469.exe (PID: 5360)
      • Unicorn-14603.exe (PID: 6068)
      • Unicorn-28146.exe (PID: 5260)
      • Unicorn-39212.exe (PID: 6592)
      • Unicorn-39212.exe (PID: 1040)
      • Unicorn-38060.exe (PID: 5984)
      • Unicorn-15947.exe (PID: 2040)
      • Unicorn-35813.exe (PID: 5228)
      • Unicorn-19477.exe (PID: 7184)
      • Unicorn-65148.exe (PID: 7172)
      • Unicorn-15755.exe (PID: 7248)
      • Unicorn-35356.exe (PID: 7240)
      • Unicorn-3140.exe (PID: 7196)
      • Unicorn-35813.exe (PID: 856)
      • Unicorn-29897.exe (PID: 7260)
      • Unicorn-32697.exe (PID: 7272)
      • Unicorn-34604.exe (PID: 7684)
      • Unicorn-60540.exe (PID: 7716)
      • Unicorn-17173.exe (PID: 7812)
      • Unicorn-836.exe (PID: 7824)
      • Unicorn-836.exe (PID: 7832)
      • Unicorn-27186.exe (PID: 7864)
      • Unicorn-13451.exe (PID: 7856)
      • Unicorn-36259.exe (PID: 7880)
      • Unicorn-24101.exe (PID: 8056)
      • Unicorn-24101.exe (PID: 8048)
      • Unicorn-13088.exe (PID: 8096)
      • Unicorn-13088.exe (PID: 8104)
      • Unicorn-57951.exe (PID: 7444)
      • Unicorn-40245.exe (PID: 8136)
      • Unicorn-52305.exe (PID: 8160)
      • Unicorn-866.exe (PID: 8180)
      • Unicorn-51407.exe (PID: 7380)
      • Unicorn-57951.exe (PID: 7452)
      • Unicorn-6612.exe (PID: 7424)
      • Unicorn-61708.exe (PID: 7464)
      • Unicorn-61708.exe (PID: 7484)
      • Unicorn-6612.exe (PID: 7416)
      • Unicorn-61708.exe (PID: 7472)
      • Unicorn-1687.exe (PID: 7520)
      • Unicorn-8978.exe (PID: 7544)
      • Unicorn-15422.exe (PID: 7528)
      • Unicorn-19913.exe (PID: 7348)
      • Unicorn-8978.exe (PID: 7340)
      • Unicorn-28579.exe (PID: 7344)
      • Unicorn-3378.exe (PID: 7536)
      • Unicorn-15422.exe (PID: 7316)
      • Unicorn-48325.exe (PID: 6228)
      • Unicorn-64147.exe (PID: 7552)
      • Unicorn-1812.exe (PID: 7772)
      • Unicorn-11826.exe (PID: 3300)
      • Unicorn-19109.exe (PID: 780)
      • Unicorn-15771.exe (PID: 6112)
      • Unicorn-2580.exe (PID: 7996)
      • Unicorn-15579.exe (PID: 7972)
      • Unicorn-18459.exe (PID: 8036)
      • Unicorn-15771.exe (PID: 2148)
      • Unicorn-9794.exe (PID: 8016)
      • Unicorn-2964.exe (PID: 7948)
      • Unicorn-2964.exe (PID: 7944)
      • Unicorn-12594.exe (PID: 8020)
      • Unicorn-35637.exe (PID: 8028)
      • Unicorn-59251.exe (PID: 5084)
      • Unicorn-29724.exe (PID: 7592)
      • Unicorn-29724.exe (PID: 7620)
      • Unicorn-24907.exe (PID: 4652)
      • Unicorn-28821.exe (PID: 8204)
      • Unicorn-45349.exe (PID: 7752)
      • Unicorn-42042.exe (PID: 8224)
      • Unicorn-23240.exe (PID: 8248)
      • Unicorn-5883.exe (PID: 7924)
      • Unicorn-11882.exe (PID: 8296)
      • Unicorn-7284.exe (PID: 8324)
      • Unicorn-20491.exe (PID: 8340)
      • Unicorn-36709.exe (PID: 8348)
      • Unicorn-46885.exe (PID: 8272)
      • Unicorn-53045.exe (PID: 8372)
      • Unicorn-49324.exe (PID: 8384)
      • Unicorn-51300.exe (PID: 8424)
      • Unicorn-2235.exe (PID: 8448)
      • Unicorn-37669.exe (PID: 8520)
      • Unicorn-21333.exe (PID: 8528)
      • Unicorn-40165.exe (PID: 8652)
      • Unicorn-53813.exe (PID: 8636)
      • Unicorn-7170.exe (PID: 8676)
      • Unicorn-4804.exe (PID: 8592)
      • Unicorn-4804.exe (PID: 8584)
      • Unicorn-55795.exe (PID: 8692)
      • Unicorn-23253.exe (PID: 8720)
      • Unicorn-23445.exe (PID: 8700)
      • Unicorn-23445.exe (PID: 8704)
      • Unicorn-39397.exe (PID: 8752)
      • Unicorn-39205.exe (PID: 8776)
      • Unicorn-35867.exe (PID: 8796)
      • Unicorn-24524.exe (PID: 8900)
      • Unicorn-64860.exe (PID: 8908)
      • Unicorn-40741.exe (PID: 8980)
      • Unicorn-39205.exe (PID: 8820)
      • Unicorn-35867.exe (PID: 8804)
      • Unicorn-57715.exe (PID: 8840)
      • Unicorn-5499.exe (PID: 8848)
      • Unicorn-8763.exe (PID: 8864)
      • Unicorn-28188.exe (PID: 8888)
      • Unicorn-98.exe (PID: 8856)
      • Unicorn-4539.exe (PID: 9004)
      • Unicorn-25564.exe (PID: 9084)
      • Unicorn-18274.exe (PID: 8988)
      • Unicorn-17890.exe (PID: 9036)
      • Unicorn-18274.exe (PID: 8992)
      • Unicorn-14996.exe (PID: 9192)
      • Unicorn-31141.exe (PID: 9212)
      • Unicorn-63164.exe (PID: 6300)
      • Unicorn-34732.exe (PID: 9180)
      • Unicorn-59987.exe (PID: 8288)
      • Unicorn-48172.exe (PID: 9228)
      • Unicorn-41141.exe (PID: 9300)
      • Unicorn-57669.exe (PID: 9284)
      • Unicorn-20124.exe (PID: 8308)
      • Unicorn-36003.exe (PID: 7580)
      • Unicorn-23845.exe (PID: 9332)
      • Unicorn-53184.exe (PID: 9444)
      • Unicorn-9044.exe (PID: 9396)
      • Unicorn-9044.exe (PID: 9428)
      • Unicorn-9044.exe (PID: 9420)
      • Unicorn-55650.exe (PID: 9452)
      • Unicorn-23845.exe (PID: 9340)
      • Unicorn-9044.exe (PID: 9412)
      • Unicorn-60741.exe (PID: 9552)
      • Unicorn-57020.exe (PID: 9584)
      • Unicorn-30508.exe (PID: 9624)
      • Unicorn-43122.exe (PID: 9640)
      • Unicorn-9044.exe (PID: 9404)
      • Unicorn-58748.exe (PID: 9692)
      • Unicorn-36626.exe (PID: 9740)
      • Unicorn-57024.exe (PID: 9732)
      • Unicorn-6833.exe (PID: 9764)
      • Unicorn-18085.exe (PID: 9796)
      • Unicorn-53148.exe (PID: 9664)
      • Unicorn-58748.exe (PID: 9672)
      • Unicorn-6946.exe (PID: 9680)
      • Unicorn-34395.exe (PID: 9836)
      • Unicorn-19813.exe (PID: 9872)
      • Unicorn-36149.exe (PID: 9892)
      • Unicorn-16313.exe (PID: 9920)
      • Unicorn-22444.exe (PID: 9928)
      • Unicorn-30402.exe (PID: 9856)
      • Unicorn-15026.exe (PID: 10000)
      • Unicorn-18395.exe (PID: 9976)
      • Unicorn-2242.exe (PID: 10132)
      • Unicorn-38645.exe (PID: 10080)
      • Unicorn-43387.exe (PID: 10156)
      • Unicorn-64524.exe (PID: 9952)
      • Unicorn-17068.exe (PID: 10180)
      • Unicorn-44348.exe (PID: 9320)
      • Unicorn-13476.exe (PID: 10200)
      • Unicorn-64332.exe (PID: 10228)
      • Unicorn-16357.exe (PID: 8816)
      • Unicorn-15287.exe (PID: 7624)
      • Unicorn-54348.exe (PID: 8444)
      • Unicorn-1883.exe (PID: 8440)
      • Unicorn-40389.exe (PID: 10124)
      • Unicorn-54732.exe (PID: 10276)
      • Unicorn-43404.exe (PID: 10100)
      • Unicorn-7332.exe (PID: 9792)
      • Unicorn-19650.exe (PID: 10268)
      • Unicorn-6329.exe (PID: 10260)
      • Unicorn-58069.exe (PID: 10332)
      • Unicorn-61084.exe (PID: 10352)
      • Unicorn-9361.exe (PID: 10384)
      • Unicorn-60181.exe (PID: 10420)
      • Unicorn-7451.exe (PID: 10444)
      • Unicorn-25179.exe (PID: 10432)
      • Unicorn-23403.exe (PID: 10480)
      • Unicorn-22827.exe (PID: 10532)
      • Unicorn-52371.exe (PID: 10556)
      • Unicorn-40307.exe (PID: 10568)
      • Unicorn-27317.exe (PID: 10452)
      • Unicorn-59059.exe (PID: 10592)
      • Unicorn-54172.exe (PID: 10684)
      • Unicorn-1764.exe (PID: 10668)
      • Unicorn-34245.exe (PID: 10704)
      • Unicorn-51484.exe (PID: 10640)
      • Unicorn-65500.exe (PID: 10764)
      • Unicorn-6315.exe (PID: 10784)
      • Unicorn-48012.exe (PID: 10824)
      • Unicorn-4644.exe (PID: 10864)
      • Unicorn-59827.exe (PID: 10744)
      • Unicorn-32251.exe (PID: 10800)
      • Unicorn-7083.exe (PID: 10908)
      • Unicorn-52755.exe (PID: 10916)
      • Unicorn-56092.exe (PID: 10952)
      • Unicorn-11585.exe (PID: 10980)
      • Unicorn-39205.exe (PID: 8784)
      • Unicorn-37125.exe (PID: 10892)
      • Unicorn-11201.exe (PID: 11020)
      • Unicorn-54573.exe (PID: 11060)
      • Unicorn-45794.exe (PID: 11104)
      • Unicorn-59670.exe (PID: 11120)
      • Unicorn-45410.exe (PID: 11136)
      • Unicorn-12737.exe (PID: 11148)
      • Unicorn-45410.exe (PID: 11164)
      • Unicorn-61746.exe (PID: 11188)
      • Unicorn-61554.exe (PID: 11204)
      • Unicorn-8632.exe (PID: 2384)
      • Unicorn-44450.exe (PID: 5164)
      • Unicorn-60101.exe (PID: 1196)
      • Unicorn-28498.exe (PID: 11256)
      • Unicorn-44450.exe (PID: 11288)
      • Unicorn-61554.exe (PID: 11212)
      • Unicorn-24584.exe (PID: 3268)
      • Unicorn-58797.exe (PID: 11316)
      • Unicorn-24584.exe (PID: 5304)
      • Unicorn-30994.exe (PID: 11268)
      • Unicorn-60329.exe (PID: 11276)
      • Unicorn-60101.exe (PID: 4268)
      • Unicorn-58797.exe (PID: 11308)
      • Unicorn-38200.exe (PID: 11376)
      • Unicorn-30418.exe (PID: 11420)
      • Unicorn-30610.exe (PID: 11404)
      • Unicorn-24776.exe (PID: 10636)
      • Unicorn-54352.exe (PID: 11480)
      • Unicorn-63666.exe (PID: 11396)
      • Unicorn-57536.exe (PID: 11496)
      • Unicorn-54882.exe (PID: 11448)
      • Unicorn-9976.exe (PID: 11536)
      • Unicorn-43416.exe (PID: 11460)
      • Unicorn-62441.exe (PID: 11560)
      • Unicorn-23711.exe (PID: 11544)
      • Unicorn-32265.exe (PID: 11608)
      • Unicorn-54736.exe (PID: 11388)
      • Unicorn-33624.exe (PID: 11764)
      • Unicorn-33135.exe (PID: 11832)
      • Unicorn-33624.exe (PID: 11772)
      • Unicorn-19784.exe (PID: 11804)
      • Unicorn-18632.exe (PID: 11880)
      • Unicorn-38233.exe (PID: 11872)
      • Unicorn-27704.exe (PID: 11596)
      • Unicorn-29577.exe (PID: 11552)
      • Unicorn-16194.exe (PID: 11636)
      • Unicorn-3092.exe (PID: 11732)
      • Unicorn-56095.exe (PID: 11896)
      • Unicorn-62432.exe (PID: 11888)
      • Unicorn-56095.exe (PID: 11916)
      • Unicorn-2876.exe (PID: 12000)
      • Unicorn-6136.exe (PID: 12028)
      • Unicorn-5944.exe (PID: 12068)
      • Unicorn-35440.exe (PID: 12124)
      • Unicorn-35440.exe (PID: 12120)
      • Unicorn-38040.exe (PID: 12152)
      • Unicorn-12104.exe (PID: 12168)
      • Unicorn-37429.exe (PID: 11932)
      • Unicorn-65327.exe (PID: 12192)
      • Unicorn-65327.exe (PID: 12188)
      • Unicorn-14408.exe (PID: 12220)
      • Unicorn-46505.exe (PID: 12244)
      • Unicorn-46505.exe (PID: 12252)
      • Unicorn-13448.exe (PID: 12272)
      • Unicorn-13448.exe (PID: 12280)
      • Unicorn-26607.exe (PID: 924)
      • Unicorn-13448.exe (PID: 11184)
      • Unicorn-46998.exe (PID: 3032)
      • Unicorn-46614.exe (PID: 9120)
      • Unicorn-12191.exe (PID: 2968)
      • Unicorn-42978.exe (PID: 11704)
      • Unicorn-18056.exe (PID: 12296)
      • Unicorn-12191.exe (PID: 12064)
      • Unicorn-2597.exe (PID: 12336)
      • Unicorn-25528.exe (PID: 12344)
      • Unicorn-11423.exe (PID: 12372)
      • Unicorn-33122.exe (PID: 3024)
      • Unicorn-33049.exe (PID: 12264)
      • Unicorn-9887.exe (PID: 11728)
      • Unicorn-33541.exe (PID: 12392)
      • Unicorn-39317.exe (PID: 12440)
      • Unicorn-41513.exe (PID: 12448)
      • Unicorn-5000.exe (PID: 12472)
      • Unicorn-43049.exe (PID: 12608)
      • Unicorn-21528.exe (PID: 12488)
      • Unicorn-8565.exe (PID: 12536)
      • Unicorn-28166.exe (PID: 12524)
      • Unicorn-21039.exe (PID: 12548)
      • Unicorn-53520.exe (PID: 12592)
      • Unicorn-2753.exe (PID: 12400)
      • Unicorn-38087.exe (PID: 12712)
      • Unicorn-62530.exe (PID: 12764)
      • Unicorn-61762.exe (PID: 12628)
      • Unicorn-12177.exe (PID: 12660)
      • Unicorn-15768.exe (PID: 12900)
      • Unicorn-14236.exe (PID: 12872)
      • Unicorn-41753.exe (PID: 12952)
      • Unicorn-14127.exe (PID: 12968)
      • Unicorn-15897.exe (PID: 12860)
      • Unicorn-32789.exe (PID: 12920)
      • Unicorn-21794.exe (PID: 13032)
      • Unicorn-33531.exe (PID: 13040)
      • Unicorn-23055.exe (PID: 13004)
      • Unicorn-23906.exe (PID: 13100)
      • Unicorn-57647.exe (PID: 13108)
      • Unicorn-53625.exe (PID: 13076)
      • Unicorn-40272.exe (PID: 13184)
      • Unicorn-13537.exe (PID: 13176)
      • Unicorn-31804.exe (PID: 13160)
      • Unicorn-23906.exe (PID: 13092)
      • Unicorn-58249.exe (PID: 13296)
      • Unicorn-42104.exe (PID: 13288)
      • Unicorn-6993.exe (PID: 13144)
      • Unicorn-56002.exe (PID: 13152)
      • Unicorn-59510.exe (PID: 13276)
      • Unicorn-14040.exe (PID: 4272)
      • Unicorn-41040.exe (PID: 4608)
      • Unicorn-59785.exe (PID: 1600)
      • Unicorn-14040.exe (PID: 4012)
      • Unicorn-26920.exe (PID: 13320)
      • Unicorn-48047.exe (PID: 5232)
    • Create files in a temporary directory

      • 1 (589).exe (PID: 2564)
      • Unicorn-49727.exe (PID: 4688)
      • Unicorn-15508.exe (PID: 2244)
      • Unicorn-47509.exe (PID: 4244)
      • Unicorn-1323.exe (PID: 6708)
      • Unicorn-28507.exe (PID: 6476)
      • Unicorn-34588.exe (PID: 616)
      • Unicorn-57331.exe (PID: 2692)
      • Unicorn-53420.exe (PID: 1228)
      • Unicorn-43891.exe (PID: 680)
      • Unicorn-17083.exe (PID: 728)
      • Unicorn-27451.exe (PID: 5392)
      • Unicorn-13819.exe (PID: 3100)
      • Unicorn-38060.exe (PID: 5984)
      • Unicorn-34469.exe (PID: 5360)
      • Unicorn-30866.exe (PID: 2096)
      • Unicorn-14603.exe (PID: 6068)
      • Unicorn-39212.exe (PID: 6592)
      • Unicorn-53420.exe (PID: 2600)
      • Unicorn-15947.exe (PID: 2040)
      • Unicorn-15755.exe (PID: 7248)
      • Unicorn-32697.exe (PID: 7272)
      • Unicorn-19477.exe (PID: 7184)
      • Unicorn-34604.exe (PID: 7684)
      • Unicorn-836.exe (PID: 7832)
      • Unicorn-27186.exe (PID: 7864)
      • Unicorn-36259.exe (PID: 7880)
      • Unicorn-24101.exe (PID: 8056)
      • Unicorn-13088.exe (PID: 8104)
      • Unicorn-13088.exe (PID: 8096)
      • Unicorn-39212.exe (PID: 1040)
      • Unicorn-866.exe (PID: 8180)
      • Unicorn-51407.exe (PID: 7380)
      • Unicorn-52305.exe (PID: 8160)
      • Unicorn-61708.exe (PID: 7464)
      • Unicorn-6612.exe (PID: 7416)
      • Unicorn-57951.exe (PID: 7444)
      • Unicorn-3140.exe (PID: 7196)
      • Unicorn-28579.exe (PID: 7344)
      • Unicorn-61708.exe (PID: 7472)
      • Unicorn-15422.exe (PID: 7316)
      • Unicorn-19913.exe (PID: 7348)
      • Unicorn-8978.exe (PID: 7544)
      • Unicorn-35356.exe (PID: 7240)
      • Unicorn-65148.exe (PID: 7172)
      • Unicorn-35813.exe (PID: 856)
      • Unicorn-3378.exe (PID: 7536)
      • Unicorn-8978.exe (PID: 7340)
      • Unicorn-29897.exe (PID: 7260)
      • Unicorn-48325.exe (PID: 6228)
      • Unicorn-1812.exe (PID: 7772)
      • Unicorn-11826.exe (PID: 3300)
      • Unicorn-15579.exe (PID: 7972)
      • Unicorn-35637.exe (PID: 8028)
      • Unicorn-60540.exe (PID: 7716)
      • Unicorn-15771.exe (PID: 2148)
      • Unicorn-17173.exe (PID: 7812)
      • Unicorn-2964.exe (PID: 7944)
      • Unicorn-28146.exe (PID: 5260)
      • Unicorn-18459.exe (PID: 8036)
      • Unicorn-836.exe (PID: 7824)
      • Unicorn-59251.exe (PID: 5084)
      • Unicorn-5883.exe (PID: 7924)
      • Unicorn-29724.exe (PID: 7620)
      • Unicorn-24907.exe (PID: 4652)
      • Unicorn-24101.exe (PID: 8048)
      • Unicorn-29724.exe (PID: 7592)
      • Unicorn-28821.exe (PID: 8204)
      • Unicorn-45349.exe (PID: 7752)
      • Unicorn-42042.exe (PID: 8224)
      • Unicorn-46885.exe (PID: 8272)
      • Unicorn-40245.exe (PID: 8136)
      • Unicorn-49324.exe (PID: 8384)
      • Unicorn-23240.exe (PID: 8248)
      • Unicorn-53045.exe (PID: 8372)
      • Unicorn-13451.exe (PID: 7856)
      • Unicorn-7284.exe (PID: 8324)
      • Unicorn-11882.exe (PID: 8296)
      • Unicorn-36709.exe (PID: 8348)
      • Unicorn-21333.exe (PID: 8528)
      • Unicorn-51300.exe (PID: 8424)
      • Unicorn-20491.exe (PID: 8340)
      • Unicorn-2235.exe (PID: 8448)
      • Unicorn-55795.exe (PID: 8692)
      • Unicorn-37669.exe (PID: 8520)
      • Unicorn-4804.exe (PID: 8592)
      • Unicorn-40165.exe (PID: 8652)
      • Unicorn-4804.exe (PID: 8584)
      • Unicorn-23445.exe (PID: 8704)
      • Unicorn-7170.exe (PID: 8676)
      • Unicorn-15422.exe (PID: 7528)
      • Unicorn-23253.exe (PID: 8720)
      • Unicorn-57951.exe (PID: 7452)
      • Unicorn-53813.exe (PID: 8636)
      • Unicorn-35867.exe (PID: 8804)
      • Unicorn-23445.exe (PID: 8700)
      • Unicorn-18274.exe (PID: 8988)
      • Unicorn-35867.exe (PID: 8796)
      • Unicorn-98.exe (PID: 8856)
      • Unicorn-40741.exe (PID: 8980)
      • Unicorn-57715.exe (PID: 8840)
      • Unicorn-39205.exe (PID: 8784)
      • Unicorn-24524.exe (PID: 8900)
      • Unicorn-18274.exe (PID: 8992)
      • Unicorn-61708.exe (PID: 7484)
      • Unicorn-1687.exe (PID: 7520)
      • Unicorn-5499.exe (PID: 8848)
      • Unicorn-4539.exe (PID: 9004)
      • Unicorn-17890.exe (PID: 9036)
      • Unicorn-28188.exe (PID: 8888)
      • Unicorn-33685.exe (PID: 3096)
      • Unicorn-64860.exe (PID: 8908)
      • Unicorn-39205.exe (PID: 8820)
      • Unicorn-31141.exe (PID: 9212)
      • Unicorn-64147.exe (PID: 7552)
      • Unicorn-34732.exe (PID: 9180)
      • Unicorn-12594.exe (PID: 8020)
      • Unicorn-2964.exe (PID: 7948)
      • Unicorn-2580.exe (PID: 7996)
      • Unicorn-15771.exe (PID: 6112)
      • Unicorn-20124.exe (PID: 8308)
      • Unicorn-36003.exe (PID: 7580)
      • Unicorn-48172.exe (PID: 9228)
      • Unicorn-57669.exe (PID: 9284)
      • Unicorn-23845.exe (PID: 9332)
      • Unicorn-23845.exe (PID: 9340)
      • Unicorn-41141.exe (PID: 9300)
      • Unicorn-60741.exe (PID: 9552)
      • Unicorn-53184.exe (PID: 9444)
      • Unicorn-57020.exe (PID: 9584)
      • Unicorn-9044.exe (PID: 9428)
      • Unicorn-9044.exe (PID: 9420)
      • Unicorn-9044.exe (PID: 9404)
      • Unicorn-9044.exe (PID: 9412)
      • Unicorn-30508.exe (PID: 9624)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 7328)
      • BackgroundTransferHost.exe (PID: 7564)
      • BackgroundTransferHost.exe (PID: 7764)
      • BackgroundTransferHost.exe (PID: 7624)
      • BackgroundTransferHost.exe (PID: 8884)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 7564)
      • WerFault.exe (PID: 11704)
    • Checks proxy server information

      • BackgroundTransferHost.exe (PID: 7564)
    • Reads the software policy settings

      • BackgroundTransferHost.exe (PID: 7564)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:01:20 00:32:00+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 176128
InitializedDataSize: 299008
UninitializedDataSize: -
EntryPoint: 0x13d4
OSVersion: 4
ImageVersion: 1
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: UEFI
ProductName: Kawaii-Unicorn
FileVersion: 1
ProductVersion: 1
InternalName: Kawaii-Unicorn
OriginalFileName: Kawaii-Unicorn.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
493
Monitored processes
358
Malicious processes
52
Suspicious processes
52

Behavior graph

Click at the process to see the details
start 1 (589).exe sppextcomobj.exe no specs slui.exe no specs unicorn-49727.exe unicorn-15508.exe unicorn-28507.exe unicorn-47509.exe unicorn-27451.exe unicorn-1323.exe unicorn-57331.exe unicorn-34588.exe unicorn-30866.exe unicorn-53420.exe unicorn-53420.exe unicorn-43891.exe unicorn-13819.exe unicorn-33685.exe unicorn-17083.exe unicorn-38060.exe unicorn-14603.exe unicorn-34469.exe unicorn-28146.exe unicorn-39212.exe unicorn-39212.exe unicorn-15947.exe unicorn-35813.exe unicorn-35813.exe unicorn-65148.exe unicorn-19477.exe unicorn-3140.exe unicorn-35356.exe unicorn-15755.exe unicorn-29897.exe unicorn-32697.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe unicorn-34604.exe unicorn-60540.exe backgroundtransferhost.exe no specs unicorn-17173.exe unicorn-836.exe unicorn-836.exe unicorn-13451.exe unicorn-27186.exe unicorn-36259.exe unicorn-24101.exe unicorn-24101.exe unicorn-13088.exe unicorn-13088.exe unicorn-40245.exe unicorn-52305.exe unicorn-866.exe unicorn-51407.exe unicorn-6612.exe unicorn-6612.exe unicorn-57951.exe unicorn-57951.exe unicorn-61708.exe unicorn-61708.exe unicorn-61708.exe unicorn-1687.exe unicorn-15422.exe unicorn-3378.exe unicorn-19913.exe unicorn-8978.exe unicorn-28579.exe unicorn-8978.exe unicorn-15422.exe backgroundtransferhost.exe no specs unicorn-48325.exe unicorn-64147.exe unicorn-1812.exe unicorn-11826.exe unicorn-2964.exe unicorn-2964.exe unicorn-19109.exe unicorn-15771.exe unicorn-2580.exe unicorn-15579.exe unicorn-15771.exe unicorn-9794.exe unicorn-12594.exe unicorn-35637.exe unicorn-18459.exe unicorn-59251.exe unicorn-29724.exe unicorn-29724.exe unicorn-5883.exe unicorn-24907.exe unicorn-45349.exe unicorn-28821.exe unicorn-42042.exe unicorn-23240.exe unicorn-46885.exe unicorn-11882.exe unicorn-7284.exe unicorn-20491.exe unicorn-36709.exe unicorn-53045.exe unicorn-49324.exe unicorn-51300.exe unicorn-2235.exe unicorn-37669.exe unicorn-21333.exe unicorn-4804.exe unicorn-4804.exe unicorn-53813.exe unicorn-40165.exe unicorn-7170.exe unicorn-55795.exe unicorn-23445.exe unicorn-23445.exe unicorn-23253.exe unicorn-39397.exe unicorn-39205.exe unicorn-39205.exe unicorn-35867.exe unicorn-35867.exe unicorn-39205.exe unicorn-57715.exe unicorn-5499.exe unicorn-98.exe unicorn-8763.exe unicorn-28188.exe unicorn-24524.exe unicorn-64860.exe unicorn-40741.exe unicorn-18274.exe unicorn-18274.exe unicorn-4539.exe unicorn-17890.exe unicorn-25564.exe unicorn-34732.exe unicorn-14996.exe unicorn-31141.exe unicorn-63164.exe unicorn-59987.exe unicorn-20124.exe unicorn-36003.exe backgroundtransferhost.exe no specs unicorn-48172.exe unicorn-57669.exe unicorn-41141.exe unicorn-23845.exe unicorn-23845.exe unicorn-9044.exe unicorn-9044.exe unicorn-9044.exe unicorn-9044.exe unicorn-9044.exe unicorn-53184.exe unicorn-55650.exe no specs unicorn-60741.exe unicorn-57020.exe unicorn-30508.exe unicorn-43122.exe unicorn-53148.exe unicorn-58748.exe unicorn-6946.exe unicorn-58748.exe unicorn-57024.exe unicorn-36626.exe unicorn-6833.exe unicorn-18085.exe unicorn-34395.exe unicorn-30402.exe unicorn-19813.exe unicorn-36149.exe unicorn-16313.exe unicorn-22444.exe unicorn-64524.exe unicorn-18395.exe unicorn-15026.exe unicorn-38645.exe unicorn-2242.exe unicorn-43387.exe unicorn-17068.exe unicorn-13476.exe unicorn-64332.exe unicorn-44348.exe unicorn-16357.exe unicorn-15287.exe unicorn-54348.exe unicorn-1883.exe unicorn-43404.exe unicorn-40389.exe unicorn-7332.exe unicorn-6329.exe unicorn-19650.exe unicorn-54732.exe unicorn-58069.exe unicorn-61084.exe unicorn-9361.exe unicorn-60181.exe unicorn-25179.exe unicorn-7451.exe unicorn-27317.exe unicorn-23403.exe unicorn-22827.exe unicorn-52371.exe unicorn-40307.exe unicorn-59059.exe unicorn-51484.exe unicorn-1764.exe unicorn-54172.exe unicorn-34245.exe unicorn-59827.exe unicorn-65500.exe unicorn-6315.exe unicorn-32251.exe unicorn-48012.exe unicorn-4644.exe no specs unicorn-37125.exe unicorn-7083.exe no specs unicorn-52755.exe no specs unicorn-56092.exe no specs unicorn-11585.exe no specs unicorn-11201.exe no specs unicorn-54573.exe no specs unicorn-45794.exe no specs unicorn-59670.exe no specs unicorn-45410.exe no specs unicorn-12737.exe no specs unicorn-45410.exe no specs unicorn-61746.exe no specs unicorn-61554.exe no specs unicorn-61554.exe no specs unicorn-28498.exe no specs unicorn-24776.exe no specs unicorn-8632.exe no specs unicorn-60101.exe no specs unicorn-60101.exe no specs unicorn-44450.exe no specs unicorn-24584.exe no specs unicorn-24584.exe no specs unicorn-30994.exe no specs unicorn-60329.exe no specs unicorn-44450.exe no specs unicorn-58797.exe no specs unicorn-58797.exe no specs unicorn-38200.exe no specs unicorn-54736.exe no specs unicorn-63666.exe no specs unicorn-30610.exe no specs unicorn-30418.exe no specs unicorn-54882.exe no specs unicorn-43416.exe no specs unicorn-54352.exe no specs unicorn-57536.exe no specs unicorn-9976.exe no specs unicorn-23711.exe no specs unicorn-29577.exe no specs unicorn-62441.exe no specs unicorn-27704.exe no specs unicorn-32265.exe no specs unicorn-16194.exe no specs werfault.exe no specs unicorn-3092.exe no specs unicorn-33624.exe no specs unicorn-33624.exe no specs unicorn-19784.exe no specs unicorn-33135.exe no specs unicorn-38233.exe no specs unicorn-18632.exe no specs unicorn-62432.exe no specs unicorn-56095.exe no specs unicorn-56095.exe no specs unicorn-37429.exe no specs unicorn-2876.exe no specs unicorn-6136.exe no specs unicorn-5944.exe no specs unicorn-35440.exe no specs unicorn-35440.exe no specs unicorn-38040.exe no specs unicorn-12104.exe no specs unicorn-65327.exe no specs unicorn-65327.exe no specs unicorn-14408.exe no specs unicorn-46505.exe no specs unicorn-46505.exe no specs unicorn-33049.exe no specs unicorn-13448.exe no specs unicorn-13448.exe no specs unicorn-13448.exe no specs unicorn-33122.exe no specs unicorn-46998.exe no specs unicorn-26607.exe no specs unicorn-46614.exe no specs unicorn-9887.exe no specs unicorn-42978.exe no specs unicorn-12191.exe no specs unicorn-12191.exe no specs unicorn-18056.exe no specs unicorn-2597.exe no specs unicorn-25528.exe no specs unicorn-11423.exe no specs unicorn-33541.exe no specs unicorn-2753.exe no specs unicorn-39317.exe no specs unicorn-41513.exe no specs unicorn-5000.exe no specs unicorn-21528.exe no specs unicorn-28166.exe no specs unicorn-8565.exe no specs unicorn-21039.exe no specs unicorn-53520.exe no specs unicorn-43049.exe no specs unicorn-61762.exe no specs unicorn-12177.exe no specs unicorn-38087.exe no specs unicorn-63791.exe no specs unicorn-62530.exe no specs unicorn-15897.exe no specs unicorn-14236.exe no specs unicorn-15768.exe no specs unicorn-32789.exe no specs unicorn-41753.exe no specs unicorn-14127.exe no specs unicorn-23055.exe no specs unicorn-21794.exe no specs unicorn-33531.exe no specs unicorn-53625.exe no specs unicorn-23906.exe no specs unicorn-23906.exe no specs unicorn-57647.exe no specs unicorn-6993.exe no specs unicorn-56002.exe no specs unicorn-31804.exe no specs unicorn-13537.exe no specs unicorn-40272.exe no specs unicorn-59510.exe no specs unicorn-42104.exe no specs unicorn-58249.exe no specs unicorn-14040.exe no specs unicorn-14040.exe no specs unicorn-41040.exe no specs unicorn-59785.exe no specs unicorn-48047.exe no specs unicorn-26920.exe no specs unicorn-59401.exe no specs unicorn-62930.exe no specs unicorn-14341.exe no specs unicorn-16034.exe no specs unicorn-16034.exe no specs unicorn-62582.exe no specs unicorn-44985.exe no specs unicorn-58720.exe no specs unicorn-12312.exe no specs unicorn-42000.exe no specs unicorn-60832.exe no specs unicorn-8639.exe no specs unicorn-58518.exe no specs unicorn-33449.exe no specs unicorn-36344.exe no specs unicorn-1342.exe no specs unicorn-21208.exe no specs unicorn-35768.exe no specs unicorn-3096.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
616C:\Users\admin\AppData\Local\Temp\Unicorn-34588.exeC:\Users\admin\AppData\Local\Temp\Unicorn-34588.exe
Unicorn-47509.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-34588.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
680C:\Users\admin\AppData\Local\Temp\Unicorn-43891.exeC:\Users\admin\AppData\Local\Temp\Unicorn-43891.exe
Unicorn-49727.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-43891.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
728C:\Users\admin\AppData\Local\Temp\Unicorn-17083.exeC:\Users\admin\AppData\Local\Temp\Unicorn-17083.exe
1 (589).exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-17083.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
780C:\Users\admin\AppData\Local\Temp\Unicorn-19109.exeC:\Users\admin\AppData\Local\Temp\Unicorn-19109.exe
Unicorn-836.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-19109.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
856C:\Users\admin\AppData\Local\Temp\Unicorn-35813.exeC:\Users\admin\AppData\Local\Temp\Unicorn-35813.exe
Unicorn-33685.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-35813.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
924C:\Users\admin\AppData\Local\Temp\Unicorn-26607.exeC:\Users\admin\AppData\Local\Temp\Unicorn-26607.exeUnicorn-17173.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-26607.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1040C:\Users\admin\AppData\Local\Temp\Unicorn-39212.exeC:\Users\admin\AppData\Local\Temp\Unicorn-39212.exe
Unicorn-53420.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-39212.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1196C:\Users\admin\AppData\Local\Temp\Unicorn-60101.exeC:\Users\admin\AppData\Local\Temp\Unicorn-60101.exeUnicorn-39205.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-60101.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1228C:\Users\admin\AppData\Local\Temp\Unicorn-53420.exeC:\Users\admin\AppData\Local\Temp\Unicorn-53420.exe
Unicorn-1323.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-53420.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1600C:\Users\admin\AppData\Local\Temp\Unicorn-59785.exeC:\Users\admin\AppData\Local\Temp\Unicorn-59785.exeUnicorn-53045.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-59785.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
Total events
10 339
Read events
10 324
Write events
15
Delete events
0

Modification events

(PID) Process:(7328) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7328) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7328) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7564) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7564) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7564) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7764) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7764) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7764) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7624) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
Executable files
1 051
Suspicious files
5
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
4688Unicorn-49727.exeC:\Users\admin\AppData\Local\Temp\Unicorn-15508.exeexecutable
MD5:EB4171CB41460C840AFE3A4822EE36CE
SHA256:DCE86415047BB8D75258942D42EE9AC1BEE9B30D8E3C1EBAB39A6B26C1F2D1AD
25641 (589).exeC:\Users\admin\AppData\Local\Temp\Unicorn-28507.exeexecutable
MD5:2E0ED64FB0BEFD33970793169CEBD95E
SHA256:5C8534B3A5915C052DC769286D1DD3BD2E12ABDFF43A3D288281A92973F41627
6476Unicorn-28507.exeC:\Users\admin\AppData\Local\Temp\Unicorn-1323.exeexecutable
MD5:948FA0B6009D3BAFA8FF125E7C3F951A
SHA256:5E6D547D81FA71AEC5F5CC13BC0C0BCBF5FA358EFCC64559BA932B39EB9E13CE
25641 (589).exeC:\Users\admin\AppData\Local\Temp\Unicorn-49727.exeexecutable
MD5:F6F4F80D7B8040F15AABBBDA1004C4DA
SHA256:31A6BD420F20245614BB7984643E1A9F12E2527B85218F65C994CE05BB5B37BE
2244Unicorn-15508.exeC:\Users\admin\AppData\Local\Temp\Unicorn-47509.exeexecutable
MD5:7BD52AD4B42C3D6B29A3BFDB583275EA
SHA256:98032FE89AE91DC302F44ADF15C4330FB47A48B78F3C7C92F5BB07DB3852F918
4688Unicorn-49727.exeC:\Users\admin\AppData\Local\Temp\Unicorn-27451.exeexecutable
MD5:7AEACD7EA58F5C8901B1A4352B9401E3
SHA256:21DC5E91183554C66DF36A379AE8A75B286962A32A2A7BF78B0CCF950F7A7588
25641 (589).exeC:\Users\admin\AppData\Local\Temp\Unicorn-57331.exeexecutable
MD5:3E77B34E8591AC3995CA37710283F982
SHA256:296653AB6FB3195AA38B38A41A9F7B3E37D5BA4D3011019C5F3D0ABF76B1BD13
4244Unicorn-47509.exeC:\Users\admin\AppData\Local\Temp\Unicorn-34588.exeexecutable
MD5:2AD0BAFAB332A631D90E2171082226EB
SHA256:2028E3D2480F899768BFF8A84B686AE069D278CB6BB808A602D3D95E02E07008
4244Unicorn-47509.exeC:\Users\admin\AppData\Local\Temp\Unicorn-14603.exeexecutable
MD5:69F1D156458641A61ED1ED110AE208A0
SHA256:C80912473A5AB005A26B00493C52B6AD18BC04B77C3B5CA53D84E19DA3E0BCB3
2244Unicorn-15508.exeC:\Users\admin\AppData\Local\Temp\Unicorn-30866.exeexecutable
MD5:31B71275AB71D61A782C1DBD72087579
SHA256:A0AAC4649B8298302F2150984F273EE0FC7FBE84655A70E27395D125EC9CA75F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
23
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2136
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7564
BackgroundTransferHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
8812
SIHClient.exe
GET
200
92.123.22.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
8812
SIHClient.exe
GET
200
92.123.22.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
2.16.164.120:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
20.190.160.65:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
3216
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2136
backgroundTaskHost.exe
20.199.58.43:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
2136
backgroundTaskHost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 2.16.164.120
  • 2.16.164.72
whitelisted
google.com
  • 142.250.185.238
whitelisted
login.live.com
  • 20.190.160.65
  • 20.190.160.67
  • 20.190.160.132
  • 20.190.160.22
  • 20.190.160.2
  • 40.126.32.68
  • 20.190.160.3
  • 20.190.160.131
whitelisted
ocsp.digicert.com
  • 184.30.131.245
  • 2.23.77.188
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
www.bing.com
  • 2.17.22.48
  • 2.17.22.34
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
www.microsoft.com
  • 92.123.22.101
whitelisted

Threats

No threats detected
No debug info