File name:

1 (1282)

Full analysis: https://app.any.run/tasks/b1849a12-a208-4d48-9136-80e997cc9c11
Verdict: Malicious activity
Analysis date: March 24, 2025, 13:38:39
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections
MD5:

B75FAB393C758D8C0E19900619B39D90

SHA1:

81E26300CFF060437ADBA9043B1215EEC845B778

SHA256:

52FEA37F908EE778D310C22CBDD178352326E4F0E115D194CE530A058392339A

SSDEEP:

3072:cW+3Dth/pDWCVupEDkSNWX4I66HuL+msfpfu4hwRLcBuI6:cW+3DthxDEiYSPI+yzfpfu4hwRLcBuI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 1 (1282).exe (PID: 2136)
      • Unicorn-22247.exe (PID: 976)
      • Unicorn-50591.exe (PID: 960)
      • Unicorn-23503.exe (PID: 7340)
      • Unicorn-56367.exe (PID: 7360)
      • Unicorn-28333.exe (PID: 7376)
      • Unicorn-1753.exe (PID: 2096)
      • Unicorn-2380.exe (PID: 7396)
      • Unicorn-46419.exe (PID: 7436)
      • Unicorn-51847.exe (PID: 7496)
      • Unicorn-60015.exe (PID: 7472)
      • Unicorn-28996.exe (PID: 7520)
      • Unicorn-15453.exe (PID: 7456)
      • Unicorn-22610.exe (PID: 7552)
      • Unicorn-30201.exe (PID: 7824)
      • Unicorn-866.exe (PID: 7796)
      • Unicorn-23132.exe (PID: 7856)
      • Unicorn-37431.exe (PID: 7848)
      • Unicorn-15427.exe (PID: 7904)
      • Unicorn-35293.exe (PID: 7912)
      • Unicorn-57851.exe (PID: 7936)
      • Unicorn-57851.exe (PID: 7944)
      • Unicorn-19948.exe (PID: 8004)
      • Unicorn-43553.exe (PID: 7976)
      • Unicorn-26959.exe (PID: 7540)
      • Unicorn-9013.exe (PID: 8028)
      • Unicorn-27255.exe (PID: 6148)
      • Unicorn-23917.exe (PID: 1228)
      • Unicorn-17123.exe (PID: 4844)
      • Unicorn-7794.exe (PID: 6068)
      • Unicorn-52262.exe (PID: 2040)
      • Unicorn-64779.exe (PID: 1040)
      • Unicorn-15578.exe (PID: 5360)
      • Unicorn-6516.exe (PID: 7768)
      • Unicorn-53679.exe (PID: 7648)
      • Unicorn-37535.exe (PID: 7724)
      • Unicorn-33067.exe (PID: 7740)
      • Unicorn-54234.exe (PID: 7776)
      • Unicorn-45511.exe (PID: 7620)
      • Unicorn-41981.exe (PID: 7884)
      • Unicorn-32875.exe (PID: 5212)
      • Unicorn-10404.exe (PID: 8020)
      • Unicorn-32875.exe (PID: 8172)
      • Unicorn-58126.exe (PID: 1628)
      • Unicorn-53679.exe (PID: 7656)
      • Unicorn-31981.exe (PID: 7488)
      • Unicorn-30664.exe (PID: 732)
      • Unicorn-23461.exe (PID: 7984)
      • Unicorn-62624.exe (PID: 6768)
      • Unicorn-19231.exe (PID: 5640)
      • Unicorn-19231.exe (PID: 1660)
      • Unicorn-45511.exe (PID: 7636)
      • Unicorn-32875.exe (PID: 2108)
      • Unicorn-10404.exe (PID: 8012)
      • Unicorn-23726.exe (PID: 7992)
      • Unicorn-58126.exe (PID: 6540)
      • Unicorn-24598.exe (PID: 7252)
      • Unicorn-36658.exe (PID: 7416)
      • Unicorn-24580.exe (PID: 6512)
      • Unicorn-33954.exe (PID: 7712)
      • Unicorn-29432.exe (PID: 8140)
      • Unicorn-11058.exe (PID: 5400)
      • Unicorn-19973.exe (PID: 4068)
      • Unicorn-46855.exe (PID: 7644)
      • Unicorn-43923.exe (PID: 6676)
      • Unicorn-2073.exe (PID: 8396)
      • Unicorn-63718.exe (PID: 8448)
      • Unicorn-31287.exe (PID: 2420)
      • Unicorn-32560.exe (PID: 8484)
      • Unicorn-31430.exe (PID: 8636)
      • Unicorn-33467.exe (PID: 8656)
      • Unicorn-48150.exe (PID: 8680)
      • Unicorn-48150.exe (PID: 8688)
      • Unicorn-47958.exe (PID: 8596)
      • Unicorn-12454.exe (PID: 2656)
      • Unicorn-3588.exe (PID: 8836)
      • Unicorn-8077.exe (PID: 8912)
      • Unicorn-7693.exe (PID: 9092)
      • Unicorn-15020.exe (PID: 8800)
      • Unicorn-3588.exe (PID: 8828)
      • Unicorn-45026.exe (PID: 9032)
      • Unicorn-29817.exe (PID: 7968)
      • Unicorn-57470.exe (PID: 8948)
      • Unicorn-9731.exe (PID: 9112)
      • Unicorn-19946.exe (PID: 9128)
      • Unicorn-23707.exe (PID: 9068)
      • Unicorn-61170.exe (PID: 8128)
      • Unicorn-53578.exe (PID: 5200)
      • Unicorn-57086.exe (PID: 8476)
      • Unicorn-50433.exe (PID: 5596)
      • Unicorn-51532.exe (PID: 8620)
      • Unicorn-18192.exe (PID: 9196)
      • Unicorn-62624.exe (PID: 1188)
      • Unicorn-44832.exe (PID: 472)
      • Unicorn-37242.exe (PID: 9400)
      • Unicorn-40293.exe (PID: 8380)
      • Unicorn-29458.exe (PID: 8440)
      • Unicorn-49795.exe (PID: 8392)
      • Unicorn-16054.exe (PID: 8300)
      • Unicorn-41435.exe (PID: 6656)
      • Unicorn-45410.exe (PID: 9424)
      • Unicorn-43748.exe (PID: 8520)
      • Unicorn-11651.exe (PID: 9496)
      • Unicorn-43748.exe (PID: 8504)
      • Unicorn-29458.exe (PID: 8456)
      • Unicorn-19375.exe (PID: 8340)
      • Unicorn-5417.exe (PID: 5936)
      • Unicorn-9923.exe (PID: 1196)
      • Unicorn-37242.exe (PID: 9408)
      • Unicorn-37220.exe (PID: 3900)
      • Unicorn-54657.exe (PID: 9560)
      • Unicorn-40293.exe (PID: 8560)
      • Unicorn-24776.exe (PID: 8364)
      • Unicorn-54133.exe (PID: 8968)
      • Unicorn-30034.exe (PID: 9508)
      • Unicorn-32701.exe (PID: 9316)
      • Unicorn-1637.exe (PID: 9608)
      • Unicorn-19905.exe (PID: 9212)
      • Unicorn-7759.exe (PID: 9628)
      • Unicorn-14188.exe (PID: 6324)
      • Unicorn-34672.exe (PID: 9800)
      • Unicorn-676.exe (PID: 9660)
      • Unicorn-59369.exe (PID: 9468)
      • Unicorn-33734.exe (PID: 9776)
      • Unicorn-47309.exe (PID: 9600)
      • Unicorn-54922.exe (PID: 9568)
      • Unicorn-6276.exe (PID: 9668)
      • Unicorn-10796.exe (PID: 8424)
      • Unicorn-1253.exe (PID: 9828)
      • Unicorn-60660.exe (PID: 9820)
      • Unicorn-22228.exe (PID: 9876)
      • Unicorn-45284.exe (PID: 9896)
      • Unicorn-39162.exe (PID: 9940)
      • Unicorn-33734.exe (PID: 9768)
      • Unicorn-42862.exe (PID: 10012)
      • Unicorn-48653.exe (PID: 10032)
      • Unicorn-31570.exe (PID: 10060)
      • Unicorn-27486.exe (PID: 10052)
      • Unicorn-24148.exe (PID: 10164)
      • Unicorn-15425.exe (PID: 10128)
      • Unicorn-43416.exe (PID: 9964)
      • Unicorn-60158.exe (PID: 9024)
      • Unicorn-51228.exe (PID: 8632)
      • Unicorn-60158.exe (PID: 8608)
      • Unicorn-31113.exe (PID: 9988)
      • Unicorn-45773.exe (PID: 8972)
      • Unicorn-27294.exe (PID: 8252)
      • Unicorn-11341.exe (PID: 10120)
      • Unicorn-31932.exe (PID: 10188)
      • Unicorn-27294.exe (PID: 8260)
      • Unicorn-4304.exe (PID: 10256)
      • Unicorn-24724.exe (PID: 10280)
      • Unicorn-1895.exe (PID: 10324)
      • Unicorn-24724.exe (PID: 10288)
      • Unicorn-25247.exe (PID: 8232)
      • Unicorn-28424.exe (PID: 10392)
      • Unicorn-28913.exe (PID: 10576)
      • Unicorn-33816.exe (PID: 10512)
      • Unicorn-12649.exe (PID: 10536)
      • Unicorn-29178.exe (PID: 10568)
      • Unicorn-8736.exe (PID: 10608)
      • Unicorn-3365.exe (PID: 10352)
      • Unicorn-24340.exe (PID: 10380)
      • Unicorn-8373.exe (PID: 10628)
      • Unicorn-59089.exe (PID: 10660)
      • Unicorn-18192.exe (PID: 9188)
      • Unicorn-30012.exe (PID: 4300)
      • Unicorn-49795.exe (PID: 8372)
      • Unicorn-38512.exe (PID: 8356)
      • Unicorn-54922.exe (PID: 9576)
      • Unicorn-5822.exe (PID: 2772)
      • Unicorn-41435.exe (PID: 9204)
      • Unicorn-37242.exe (PID: 9416)
      • Unicorn-30166.exe (PID: 7208)
      • Unicorn-59006.exe (PID: 9584)
      • Unicorn-9015.exe (PID: 10732)
      • Unicorn-39738.exe (PID: 10076)
      • Unicorn-14849.exe (PID: 8268)
      • Unicorn-9909.exe (PID: 10708)
      • Unicorn-39241.exe (PID: 8100)
      • Unicorn-16438.exe (PID: 8992)
      • Unicorn-38460.exe (PID: 10272)
      • Unicorn-63453.exe (PID: 9488)
      • Unicorn-6276.exe (PID: 9676)
      • Unicorn-1637.exe (PID: 9616)
      • Unicorn-38180.exe (PID: 8576)
      • Unicorn-12646.exe (PID: 7784)
      • Unicorn-45511.exe (PID: 7628)
      • Unicorn-4932.exe (PID: 9156)
      • Unicorn-7759.exe (PID: 9644)
      • Unicorn-21569.exe (PID: 8940)
      • Unicorn-13631.exe (PID: 1760)
      • Unicorn-48562.exe (PID: 5260)
      • Unicorn-13505.exe (PID: 9848)
      • Unicorn-42286.exe (PID: 9548)
    • Starts itself from another location

      • Unicorn-22247.exe (PID: 976)
      • Unicorn-50591.exe (PID: 960)
      • 1 (1282).exe (PID: 2136)
      • Unicorn-1753.exe (PID: 2096)
      • Unicorn-56367.exe (PID: 7360)
      • Unicorn-23503.exe (PID: 7340)
      • Unicorn-46419.exe (PID: 7436)
      • Unicorn-28333.exe (PID: 7376)
      • Unicorn-2380.exe (PID: 7396)
      • Unicorn-15453.exe (PID: 7456)
      • Unicorn-51847.exe (PID: 7496)
      • Unicorn-31981.exe (PID: 7488)
      • Unicorn-60015.exe (PID: 7472)
      • Unicorn-22610.exe (PID: 7552)
      • Unicorn-866.exe (PID: 7796)
      • Unicorn-23132.exe (PID: 7856)
      • Unicorn-37431.exe (PID: 7848)
      • Unicorn-15427.exe (PID: 7904)
      • Unicorn-35293.exe (PID: 7912)
      • Unicorn-57851.exe (PID: 7936)
      • Unicorn-10404.exe (PID: 8020)
      • Unicorn-9013.exe (PID: 8028)
      • Unicorn-29817.exe (PID: 7968)
      • Unicorn-10404.exe (PID: 8012)
      • Unicorn-23461.exe (PID: 7984)
      • Unicorn-19948.exe (PID: 8004)
      • Unicorn-23726.exe (PID: 7992)
      • Unicorn-28996.exe (PID: 7520)
      • Unicorn-27255.exe (PID: 6148)
      • Unicorn-23917.exe (PID: 1228)
      • Unicorn-30201.exe (PID: 7824)
      • Unicorn-17123.exe (PID: 4844)
      • Unicorn-43553.exe (PID: 7976)
      • Unicorn-26959.exe (PID: 7540)
      • Unicorn-52262.exe (PID: 2040)
      • Unicorn-37535.exe (PID: 7724)
      • Unicorn-64779.exe (PID: 1040)
      • Unicorn-33067.exe (PID: 7740)
      • Unicorn-54234.exe (PID: 7776)
      • Unicorn-53679.exe (PID: 7648)
      • Unicorn-12646.exe (PID: 7784)
      • Unicorn-6516.exe (PID: 7768)
      • Unicorn-45511.exe (PID: 7620)
      • Unicorn-41981.exe (PID: 7884)
      • Unicorn-32875.exe (PID: 5212)
      • Unicorn-58126.exe (PID: 1628)
      • Unicorn-62624.exe (PID: 6768)
      • Unicorn-62624.exe (PID: 1188)
      • Unicorn-24598.exe (PID: 7252)
      • Unicorn-5417.exe (PID: 5936)
      • Unicorn-19231.exe (PID: 5640)
      • Unicorn-30664.exe (PID: 732)
      • Unicorn-57851.exe (PID: 7944)
      • Unicorn-36658.exe (PID: 7416)
      • Unicorn-45511.exe (PID: 7628)
      • Unicorn-13631.exe (PID: 1760)
      • Unicorn-19231.exe (PID: 1660)
      • Unicorn-32875.exe (PID: 2108)
      • Unicorn-30166.exe (PID: 7208)
      • Unicorn-5822.exe (PID: 2772)
      • Unicorn-29432.exe (PID: 8140)
      • Unicorn-7794.exe (PID: 6068)
      • Unicorn-11058.exe (PID: 5400)
      • Unicorn-48562.exe (PID: 5260)
      • Unicorn-24580.exe (PID: 6512)
      • Unicorn-33954.exe (PID: 7712)
      • Unicorn-2073.exe (PID: 8396)
      • Unicorn-10796.exe (PID: 8424)
      • Unicorn-19973.exe (PID: 4068)
      • Unicorn-31287.exe (PID: 2420)
      • Unicorn-15578.exe (PID: 5360)
      • Unicorn-63718.exe (PID: 8448)
      • Unicorn-47958.exe (PID: 8596)
      • Unicorn-48150.exe (PID: 8680)
      • Unicorn-31430.exe (PID: 8636)
      • Unicorn-33467.exe (PID: 8656)
      • Unicorn-48150.exe (PID: 8688)
      • Unicorn-32560.exe (PID: 8484)
      • Unicorn-3588.exe (PID: 8836)
      • Unicorn-12454.exe (PID: 2656)
      • Unicorn-45773.exe (PID: 8972)
      • Unicorn-16438.exe (PID: 8992)
      • Unicorn-15020.exe (PID: 8800)
      • Unicorn-3588.exe (PID: 8828)
      • Unicorn-58126.exe (PID: 6540)
      • Unicorn-45026.exe (PID: 9032)
      • Unicorn-23707.exe (PID: 9068)
      • Unicorn-53679.exe (PID: 7656)
      • Unicorn-32875.exe (PID: 8172)
      • Unicorn-9731.exe (PID: 9112)
      • Unicorn-53578.exe (PID: 5200)
      • Unicorn-57086.exe (PID: 8476)
      • Unicorn-18192.exe (PID: 9196)
      • Unicorn-18192.exe (PID: 9188)
      • Unicorn-51532.exe (PID: 8620)
      • Unicorn-49795.exe (PID: 8392)
      • Unicorn-44832.exe (PID: 472)
      • Unicorn-16054.exe (PID: 8300)
      • Unicorn-37242.exe (PID: 9400)
      • Unicorn-40293.exe (PID: 8380)
      • Unicorn-30012.exe (PID: 4300)
      • Unicorn-38180.exe (PID: 8576)
      • Unicorn-29458.exe (PID: 8440)
      • Unicorn-43748.exe (PID: 8520)
      • Unicorn-43748.exe (PID: 8504)
      • Unicorn-11651.exe (PID: 9496)
      • Unicorn-45410.exe (PID: 9424)
      • Unicorn-21569.exe (PID: 8940)
      • Unicorn-41435.exe (PID: 6656)
      • Unicorn-29458.exe (PID: 8456)
      • Unicorn-19375.exe (PID: 8340)
      • Unicorn-4932.exe (PID: 9156)
      • Unicorn-49795.exe (PID: 8372)
      • Unicorn-37220.exe (PID: 3900)
      • Unicorn-45511.exe (PID: 7636)
      • Unicorn-9923.exe (PID: 1196)
      • Unicorn-38512.exe (PID: 8356)
      • Unicorn-24776.exe (PID: 8364)
      • Unicorn-54133.exe (PID: 8968)
      • Unicorn-54657.exe (PID: 9560)
      • Unicorn-54922.exe (PID: 9576)
      • Unicorn-40293.exe (PID: 8560)
      • Unicorn-41435.exe (PID: 9204)
      • Unicorn-46855.exe (PID: 7644)
      • Unicorn-19905.exe (PID: 9212)
      • Unicorn-30034.exe (PID: 9508)
      • Unicorn-7759.exe (PID: 9644)
      • Unicorn-37242.exe (PID: 9416)
      • Unicorn-6276.exe (PID: 9676)
      • Unicorn-6276.exe (PID: 9668)
      • Unicorn-13505.exe (PID: 9848)
      • Unicorn-34672.exe (PID: 9800)
      • Unicorn-59369.exe (PID: 9468)
      • Unicorn-676.exe (PID: 9660)
      • Unicorn-43923.exe (PID: 6676)
      • Unicorn-33734.exe (PID: 9776)
      • Unicorn-1637.exe (PID: 9616)
      • Unicorn-60660.exe (PID: 9820)
      • Unicorn-22228.exe (PID: 9876)
      • Unicorn-45284.exe (PID: 9896)
      • Unicorn-33734.exe (PID: 9768)
      • Unicorn-1253.exe (PID: 9828)
      • Unicorn-42862.exe (PID: 10012)
      • Unicorn-48653.exe (PID: 10032)
      • Unicorn-31570.exe (PID: 10060)
      • Unicorn-27486.exe (PID: 10052)
      • Unicorn-39738.exe (PID: 10076)
      • Unicorn-24148.exe (PID: 10164)
      • Unicorn-15425.exe (PID: 10128)
      • Unicorn-39162.exe (PID: 9940)
      • Unicorn-43416.exe (PID: 9964)
      • Unicorn-11341.exe (PID: 10120)
      • Unicorn-51228.exe (PID: 8632)
      • Unicorn-60158.exe (PID: 9024)
      • Unicorn-8077.exe (PID: 8912)
      • Unicorn-31113.exe (PID: 9988)
      • Unicorn-27294.exe (PID: 8252)
      • Unicorn-14849.exe (PID: 8268)
      • Unicorn-25247.exe (PID: 8232)
      • Unicorn-4304.exe (PID: 10256)
      • Unicorn-14188.exe (PID: 6324)
      • Unicorn-38460.exe (PID: 10272)
      • Unicorn-24724.exe (PID: 10288)
      • Unicorn-1895.exe (PID: 10324)
      • Unicorn-19946.exe (PID: 9128)
      • Unicorn-3365.exe (PID: 10352)
      • Unicorn-24340.exe (PID: 10380)
      • Unicorn-28424.exe (PID: 10392)
      • Unicorn-33816.exe (PID: 10512)
      • Unicorn-28913.exe (PID: 10576)
      • Unicorn-29178.exe (PID: 10568)
      • Unicorn-12649.exe (PID: 10536)
      • Unicorn-8373.exe (PID: 10628)
      • Unicorn-50433.exe (PID: 5596)
      • Unicorn-61170.exe (PID: 8128)
      • Unicorn-8851.exe (PID: 9476)
      • Unicorn-8736.exe (PID: 10608)
      • Unicorn-59089.exe (PID: 10660)
      • Unicorn-63453.exe (PID: 9488)
      • Unicorn-37242.exe (PID: 9408)
      • Unicorn-39241.exe (PID: 8100)
      • Unicorn-47309.exe (PID: 9600)
      • Unicorn-31932.exe (PID: 10188)
      • Unicorn-7759.exe (PID: 9628)
      • Unicorn-60158.exe (PID: 8608)
    • Executes application which crashes

      • Unicorn-65254.exe (PID: 8220)
      • Unicorn-293.exe (PID: 4988)
  • INFO

    • The sample compiled with chinese language support

      • 1 (1282).exe (PID: 2136)
      • Unicorn-57851.exe (PID: 7944)
      • Unicorn-12454.exe (PID: 2656)
      • Unicorn-38512.exe (PID: 8356)
      • Unicorn-60158.exe (PID: 9024)
      • Unicorn-41435.exe (PID: 9204)
      • Unicorn-14188.exe (PID: 6324)
      • Unicorn-12646.exe (PID: 7784)
      • Unicorn-7759.exe (PID: 9644)
      • Unicorn-27294.exe (PID: 8252)
      • Unicorn-60015.exe (PID: 7472)
      • Unicorn-38460.exe (PID: 10272)
      • Unicorn-29817.exe (PID: 7968)
      • Unicorn-27294.exe (PID: 8260)
      • Unicorn-53679.exe (PID: 7656)
      • Unicorn-4304.exe (PID: 10256)
      • Unicorn-9013.exe (PID: 8028)
      • Unicorn-28333.exe (PID: 7376)
      • Unicorn-24724.exe (PID: 10280)
      • Unicorn-31113.exe (PID: 9988)
      • Unicorn-25247.exe (PID: 8232)
      • Unicorn-9731.exe (PID: 9112)
      • Unicorn-45511.exe (PID: 7620)
      • Unicorn-31287.exe (PID: 2420)
      • Unicorn-24340.exe (PID: 10380)
      • Unicorn-51847.exe (PID: 7496)
      • Unicorn-32875.exe (PID: 5212)
      • Unicorn-3365.exe (PID: 10352)
      • Unicorn-19946.exe (PID: 9128)
      • Unicorn-58126.exe (PID: 1628)
      • Unicorn-45773.exe (PID: 8972)
      • Unicorn-19231.exe (PID: 1660)
      • Unicorn-28424.exe (PID: 10392)
      • Unicorn-23707.exe (PID: 9068)
      • Unicorn-33816.exe (PID: 10512)
      • Unicorn-57470.exe (PID: 8948)
      • Unicorn-41981.exe (PID: 7884)
      • Unicorn-1895.exe (PID: 10324)
      • Unicorn-24724.exe (PID: 10288)
      • Unicorn-45026.exe (PID: 9032)
      • Unicorn-29178.exe (PID: 10568)
      • Unicorn-43923.exe (PID: 6676)
      • Unicorn-45284.exe (PID: 9896)
      • Unicorn-18192.exe (PID: 9196)
      • Unicorn-16438.exe (PID: 8992)
      • Unicorn-59089.exe (PID: 10660)
      • Unicorn-53578.exe (PID: 5200)
      • Unicorn-62624.exe (PID: 1188)
      • Unicorn-57086.exe (PID: 8476)
      • Unicorn-18192.exe (PID: 9188)
      • Unicorn-49795.exe (PID: 8392)
      • Unicorn-51532.exe (PID: 8620)
      • Unicorn-16054.exe (PID: 8300)
      • Unicorn-12649.exe (PID: 10536)
      • Unicorn-10404.exe (PID: 8020)
      • Unicorn-8736.exe (PID: 10608)
      • Unicorn-8373.exe (PID: 10628)
      • Unicorn-22610.exe (PID: 7552)
      • Unicorn-37242.exe (PID: 9400)
      • Unicorn-23726.exe (PID: 7992)
      • Unicorn-62624.exe (PID: 6768)
      • Unicorn-1753.exe (PID: 2096)
      • Unicorn-11651.exe (PID: 9496)
      • Unicorn-28913.exe (PID: 10576)
      • Unicorn-26959.exe (PID: 7540)
      • Unicorn-50591.exe (PID: 960)
      • Unicorn-32875.exe (PID: 2108)
      • Unicorn-13631.exe (PID: 1760)
      • Unicorn-30664.exe (PID: 732)
      • Unicorn-24598.exe (PID: 7252)
      • Unicorn-22247.exe (PID: 976)
      • Unicorn-29458.exe (PID: 8456)
      • Unicorn-19375.exe (PID: 8340)
      • Unicorn-27255.exe (PID: 6148)
      • Unicorn-28996.exe (PID: 7520)
      • Unicorn-40293.exe (PID: 8560)
      • Unicorn-9923.exe (PID: 1196)
      • Unicorn-46419.exe (PID: 7436)
      • Unicorn-54133.exe (PID: 8968)
      • Unicorn-48562.exe (PID: 5260)
      • Unicorn-7794.exe (PID: 6068)
      • Unicorn-15453.exe (PID: 7456)
      • Unicorn-23503.exe (PID: 7340)
      • Unicorn-30201.exe (PID: 7824)
      • Unicorn-37242.exe (PID: 9416)
      • Unicorn-24580.exe (PID: 6512)
      • Unicorn-866.exe (PID: 7796)
      • Unicorn-10404.exe (PID: 8012)
      • Unicorn-23461.exe (PID: 7984)
      • Unicorn-13505.exe (PID: 9848)
      • Unicorn-59369.exe (PID: 9468)
      • Unicorn-33954.exe (PID: 7712)
      • Unicorn-29432.exe (PID: 8140)
      • Unicorn-2380.exe (PID: 7396)
      • Unicorn-1637.exe (PID: 9616)
      • Unicorn-39241.exe (PID: 8100)
      • Unicorn-59006.exe (PID: 9584)
      • Unicorn-5822.exe (PID: 2772)
      • Unicorn-64779.exe (PID: 1040)
      • Unicorn-9909.exe (PID: 10708)
      • Unicorn-54657.exe (PID: 9560)
      • Unicorn-52262.exe (PID: 2040)
      • Unicorn-42862.exe (PID: 10012)
      • Unicorn-43416.exe (PID: 9964)
      • Unicorn-35293.exe (PID: 7912)
      • Unicorn-42286.exe (PID: 9548)
      • Unicorn-23132.exe (PID: 7856)
      • Unicorn-47958.exe (PID: 8596)
      • Unicorn-27486.exe (PID: 10052)
      • Unicorn-32560.exe (PID: 8484)
      • Unicorn-37535.exe (PID: 7724)
      • Unicorn-48653.exe (PID: 10032)
      • Unicorn-39738.exe (PID: 10076)
      • Unicorn-22228.exe (PID: 9876)
      • Unicorn-3588.exe (PID: 8828)
      • Unicorn-29458.exe (PID: 8440)
      • Unicorn-15425.exe (PID: 10128)
      • Unicorn-3588.exe (PID: 8836)
      • Unicorn-6516.exe (PID: 7768)
      • Unicorn-31932.exe (PID: 10188)
      • Unicorn-51228.exe (PID: 8632)
      • Unicorn-2073.exe (PID: 8396)
      • Unicorn-39162.exe (PID: 9940)
      • Unicorn-9015.exe (PID: 10732)
      • Unicorn-31430.exe (PID: 8636)
      • Unicorn-43748.exe (PID: 8504)
      • Unicorn-8077.exe (PID: 8912)
      • Unicorn-46855.exe (PID: 7644)
      • Unicorn-56367.exe (PID: 7360)
      • Unicorn-32701.exe (PID: 9316)
      • Unicorn-57851.exe (PID: 7936)
      • Unicorn-31981.exe (PID: 7488)
      • Unicorn-60660.exe (PID: 9820)
      • Unicorn-30166.exe (PID: 7208)
      • Unicorn-40293.exe (PID: 8380)
      • Unicorn-41435.exe (PID: 6656)
      • Unicorn-37242.exe (PID: 9408)
      • Unicorn-36658.exe (PID: 7416)
      • Unicorn-21569.exe (PID: 8940)
      • Unicorn-4932.exe (PID: 9156)
      • Unicorn-24776.exe (PID: 8364)
      • Unicorn-43553.exe (PID: 7976)
      • Unicorn-47309.exe (PID: 9600)
      • Unicorn-37431.exe (PID: 7848)
      • Unicorn-45511.exe (PID: 7628)
      • Unicorn-11341.exe (PID: 10120)
      • Unicorn-33067.exe (PID: 7740)
      • Unicorn-34672.exe (PID: 9800)
      • Unicorn-31570.exe (PID: 10060)
      • Unicorn-15427.exe (PID: 7904)
      • Unicorn-33467.exe (PID: 8656)
      • Unicorn-49795.exe (PID: 8372)
      • Unicorn-48150.exe (PID: 8688)
      • Unicorn-30012.exe (PID: 4300)
      • Unicorn-45511.exe (PID: 7636)
      • Unicorn-23917.exe (PID: 1228)
      • Unicorn-17123.exe (PID: 4844)
      • Unicorn-11058.exe (PID: 5400)
      • Unicorn-15578.exe (PID: 5360)
      • Unicorn-6276.exe (PID: 9668)
      • Unicorn-60158.exe (PID: 8608)
      • Unicorn-15020.exe (PID: 8800)
      • Unicorn-7693.exe (PID: 9092)
      • Unicorn-32875.exe (PID: 8172)
      • Unicorn-58126.exe (PID: 6540)
      • Unicorn-48150.exe (PID: 8680)
      • Unicorn-6276.exe (PID: 9676)
    • Reads the computer name

      • Unicorn-22247.exe (PID: 976)
      • Unicorn-50591.exe (PID: 960)
      • 1 (1282).exe (PID: 2136)
      • Unicorn-1753.exe (PID: 2096)
      • Unicorn-23503.exe (PID: 7340)
      • Unicorn-2380.exe (PID: 7396)
      • Unicorn-56367.exe (PID: 7360)
      • Unicorn-46419.exe (PID: 7436)
      • Unicorn-15453.exe (PID: 7456)
      • Unicorn-31981.exe (PID: 7488)
      • Unicorn-28996.exe (PID: 7520)
      • Unicorn-26959.exe (PID: 7540)
      • Unicorn-22610.exe (PID: 7552)
      • Unicorn-51847.exe (PID: 7496)
      • Unicorn-866.exe (PID: 7796)
      • Unicorn-23132.exe (PID: 7856)
      • Unicorn-29817.exe (PID: 7968)
      • Unicorn-57851.exe (PID: 7944)
      • Unicorn-9013.exe (PID: 8028)
      • Unicorn-10404.exe (PID: 8020)
      • Unicorn-10404.exe (PID: 8012)
      • Unicorn-23461.exe (PID: 7984)
      • Unicorn-17123.exe (PID: 4844)
      • Unicorn-15578.exe (PID: 5360)
      • Unicorn-64779.exe (PID: 1040)
      • Unicorn-53679.exe (PID: 7656)
      • Unicorn-62624.exe (PID: 1188)
      • Unicorn-45511.exe (PID: 7620)
      • Unicorn-30664.exe (PID: 732)
      • Unicorn-45511.exe (PID: 7636)
      • Unicorn-36658.exe (PID: 7416)
      • Unicorn-31287.exe (PID: 2420)
      • Unicorn-10796.exe (PID: 8424)
      • Unicorn-31430.exe (PID: 8636)
      • Unicorn-29458.exe (PID: 8456)
      • Unicorn-63453.exe (PID: 9488)
      • Unicorn-33734.exe (PID: 9776)
      • Unicorn-24724.exe (PID: 10280)
      • Unicorn-29178.exe (PID: 10568)
      • Unicorn-8373.exe (PID: 10628)
    • Checks supported languages

      • 1 (1282).exe (PID: 2136)
      • Unicorn-22247.exe (PID: 976)
      • Unicorn-50591.exe (PID: 960)
      • Unicorn-1753.exe (PID: 2096)
      • Unicorn-23503.exe (PID: 7340)
      • Unicorn-28333.exe (PID: 7376)
      • Unicorn-46419.exe (PID: 7436)
      • Unicorn-15453.exe (PID: 7456)
      • Unicorn-60015.exe (PID: 7472)
      • Unicorn-56367.exe (PID: 7360)
      • Unicorn-2380.exe (PID: 7396)
      • Unicorn-28996.exe (PID: 7520)
      • Unicorn-22610.exe (PID: 7552)
      • Unicorn-26959.exe (PID: 7540)
      • Unicorn-866.exe (PID: 7796)
      • Unicorn-31981.exe (PID: 7488)
      • Unicorn-30201.exe (PID: 7824)
      • Unicorn-23132.exe (PID: 7856)
      • Unicorn-35293.exe (PID: 7912)
      • Unicorn-15427.exe (PID: 7904)
      • Unicorn-57851.exe (PID: 7936)
      • Unicorn-37431.exe (PID: 7848)
      • Unicorn-43553.exe (PID: 7976)
      • Unicorn-23461.exe (PID: 7984)
      • Unicorn-9013.exe (PID: 8028)
      • Unicorn-10404.exe (PID: 8020)
      • Unicorn-19948.exe (PID: 8004)
      • Unicorn-10404.exe (PID: 8012)
      • Unicorn-57851.exe (PID: 7944)
      • Unicorn-29817.exe (PID: 7968)
      • Unicorn-23726.exe (PID: 7992)
      • Unicorn-7794.exe (PID: 6068)
      • Unicorn-17123.exe (PID: 4844)
      • Unicorn-52262.exe (PID: 2040)
      • Unicorn-41981.exe (PID: 7884)
      • Unicorn-32875.exe (PID: 5212)
      • Unicorn-45511.exe (PID: 7636)
      • Unicorn-32875.exe (PID: 8172)
      • Unicorn-5822.exe (PID: 2772)
      • Unicorn-5417.exe (PID: 5936)
      • Unicorn-46855.exe (PID: 7644)
      • Unicorn-62624.exe (PID: 1188)
      • Unicorn-62624.exe (PID: 6768)
      • Unicorn-11058.exe (PID: 5400)
      • Unicorn-14188.exe (PID: 6324)
      • Unicorn-10796.exe (PID: 8424)
      • Unicorn-47958.exe (PID: 8596)
      • Unicorn-31430.exe (PID: 8636)
      • Unicorn-48150.exe (PID: 8680)
      • Unicorn-7693.exe (PID: 9092)
      • Unicorn-29458.exe (PID: 8440)
      • Unicorn-8851.exe (PID: 9476)
      • Unicorn-7759.exe (PID: 9644)
      • Unicorn-42286.exe (PID: 9548)
      • Unicorn-7759.exe (PID: 9628)
      • Unicorn-33734.exe (PID: 9776)
      • Unicorn-1253.exe (PID: 9828)
      • Unicorn-60660.exe (PID: 9820)
      • Unicorn-25247.exe (PID: 8232)
      • Unicorn-9015.exe (PID: 10732)
      • Unicorn-8736.exe (PID: 10608)
      • Unicorn-33816.exe (PID: 10512)
      • Unicorn-18758.exe (PID: 2064)
      • Unicorn-26542.exe (PID: 11460)
      • Unicorn-51430.exe (PID: 11536)
      • Unicorn-35094.exe (PID: 11504)
      • Unicorn-10397.exe (PID: 11636)
      • Unicorn-30818.exe (PID: 11792)
      • Unicorn-16188.exe (PID: 11776)
      • Unicorn-46003.exe (PID: 11628)
      • Unicorn-10397.exe (PID: 11668)
      • Unicorn-21563.exe (PID: 12060)
      • Unicorn-64237.exe (PID: 11676)
      • Unicorn-62596.exe (PID: 11920)
      • Unicorn-11357.exe (PID: 11968)
      • Unicorn-62596.exe (PID: 11912)
      • Unicorn-3381.exe (PID: 11500)
      • Unicorn-23972.exe (PID: 12340)
      • Unicorn-31129.exe (PID: 12644)
      • Unicorn-23972.exe (PID: 12324)
      • Unicorn-64258.exe (PID: 12448)
      • Unicorn-60174.exe (PID: 12528)
      • Unicorn-3381.exe (PID: 12196)
      • Unicorn-11165.exe (PID: 12760)
      • Unicorn-15249.exe (PID: 12796)
      • Unicorn-37568.exe (PID: 13116)
      • Unicorn-20220.exe (PID: 13188)
      • Unicorn-4149.exe (PID: 13180)
      • Unicorn-60921.exe (PID: 12832)
      • Unicorn-24378.exe (PID: 13092)
      • Unicorn-47988.exe (PID: 13520)
      • Unicorn-4917.exe (PID: 13584)
      • Unicorn-57818.exe (PID: 13700)
      • Unicorn-18108.exe (PID: 13864)
      • Unicorn-20683.exe (PID: 13976)
      • Unicorn-51378.exe (PID: 14136)
      • Unicorn-54030.exe (PID: 14700)
      • Unicorn-50972.exe (PID: 7244)
      • Unicorn-53957.exe (PID: 6388)
      • Unicorn-8456.exe (PID: 2244)
      • Unicorn-42664.exe (PID: 15652)
      • Unicorn-26328.exe (PID: 15624)
      • Unicorn-47656.exe (PID: 15852)
      • Unicorn-49470.exe (PID: 15888)
      • Unicorn-3823.exe (PID: 15956)
      • Unicorn-48359.exe (PID: 15996)
      • Unicorn-47656.exe (PID: 15816)
      • Unicorn-28711.exe (PID: 16188)
      • Unicorn-58425.exe (PID: 15980)
      • Unicorn-14652.exe (PID: 16468)
      • Unicorn-6623.exe (PID: 15944)
      • Unicorn-16764.exe (PID: 16440)
      • Unicorn-61252.exe (PID: 16852)
      • Unicorn-43432.exe (PID: 16804)
      • Unicorn-59193.exe (PID: 17136)
      • Unicorn-59193.exe (PID: 17128)
      • Unicorn-56033.exe (PID: 17748)
      • Unicorn-54898.exe (PID: 16828)
      • Unicorn-59873.exe (PID: 18044)
      • Unicorn-40272.exe (PID: 18052)
      • Unicorn-46032.exe (PID: 18180)
    • Create files in a temporary directory

      • 1 (1282).exe (PID: 2136)
      • Unicorn-22247.exe (PID: 976)
      • Unicorn-23503.exe (PID: 7340)
      • Unicorn-50591.exe (PID: 960)
      • Unicorn-1753.exe (PID: 2096)
      • Unicorn-2380.exe (PID: 7396)
      • Unicorn-46419.exe (PID: 7436)
      • Unicorn-15453.exe (PID: 7456)
      • Unicorn-60015.exe (PID: 7472)
      • Unicorn-28996.exe (PID: 7520)
      • Unicorn-866.exe (PID: 7796)
      • Unicorn-37431.exe (PID: 7848)
      • Unicorn-35293.exe (PID: 7912)
      • Unicorn-15427.exe (PID: 7904)
      • Unicorn-9013.exe (PID: 8028)
      • Unicorn-57851.exe (PID: 7944)
      • Unicorn-27255.exe (PID: 6148)
      • Unicorn-30201.exe (PID: 7824)
      • Unicorn-52262.exe (PID: 2040)
      • Unicorn-37535.exe (PID: 7724)
      • Unicorn-33067.exe (PID: 7740)
      • Unicorn-53679.exe (PID: 7648)
      • Unicorn-56367.exe (PID: 7360)
      • Unicorn-32875.exe (PID: 5212)
      • Unicorn-10404.exe (PID: 8020)
      • Unicorn-51847.exe (PID: 7496)
      • Unicorn-30664.exe (PID: 732)
      • Unicorn-23461.exe (PID: 7984)
      • Unicorn-57851.exe (PID: 7936)
      • Unicorn-31981.exe (PID: 7488)
      • Unicorn-19948.exe (PID: 8004)
      • Unicorn-19231.exe (PID: 5640)
      • Unicorn-32875.exe (PID: 2108)
      • Unicorn-24598.exe (PID: 7252)
      • Unicorn-24580.exe (PID: 6512)
      • Unicorn-7794.exe (PID: 6068)
      • Unicorn-29432.exe (PID: 8140)
      • Unicorn-23917.exe (PID: 1228)
      • Unicorn-15578.exe (PID: 5360)
      • Unicorn-47958.exe (PID: 8596)
      • Unicorn-31430.exe (PID: 8636)
      • Unicorn-48150.exe (PID: 8680)
      • Unicorn-12454.exe (PID: 2656)
      • Unicorn-57086.exe (PID: 8476)
      • Unicorn-62624.exe (PID: 6768)
      • Unicorn-43748.exe (PID: 8504)
      • Unicorn-22610.exe (PID: 7552)
      • Unicorn-28333.exe (PID: 7376)
      • Unicorn-23726.exe (PID: 7992)
      • Unicorn-24776.exe (PID: 8364)
      • Unicorn-45284.exe (PID: 9896)
      • Unicorn-24148.exe (PID: 10164)
      • Unicorn-3588.exe (PID: 8828)
      • Unicorn-25247.exe (PID: 8232)
      • Unicorn-27294.exe (PID: 8260)
      • Unicorn-45026.exe (PID: 9032)
      • Unicorn-12649.exe (PID: 10536)
      • Unicorn-58126.exe (PID: 1628)
      • Unicorn-18192.exe (PID: 9188)
      • Unicorn-43416.exe (PID: 9964)
      • Unicorn-29458.exe (PID: 8440)
      • Unicorn-15020.exe (PID: 8800)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 7636)
      • BackgroundTransferHost.exe (PID: 8112)
      • BackgroundTransferHost.exe (PID: 7316)
    • Checks proxy server information

      • BackgroundTransferHost.exe (PID: 8112)
    • Reads the software policy settings

      • BackgroundTransferHost.exe (PID: 8112)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 8112)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:04:26 10:28:09+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, [6], Bytes reversed lo, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 176128
InitializedDataSize: 8192
UninitializedDataSize: -
EntryPoint: 0x13b0
OSVersion: 4
ImageVersion: 1
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: aaaa
ProductName: Kawaii-Unicorn
FileVersion: 1
ProductVersion: 1
InternalName: Kawaii-Unicorn
OriginalFileName: Kawaii-Unicorn.exe
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
694
Monitored processes
556
Malicious processes
74
Suspicious processes
72

Behavior graph

Click at the process to see the details
start 1 (1282).exe sppextcomobj.exe no specs slui.exe no specs unicorn-22247.exe unicorn-50591.exe unicorn-1753.exe unicorn-23503.exe unicorn-56367.exe unicorn-28333.exe unicorn-2380.exe unicorn-46419.exe unicorn-15453.exe unicorn-60015.exe unicorn-31981.exe unicorn-51847.exe unicorn-28996.exe unicorn-26959.exe unicorn-22610.exe backgroundtransferhost.exe no specs unicorn-866.exe unicorn-30201.exe unicorn-37431.exe unicorn-23132.exe unicorn-15427.exe unicorn-35293.exe unicorn-57851.exe unicorn-57851.exe unicorn-29817.exe unicorn-43553.exe unicorn-23461.exe unicorn-23726.exe unicorn-19948.exe unicorn-10404.exe unicorn-10404.exe unicorn-9013.exe backgroundtransferhost.exe unicorn-27255.exe unicorn-23917.exe unicorn-7794.exe unicorn-17123.exe backgroundtransferhost.exe no specs unicorn-15578.exe unicorn-64779.exe unicorn-52262.exe unicorn-32661.exe no specs unicorn-37535.exe unicorn-33067.exe unicorn-6516.exe unicorn-54234.exe unicorn-12646.exe unicorn-41981.exe unicorn-53679.exe unicorn-53679.exe unicorn-45511.exe unicorn-45511.exe unicorn-45511.exe unicorn-32875.exe unicorn-32875.exe unicorn-32875.exe unicorn-62624.exe unicorn-62624.exe unicorn-58126.exe unicorn-12454.exe unicorn-58126.exe unicorn-13631.exe unicorn-19231.exe unicorn-19231.exe unicorn-30664.exe unicorn-30166.exe unicorn-24598.exe unicorn-5417.exe unicorn-36658.exe unicorn-24580.exe unicorn-5822.exe unicorn-39241.exe unicorn-46855.exe unicorn-33954.exe backgroundtransferhost.exe no specs unicorn-29432.exe unicorn-11058.exe unicorn-48562.exe unicorn-43923.exe unicorn-19973.exe unicorn-31287.exe unicorn-14188.exe unicorn-2073.exe unicorn-10796.exe unicorn-63718.exe unicorn-32560.exe unicorn-47958.exe unicorn-31430.exe unicorn-33467.exe unicorn-48150.exe unicorn-48150.exe backgroundtransferhost.exe no specs unicorn-15020.exe unicorn-3588.exe unicorn-3588.exe unicorn-8077.exe unicorn-57470.exe unicorn-45773.exe unicorn-16438.exe unicorn-45026.exe unicorn-23707.exe unicorn-7693.exe unicorn-9731.exe unicorn-19946.exe unicorn-18192.exe unicorn-18192.exe unicorn-41435.exe unicorn-65254.exe unicorn-19905.exe unicorn-16054.exe unicorn-19375.exe unicorn-38512.exe unicorn-24776.exe unicorn-49795.exe unicorn-40293.exe unicorn-49795.exe unicorn-29458.exe unicorn-29458.exe unicorn-57086.exe unicorn-43748.exe unicorn-43748.exe unicorn-37220.exe unicorn-41435.exe unicorn-40293.exe unicorn-30012.exe unicorn-9923.exe unicorn-38180.exe unicorn-50433.exe unicorn-44832.exe unicorn-53578.exe unicorn-61170.exe unicorn-51532.exe unicorn-293.exe unicorn-21569.exe unicorn-54133.exe unicorn-4932.exe unicorn-32701.exe unicorn-37242.exe unicorn-37242.exe unicorn-37242.exe unicorn-45410.exe unicorn-59369.exe unicorn-8851.exe no specs unicorn-63453.exe unicorn-11651.exe unicorn-30034.exe unicorn-42286.exe unicorn-54657.exe unicorn-54922.exe unicorn-54922.exe unicorn-59006.exe unicorn-47309.exe unicorn-1637.exe unicorn-1637.exe unicorn-7759.exe unicorn-7759.exe unicorn-676.exe unicorn-6276.exe unicorn-6276.exe unicorn-33734.exe unicorn-33734.exe unicorn-34672.exe unicorn-60660.exe unicorn-1253.exe unicorn-13505.exe unicorn-22228.exe unicorn-45284.exe unicorn-39162.exe unicorn-43416.exe unicorn-42862.exe unicorn-48653.exe unicorn-27486.exe unicorn-31570.exe unicorn-39738.exe unicorn-11341.exe unicorn-15425.exe unicorn-24148.exe unicorn-31932.exe unicorn-14849.exe unicorn-51228.exe unicorn-60158.exe unicorn-60158.exe unicorn-27294.exe unicorn-27294.exe unicorn-25247.exe unicorn-31113.exe unicorn-4304.exe unicorn-38460.exe unicorn-24724.exe unicorn-24724.exe unicorn-1895.exe unicorn-3365.exe unicorn-24340.exe unicorn-28424.exe unicorn-33816.exe unicorn-12649.exe unicorn-29178.exe unicorn-28913.exe unicorn-8736.exe unicorn-8373.exe unicorn-59089.exe unicorn-9909.exe unicorn-9015.exe werfault.exe no specs unicorn-5389.exe no specs unicorn-31756.exe no specs unicorn-10589.exe no specs unicorn-18758.exe no specs unicorn-18758.exe no specs unicorn-22842.exe no specs unicorn-6697.exe no specs unicorn-23034.exe no specs unicorn-43070.exe no specs unicorn-43070.exe no specs unicorn-51238.exe no specs unicorn-55322.exe no specs unicorn-59406.exe no specs unicorn-59961.exe no specs unicorn-26542.exe no specs unicorn-26542.exe no specs unicorn-35094.exe no specs unicorn-35094.exe no specs unicorn-43262.exe no specs unicorn-47346.exe no specs unicorn-51430.exe no specs unicorn-55514.exe no specs werfault.exe no specs unicorn-46003.exe no specs unicorn-10397.exe no specs unicorn-14481.exe no specs unicorn-60153.exe no specs unicorn-10397.exe no specs unicorn-64237.exe no specs unicorn-64237.exe no specs unicorn-64237.exe no specs unicorn-18566.exe no specs unicorn-6868.exe no specs unicorn-30818.exe no specs unicorn-18566.exe no specs unicorn-10588.exe no specs unicorn-20272.exe no specs unicorn-40138.exe no specs unicorn-16188.exe no specs unicorn-30818.exe no specs unicorn-16188.exe no specs unicorn-35789.exe no specs unicorn-35789.exe no specs unicorn-56242.exe no specs unicorn-44777.exe no specs unicorn-58512.exe no specs unicorn-58512.exe no specs unicorn-62596.exe no specs unicorn-62596.exe no specs unicorn-55712.exe no specs unicorn-48861.exe no specs unicorn-11092.exe no specs unicorn-11092.exe no specs unicorn-11092.exe no specs unicorn-11357.exe no specs unicorn-5227.exe no specs unicorn-57029.exe no specs unicorn-57029.exe no specs unicorn-21563.exe no specs unicorn-11357.exe no specs unicorn-3189.exe no specs unicorn-5227.exe no specs unicorn-40330.exe no specs unicorn-42368.exe no specs unicorn-2427.exe no specs unicorn-3381.exe no specs unicorn-15634.exe no specs unicorn-40330.exe no specs unicorn-3381.exe no specs unicorn-3381.exe no specs unicorn-23972.exe no specs unicorn-23972.exe no specs unicorn-23972.exe no specs unicorn-43838.exe no specs unicorn-43838.exe no specs unicorn-47922.exe no specs unicorn-2619.exe no specs unicorn-60174.exe no specs unicorn-64258.exe no specs unicorn-64258.exe no specs unicorn-60174.exe no specs unicorn-2805.exe no specs unicorn-59213.exe no specs unicorn-13011.exe no specs unicorn-23972.exe no specs unicorn-31129.exe no specs unicorn-25263.exe no specs unicorn-24164.exe no specs unicorn-40500.exe no specs unicorn-40500.exe no specs unicorn-48669.exe no specs unicorn-59604.exe no specs unicorn-2997.exe no specs unicorn-2997.exe no specs unicorn-56837.exe no specs unicorn-11165.exe no specs unicorn-23153.exe no specs unicorn-19101.exe no specs unicorn-15249.exe no specs unicorn-15249.exe no specs unicorn-23418.exe no specs unicorn-27502.exe no specs unicorn-60921.exe no specs unicorn-23418.exe no specs unicorn-9119.exe no specs unicorn-15249.exe no specs unicorn-44725.exe no specs unicorn-38860.exe no specs unicorn-36822.exe no specs unicorn-25455.exe no specs unicorn-65410.exe no specs unicorn-24378.exe no specs unicorn-37568.exe no specs unicorn-37568.exe no specs unicorn-57434.exe no specs unicorn-63556.exe no specs unicorn-49821.exe no specs unicorn-4149.exe no specs unicorn-20220.exe no specs unicorn-620.exe no specs unicorn-20486.exe no specs unicorn-36438.exe no specs unicorn-60677.exe no specs unicorn-54812.exe no specs unicorn-36630.exe no specs unicorn-65218.exe no specs unicorn-236.exe no specs unicorn-32354.exe no specs unicorn-53926.exe no specs unicorn-55964.exe no specs unicorn-4725.exe no specs unicorn-41866.exe no specs unicorn-41866.exe no specs unicorn-47988.exe no specs unicorn-54118.exe no specs unicorn-50589.exe no specs unicorn-4917.exe no specs unicorn-45374.exe no specs unicorn-45374.exe no specs unicorn-45929.exe no specs unicorn-13064.exe no specs unicorn-13064.exe no specs unicorn-57818.exe no specs unicorn-46121.exe no specs unicorn-63940.exe no specs unicorn-449.exe no specs unicorn-26660.exe no specs unicorn-34828.exe no specs unicorn-11615.exe no specs unicorn-63054.exe no specs unicorn-17938.exe no specs unicorn-18108.exe no specs unicorn-12508.exe no specs unicorn-42612.exe no specs unicorn-1025.exe no specs unicorn-50781.exe no specs unicorn-50781.exe no specs unicorn-25530.exe no specs unicorn-29349.exe no specs unicorn-20683.exe no specs unicorn-33698.exe no specs unicorn-11423.exe no specs unicorn-17554.exe no specs unicorn-17554.exe no specs unicorn-23675.exe no specs unicorn-29541.exe no specs unicorn-23675.exe no specs unicorn-27759.exe no specs unicorn-51378.exe no specs unicorn-59281.exe no specs unicorn-2177.exe no specs unicorn-35788.exe no specs unicorn-24827.exe no specs unicorn-24827.exe no specs unicorn-24251.exe no specs unicorn-31320.exe no specs unicorn-55270.exe no specs unicorn-14237.exe no specs unicorn-48617.exe no specs unicorn-59552.exe no specs unicorn-62544.exe no specs unicorn-23728.exe no specs unicorn-41740.exe no specs unicorn-31342.exe no specs unicorn-27834.exe no specs unicorn-11689.exe no specs unicorn-1108.exe no specs unicorn-57346.exe no specs unicorn-20324.exe no specs unicorn-54030.exe no specs unicorn-5021.exe no specs unicorn-14149.exe no specs unicorn-55950.exe no specs unicorn-64118.exe no specs unicorn-27362.exe no specs unicorn-53957.exe no specs unicorn-50972.exe no specs unicorn-288.exe no specs unicorn-8456.exe no specs unicorn-8456.exe no specs unicorn-8456.exe no specs unicorn-8648.exe no specs unicorn-30220.exe no specs unicorn-42472.exe no specs unicorn-46557.exe no specs unicorn-58809.exe no specs unicorn-27811.exe no specs unicorn-26328.exe no specs unicorn-26328.exe no specs unicorn-42664.exe no specs unicorn-42664.exe no specs unicorn-50833.exe no specs unicorn-50833.exe no specs unicorn-50833.exe no specs unicorn-1632.exe no specs unicorn-2184.exe no specs unicorn-17584.exe no specs unicorn-29836.exe no specs unicorn-47656.exe no specs unicorn-47656.exe no specs unicorn-47656.exe no specs unicorn-47656.exe no specs unicorn-47656.exe no specs unicorn-33920.exe no specs unicorn-49470.exe no specs unicorn-6623.exe no specs unicorn-3823.exe no specs unicorn-58425.exe no specs unicorn-11991.exe no specs unicorn-58425.exe no specs unicorn-58425.exe no specs unicorn-48359.exe no specs unicorn-20656.exe no specs unicorn-6623.exe no specs unicorn-6623.exe no specs unicorn-37377.exe no specs unicorn-17776.exe no specs unicorn-14791.exe no specs unicorn-28711.exe no specs unicorn-28711.exe no specs unicorn-12176.exe no specs unicorn-56016.exe no specs unicorn-428.exe no specs unicorn-428.exe no specs unicorn-60100.exe no specs unicorn-60100.exe no specs unicorn-46365.exe no specs unicorn-12680.exe no specs unicorn-16764.exe no specs unicorn-16267.exe no specs unicorn-14652.exe no specs unicorn-30988.exe no specs unicorn-18736.exe no specs unicorn-29472.exe no specs unicorn-37640.exe no specs unicorn-35072.exe no specs unicorn-54673.exe no specs unicorn-43240.exe no specs unicorn-43240.exe no specs unicorn-56976.exe no specs unicorn-56976.exe no specs unicorn-43240.exe no specs unicorn-11859.exe no specs unicorn-27096.exe no specs unicorn-27096.exe no specs unicorn-63033.exe no specs unicorn-43432.exe no specs unicorn-43432.exe no specs unicorn-43432.exe no specs unicorn-54898.exe no specs unicorn-63298.exe no specs unicorn-61252.exe no specs unicorn-5167.exe no specs unicorn-13832.exe no specs unicorn-24303.exe no specs unicorn-36172.exe no specs unicorn-36172.exe no specs unicorn-36172.exe no specs unicorn-41540.exe no specs unicorn-30604.exe no specs unicorn-38325.exe no specs unicorn-32791.exe no specs unicorn-13256.exe no specs unicorn-59193.exe no specs unicorn-7391.exe no specs unicorn-59193.exe no specs unicorn-59193.exe no specs unicorn-59193.exe no specs unicorn-59193.exe no specs unicorn-59193.exe no specs unicorn-7391.exe no specs unicorn-59193.exe no specs unicorn-5908.exe no specs unicorn-5908.exe no specs unicorn-25509.exe no specs unicorn-38145.exe no specs unicorn-49900.exe no specs unicorn-38964.exe no specs unicorn-2016.exe no specs unicorn-33203.exe no specs unicorn-37288.exe no specs unicorn-39334.exe no specs unicorn-2120.exe no specs unicorn-48057.exe no specs unicorn-48057.exe no specs unicorn-61792.exe no specs unicorn-63076.exe no specs unicorn-3324.exe no specs unicorn-339.exe no specs unicorn-7408.exe no specs unicorn-59681.exe no specs unicorn-51016.exe no specs unicorn-23168.exe no specs unicorn-39504.exe no specs unicorn-42934.exe no specs unicorn-31528.exe no specs unicorn-10096.exe no specs unicorn-56033.exe no specs unicorn-56033.exe no specs unicorn-36572.exe no specs unicorn-44741.exe no specs unicorn-61077.exe no specs unicorn-15140.exe no specs unicorn-12260.exe no specs unicorn-25995.exe no specs unicorn-42332.exe no specs unicorn-42332.exe no specs unicorn-9467.exe no specs unicorn-61269.exe no specs unicorn-61269.exe no specs unicorn-29503.exe no specs unicorn-41756.exe no specs unicorn-59873.exe no specs unicorn-40272.exe no specs unicorn-48441.exe no specs unicorn-62176.exe no specs unicorn-17443.exe no specs unicorn-29695.exe no specs unicorn-46032.exe no specs unicorn-46032.exe no specs unicorn-55484.exe no specs unicorn-36521.exe no specs unicorn-55160.exe no specs unicorn-55160.exe no specs unicorn-4860.exe no specs unicorn-13028.exe no specs unicorn-26763.exe no specs unicorn-36746.exe no specs unicorn-39016.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
472C:\Users\admin\AppData\Local\Temp\Unicorn-44832.exeC:\Users\admin\AppData\Local\Temp\Unicorn-44832.exe
Unicorn-22247.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-44832.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
732C:\Users\admin\AppData\Local\Temp\Unicorn-30664.exeC:\Users\admin\AppData\Local\Temp\Unicorn-30664.exe
Unicorn-1753.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-30664.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
960C:\Users\admin\AppData\Local\Temp\Unicorn-50591.exeC:\Users\admin\AppData\Local\Temp\Unicorn-50591.exe
Unicorn-22247.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-50591.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
976C:\Users\admin\AppData\Local\Temp\Unicorn-22247.exeC:\Users\admin\AppData\Local\Temp\Unicorn-22247.exe
1 (1282).exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-22247.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1040C:\Users\admin\AppData\Local\Temp\Unicorn-64779.exeC:\Users\admin\AppData\Local\Temp\Unicorn-64779.exe
Unicorn-37431.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-64779.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1188C:\Users\admin\AppData\Local\Temp\Unicorn-62624.exeC:\Users\admin\AppData\Local\Temp\Unicorn-62624.exe
Unicorn-28333.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-62624.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1196C:\Users\admin\AppData\Local\Temp\Unicorn-9923.exeC:\Users\admin\AppData\Local\Temp\Unicorn-9923.exe
Unicorn-31981.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-9923.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1228C:\Users\admin\AppData\Local\Temp\Unicorn-23917.exeC:\Users\admin\AppData\Local\Temp\Unicorn-23917.exe
Unicorn-46419.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-23917.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1628C:\Users\admin\AppData\Local\Temp\Unicorn-58126.exeC:\Users\admin\AppData\Local\Temp\Unicorn-58126.exe
Unicorn-31981.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-58126.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1660C:\Users\admin\AppData\Local\Temp\Unicorn-19231.exeC:\Users\admin\AppData\Local\Temp\Unicorn-19231.exe
Unicorn-22610.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-19231.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
Total events
16 252
Read events
16 237
Write events
15
Delete events
0

Modification events

(PID) Process:(7636) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7636) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7636) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(8112) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(8112) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(8112) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6676) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6676) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6676) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7316) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
Executable files
998
Suspicious files
11
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
21361 (1282).exeC:\Users\admin\AppData\Local\Temp\Unicorn-22247.exeexecutable
MD5:A8C0429973E150B5726CF411EE63530B
SHA256:965C1D597185941525D8D2B6207D5C232874722699F8A191BF92846301C0A6A7
976Unicorn-22247.exeC:\Users\admin\AppData\Local\Temp\Unicorn-50591.exeexecutable
MD5:DF389AFF8C7A92FC5271DF6D1404244A
SHA256:50BEDBAC75D90D760309C3AD805D3EA3D1BB6B5E7541498B7FE521FCEDAFA48D
21361 (1282).exeC:\Users\admin\AppData\Local\Temp\Unicorn-1753.exeexecutable
MD5:7CBBBEF5C020F5256DC64768664AC96B
SHA256:F14C98694F3FF94FE1914F794A3DD0CFACB6198126D340BF18F5612430373133
976Unicorn-22247.exeC:\Users\admin\AppData\Local\Temp\Unicorn-28333.exeexecutable
MD5:D08B5FD04015F19EC97CF523C2571468
SHA256:2B397B004D8740B78441ED2B6952EDD2D26AADDC14097A71D2BFEF693311E07E
960Unicorn-50591.exeC:\Users\admin\AppData\Local\Temp\Unicorn-23503.exeexecutable
MD5:FB6E10CC5932583B28D90F07DCB0A5C8
SHA256:9DC44DC92C8A0613B3868A00D03497D32484A98595AF073501DC2C2551AA0091
976Unicorn-22247.exeC:\Users\admin\AppData\Local\Temp\Unicorn-28996.exeexecutable
MD5:6EDD1D57B6466183793EFABE525F6622
SHA256:F04ED003599CF32F72F46942CA4317DAC9B0B58E8169AA9754062EBA0F30F730
960Unicorn-50591.exeC:\Users\admin\AppData\Local\Temp\Unicorn-23132.exeexecutable
MD5:CF02FE6791B1839145D28E3C8AE6AFEB
SHA256:7CE5F20841C38F448479DC390B39C7161BFD022842C18AC8E57FE5950A3157E3
7436Unicorn-46419.exeC:\Users\admin\AppData\Local\Temp\Unicorn-866.exeexecutable
MD5:37EDE50C23C80D5EDC725754AC8CEC58
SHA256:F39D143D34296CA627E2B4270BD731CAEDEC91EA8113AB63DBE0652444F99622
7396Unicorn-2380.exeC:\Users\admin\AppData\Local\Temp\Unicorn-26959.exeexecutable
MD5:7F4DEC323691DE50BF74B886CC6E2E5B
SHA256:C81E6A42FADBAC97520474A2C285F3650D4E192EF822AA947B107A3ECFF50A19
21361 (1282).exeC:\Users\admin\AppData\Local\Temp\Unicorn-22610.exeexecutable
MD5:26F0BCBFEA37AE8639CC0268DA3527F5
SHA256:F8A311DF23240DDD64C578A8AE80C4464C1019B86B717E2BFCF469D9A04CA98F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
24
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8568
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
8112
BackgroundTransferHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
8568
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4380
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
40.126.32.134:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.110
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.166
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 40.126.32.134
  • 20.190.160.17
  • 40.126.32.74
  • 20.190.160.132
  • 20.190.160.128
  • 40.126.32.136
  • 40.126.32.68
  • 20.190.160.3
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
arc.msn.com
  • 20.74.47.205
whitelisted
www.bing.com
  • 2.16.204.138
  • 2.16.204.135
  • 2.16.204.132
  • 2.16.204.146
  • 2.16.204.159
  • 2.16.204.160
  • 2.16.204.161
  • 2.16.204.134
  • 2.16.204.137
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
www.microsoft.com
  • 2.16.253.202
whitelisted

Threats

No threats detected
No debug info