File name:

6abb0a7186075b7f4888c072f86e9f164b6a501b320c5d4280669b3460173140

Full analysis: https://app.any.run/tasks/ae333304-22f4-463b-a929-091dd4f3dae3
Verdict: Malicious activity
Analysis date: November 12, 2024, 20:46:55
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections
MD5:

0A8DB9C8607A09FA76C5EFCB05CC4DC0

SHA1:

3B8A35D5E02718C37B5A077FB95AAE299ACA44B4

SHA256:

6ABB0A7186075B7F4888C072F86E9F164B6A501B320C5D4280669B3460173140

SSDEEP:

6144:R7zgX2/sgDvHA5qzkQeEWofx5hBqapKGBL/WAeOgTk/8SwjwpyAMEhrPO1EV+4Wa:R/2u/HA5akLeBb8aLOAeOgtx4DxmDsR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts itself from another location

      • Unicorn-3848.exe (PID: 5236)
      • Unicorn-195.exe (PID: 6352)
      • 6abb0a7186075b7f4888c072f86e9f164b6a501b320c5d4280669b3460173140.exe (PID: 5100)
      • Unicorn-50356.exe (PID: 7140)
      • Unicorn-37850.exe (PID: 1452)
      • Unicorn-26152.exe (PID: 7148)
      • Unicorn-3039.exe (PID: 6960)
      • Unicorn-39888.exe (PID: 6184)
      • Unicorn-45032.exe (PID: 6168)
      • Unicorn-662.exe (PID: 4208)
      • Unicorn-662.exe (PID: 4436)
      • Unicorn-24612.exe (PID: 6160)
      • Unicorn-63241.exe (PID: 860)
      • Unicorn-24612.exe (PID: 6224)
      • Unicorn-57376.exe (PID: 3156)
      • Unicorn-21488.exe (PID: 1700)
      • Unicorn-16588.exe (PID: 6148)
      • Unicorn-5727.exe (PID: 2280)
      • Unicorn-28840.exe (PID: 7112)
      • Unicorn-51254.exe (PID: 4680)
      • Unicorn-50844.exe (PID: 6252)
      • Unicorn-50844.exe (PID: 6028)
      • Unicorn-32370.exe (PID: 6704)
      • Unicorn-63096.exe (PID: 700)
      • Unicorn-63096.exe (PID: 5516)
      • Unicorn-26239.exe (PID: 6676)
      • Unicorn-26239.exe (PID: 300)
      • Unicorn-63096.exe (PID: 5828)
      • Unicorn-38135.exe (PID: 7036)
      • Unicorn-49261.exe (PID: 5220)
      • Unicorn-18534.exe (PID: 7040)
      • Unicorn-29469.exe (PID: 5588)
      • Unicorn-49858.exe (PID: 5900)
      • Unicorn-5488.exe (PID: 3396)
      • Unicorn-33229.exe (PID: 616)
      • Unicorn-31192.exe (PID: 6336)
      • Unicorn-33330.exe (PID: 1248)
      • Unicorn-44112.exe (PID: 4236)
      • Unicorn-37990.exe (PID: 5160)
      • Unicorn-30376.exe (PID: 5512)
      • Unicorn-35852.exe (PID: 4568)
      • Unicorn-34460.exe (PID: 6324)
      • Unicorn-11902.exe (PID: 1332)
      • Unicorn-33714.exe (PID: 4448)
      • Unicorn-4933.exe (PID: 6000)
      • Unicorn-19516.exe (PID: 4232)
      • Unicorn-4933.exe (PID: 7128)
      • Unicorn-9017.exe (PID: 3972)
      • Unicorn-33714.exe (PID: 7100)
      • Unicorn-16920.exe (PID: 4996)
      • Unicorn-23962.exe (PID: 4164)
      • Unicorn-23962.exe (PID: 5644)
      • Unicorn-53372.exe (PID: 7104)
      • Unicorn-56172.exe (PID: 6360)
      • Unicorn-36836.exe (PID: 5948)
      • Unicorn-43828.exe (PID: 824)
      • Unicorn-64995.exe (PID: 712)
      • Unicorn-17186.exe (PID: 6900)
      • Unicorn-62857.exe (PID: 6176)
      • Unicorn-16920.exe (PID: 6760)
      • Unicorn-43828.exe (PID: 6888)
      • Unicorn-17277.exe (PID: 6808)
      • Unicorn-9977.exe (PID: 7236)
      • Unicorn-59178.exe (PID: 7280)
      • Unicorn-35022.exe (PID: 7336)
      • Unicorn-18237.exe (PID: 7288)
      • Unicorn-49967.exe (PID: 7356)
      • Unicorn-5976.exe (PID: 7396)
      • Unicorn-24716.exe (PID: 7372)
      • Unicorn-2712.exe (PID: 7416)
      • Unicorn-2712.exe (PID: 7424)
      • Unicorn-55250.exe (PID: 7456)
      • Unicorn-57964.exe (PID: 7468)
      • Unicorn-10444.exe (PID: 7564)
      • Unicorn-40044.exe (PID: 7492)
      • Unicorn-55726.exe (PID: 7544)
      • Unicorn-60294.exe (PID: 7604)
      • Unicorn-37352.exe (PID: 7508)
      • Unicorn-43574.exe (PID: 7520)
      • Unicorn-60194.exe (PID: 7696)
      • Unicorn-58156.exe (PID: 7680)
      • Unicorn-10993.exe (PID: 7748)
      • Unicorn-29376.exe (PID: 7724)
      • Unicorn-42204.exe (PID: 7852)
      • Unicorn-5255.exe (PID: 7824)
      • Unicorn-42204.exe (PID: 7844)
      • Unicorn-58903.exe (PID: 7660)
      • Unicorn-3480.exe (PID: 7716)
      • Unicorn-59095.exe (PID: 7912)
      • Unicorn-47419.exe (PID: 7984)
      • Unicorn-58924.exe (PID: 8052)
      • Unicorn-54456.exe (PID: 7888)
      • Unicorn-1726.exe (PID: 7952)
      • Unicorn-24205.exe (PID: 8012)
      • Unicorn-48810.exe (PID: 8028)
      • Unicorn-63008.exe (PID: 8064)
      • Unicorn-50756.exe (PID: 8100)
      • Unicorn-46672.exe (PID: 8092)
      • Unicorn-50656.exe (PID: 3008)
      • Unicorn-58924.exe (PID: 8044)
      • Unicorn-4248.exe (PID: 8116)
      • Unicorn-50756.exe (PID: 8108)
      • Unicorn-16256.exe (PID: 8320)
      • Unicorn-42588.exe (PID: 8160)
      • Unicorn-24114.exe (PID: 8136)
      • Unicorn-42588.exe (PID: 6880)
      • Unicorn-15845.exe (PID: 8200)
      • Unicorn-793.exe (PID: 8188)
      • Unicorn-34895.exe (PID: 8284)
      • Unicorn-26060.exe (PID: 8124)
      • Unicorn-46572.exe (PID: 4904)
      • Unicorn-63319.exe (PID: 8276)
      • Unicorn-43718.exe (PID: 8292)
      • Unicorn-11675.exe (PID: 8328)
      • Unicorn-55184.exe (PID: 8260)
      • Unicorn-43718.exe (PID: 8300)
      • Unicorn-38118.exe (PID: 8268)
      • Unicorn-29158.exe (PID: 8392)
      • Unicorn-48618.exe (PID: 7264)
      • Unicorn-17892.exe (PID: 3916)
      • Unicorn-47632.exe (PID: 8440)
      • Unicorn-15322.exe (PID: 8476)
      • Unicorn-22671.exe (PID: 8492)
      • Unicorn-42348.exe (PID: 8564)
      • Unicorn-37710.exe (PID: 8556)
      • Unicorn-7154.exe (PID: 8452)
      • Unicorn-63968.exe (PID: 8412)
      • Unicorn-57554.exe (PID: 8548)
      • Unicorn-39656.exe (PID: 8604)
      • Unicorn-36126.exe (PID: 8692)
      • Unicorn-9021.exe (PID: 8632)
      • Unicorn-31605.exe (PID: 7624)
      • Unicorn-43958.exe (PID: 7636)
      • Unicorn-49770.exe (PID: 8760)
      • Unicorn-35956.exe (PID: 8812)
      • Unicorn-49962.exe (PID: 8624)
      • Unicorn-38894.exe (PID: 8668)
      • Unicorn-21465.exe (PID: 8840)
      • Unicorn-23730.exe (PID: 7880)
      • Unicorn-62982.exe (PID: 8896)
      • Unicorn-12390.exe (PID: 8916)
      • Unicorn-18420.exe (PID: 8948)
      • Unicorn-29825.exe (PID: 8804)
      • Unicorn-9121.exe (PID: 8860)
      • Unicorn-23512.exe (PID: 8876)
      • Unicorn-36894.exe (PID: 8968)
      • Unicorn-54436.exe (PID: 9068)
      • Unicorn-26610.exe (PID: 9048)
      • Unicorn-20287.exe (PID: 9128)
      • Unicorn-522.exe (PID: 9100)
      • Unicorn-5421.exe (PID: 8992)
      • Unicorn-58706.exe (PID: 9016)
      • Unicorn-32183.exe (PID: 9152)
      • Unicorn-43692.exe (PID: 6820)
      • Unicorn-5997.exe (PID: 9092)
      • Unicorn-1726.exe (PID: 7960)
    • Executable content was dropped or overwritten

      • Unicorn-3848.exe (PID: 5236)
      • Unicorn-50356.exe (PID: 7140)
      • Unicorn-195.exe (PID: 6352)
      • 6abb0a7186075b7f4888c072f86e9f164b6a501b320c5d4280669b3460173140.exe (PID: 5100)
      • Unicorn-37850.exe (PID: 1452)
      • Unicorn-3039.exe (PID: 6960)
      • Unicorn-39888.exe (PID: 6184)
      • Unicorn-45032.exe (PID: 6168)
      • Unicorn-51254.exe (PID: 4680)
      • Unicorn-662.exe (PID: 4436)
      • Unicorn-63241.exe (PID: 860)
      • Unicorn-26152.exe (PID: 7148)
      • Unicorn-24612.exe (PID: 6160)
      • Unicorn-21488.exe (PID: 1700)
      • Unicorn-16588.exe (PID: 6148)
      • Unicorn-28840.exe (PID: 7112)
      • Unicorn-5727.exe (PID: 2280)
      • Unicorn-50844.exe (PID: 6252)
      • Unicorn-50844.exe (PID: 6028)
      • Unicorn-662.exe (PID: 4208)
      • Unicorn-26239.exe (PID: 6676)
      • Unicorn-63096.exe (PID: 5828)
      • Unicorn-49261.exe (PID: 5220)
      • Unicorn-32370.exe (PID: 6704)
      • Unicorn-38135.exe (PID: 7036)
      • Unicorn-24612.exe (PID: 6224)
      • Unicorn-18534.exe (PID: 7040)
      • Unicorn-57376.exe (PID: 3156)
      • Unicorn-49858.exe (PID: 5900)
      • Unicorn-5488.exe (PID: 3396)
      • Unicorn-31192.exe (PID: 6336)
      • Unicorn-33330.exe (PID: 1248)
      • Unicorn-33229.exe (PID: 616)
      • Unicorn-44112.exe (PID: 4236)
      • Unicorn-30376.exe (PID: 5512)
      • Unicorn-37990.exe (PID: 5160)
      • Unicorn-35852.exe (PID: 4568)
      • Unicorn-34460.exe (PID: 6324)
      • Unicorn-11902.exe (PID: 1332)
      • Unicorn-4933.exe (PID: 6000)
      • Unicorn-33714.exe (PID: 4448)
      • Unicorn-19516.exe (PID: 4232)
      • Unicorn-9017.exe (PID: 3972)
      • Unicorn-63096.exe (PID: 700)
      • Unicorn-4933.exe (PID: 7128)
      • Unicorn-16920.exe (PID: 4996)
      • Unicorn-23962.exe (PID: 5644)
      • Unicorn-53372.exe (PID: 7104)
      • Unicorn-29469.exe (PID: 5588)
      • Unicorn-56172.exe (PID: 6360)
      • Unicorn-43828.exe (PID: 824)
      • Unicorn-64995.exe (PID: 712)
      • Unicorn-43828.exe (PID: 6888)
      • Unicorn-17186.exe (PID: 6900)
      • Unicorn-17277.exe (PID: 6808)
      • Unicorn-16920.exe (PID: 6760)
      • Unicorn-9977.exe (PID: 7236)
      • Unicorn-59178.exe (PID: 7280)
      • Unicorn-18237.exe (PID: 7288)
      • Unicorn-35022.exe (PID: 7336)
      • Unicorn-49967.exe (PID: 7356)
      • Unicorn-24716.exe (PID: 7372)
      • Unicorn-2712.exe (PID: 7416)
      • Unicorn-2712.exe (PID: 7424)
      • Unicorn-63096.exe (PID: 5516)
      • Unicorn-5976.exe (PID: 7396)
      • Unicorn-57964.exe (PID: 7468)
      • Unicorn-37352.exe (PID: 7508)
      • Unicorn-10444.exe (PID: 7564)
      • Unicorn-43574.exe (PID: 7520)
      • Unicorn-55726.exe (PID: 7544)
      • Unicorn-40044.exe (PID: 7492)
      • Unicorn-31605.exe (PID: 7624)
      • Unicorn-60294.exe (PID: 7604)
      • Unicorn-55250.exe (PID: 7456)
      • Unicorn-58156.exe (PID: 7680)
      • Unicorn-3480.exe (PID: 7716)
      • Unicorn-10993.exe (PID: 7748)
      • Unicorn-5255.exe (PID: 7824)
      • Unicorn-42204.exe (PID: 7852)
      • Unicorn-58903.exe (PID: 7660)
      • Unicorn-43958.exe (PID: 7636)
      • Unicorn-60194.exe (PID: 7696)
      • Unicorn-29376.exe (PID: 7724)
      • Unicorn-1726.exe (PID: 7952)
      • Unicorn-59095.exe (PID: 7912)
      • Unicorn-1726.exe (PID: 7960)
      • Unicorn-47419.exe (PID: 7984)
      • Unicorn-23730.exe (PID: 7880)
      • Unicorn-26239.exe (PID: 300)
      • Unicorn-23962.exe (PID: 4164)
      • Unicorn-58924.exe (PID: 8052)
      • Unicorn-58924.exe (PID: 8044)
      • Unicorn-54456.exe (PID: 7888)
      • Unicorn-33714.exe (PID: 7100)
      • Unicorn-4248.exe (PID: 8116)
      • Unicorn-48810.exe (PID: 8028)
      • Unicorn-50756.exe (PID: 8108)
      • Unicorn-63008.exe (PID: 8064)
      • Unicorn-50756.exe (PID: 8100)
      • Unicorn-46672.exe (PID: 8092)
      • Unicorn-46572.exe (PID: 4904)
      • Unicorn-24205.exe (PID: 8012)
      • Unicorn-24114.exe (PID: 8136)
      • Unicorn-42588.exe (PID: 6880)
      • Unicorn-26060.exe (PID: 8124)
      • Unicorn-793.exe (PID: 8188)
      • Unicorn-34895.exe (PID: 8284)
      • Unicorn-48618.exe (PID: 7264)
      • Unicorn-16256.exe (PID: 8320)
      • Unicorn-15845.exe (PID: 8200)
      • Unicorn-63319.exe (PID: 8276)
      • Unicorn-43718.exe (PID: 8300)
      • Unicorn-55184.exe (PID: 8260)
      • Unicorn-38118.exe (PID: 8268)
      • Unicorn-29158.exe (PID: 8392)
      • Unicorn-7154.exe (PID: 8452)
      • Unicorn-17892.exe (PID: 3916)
      • Unicorn-11675.exe (PID: 8328)
      • Unicorn-15322.exe (PID: 8476)
      • Unicorn-47632.exe (PID: 8440)
      • Unicorn-22671.exe (PID: 8492)
      • Unicorn-42348.exe (PID: 8564)
      • Unicorn-57554.exe (PID: 8548)
      • Unicorn-37710.exe (PID: 8556)
      • Unicorn-63968.exe (PID: 8412)
      • Unicorn-49962.exe (PID: 8624)
      • Unicorn-9021.exe (PID: 8632)
      • Unicorn-36126.exe (PID: 8692)
      • Unicorn-38894.exe (PID: 8668)
      • Unicorn-49770.exe (PID: 8760)
      • Unicorn-35956.exe (PID: 8812)
      • Unicorn-39656.exe (PID: 8604)
      • Unicorn-23512.exe (PID: 8876)
      • Unicorn-62982.exe (PID: 8896)
      • Unicorn-36894.exe (PID: 8968)
      • Unicorn-12390.exe (PID: 8916)
      • Unicorn-18420.exe (PID: 8948)
      • Unicorn-29825.exe (PID: 8804)
      • Unicorn-21465.exe (PID: 8840)
      • Unicorn-9121.exe (PID: 8860)
      • Unicorn-26610.exe (PID: 9048)
      • Unicorn-36836.exe (PID: 5948)
      • Unicorn-50656.exe (PID: 3008)
      • Unicorn-54436.exe (PID: 9068)
      • Unicorn-43718.exe (PID: 8292)
      • Unicorn-20287.exe (PID: 9128)
      • Unicorn-522.exe (PID: 9100)
      • Unicorn-5997.exe (PID: 9092)
      • Unicorn-5421.exe (PID: 8992)
      • Unicorn-58706.exe (PID: 9016)
      • Unicorn-47414.exe (PID: 9204)
      • Unicorn-43692.exe (PID: 6820)
      • Unicorn-6189.exe (PID: 6364)
      • Unicorn-6500.exe (PID: 6416)
      • Unicorn-33408.exe (PID: 2844)
      • Unicorn-45971.exe (PID: 9232)
      • Unicorn-8711.exe (PID: 7080)
      • Unicorn-49744.exe (PID: 1048)
      • Unicorn-21055.exe (PID: 7116)
      • Unicorn-42204.exe (PID: 7844)
      • Unicorn-32183.exe (PID: 9152)
      • Unicorn-15125.exe (PID: 6776)
      • Unicorn-21518.exe (PID: 6908)
      • Unicorn-41768.exe (PID: 9332)
      • Unicorn-35462.exe (PID: 9840)
      • Unicorn-22116.exe (PID: 9652)
      • Unicorn-9863.exe (PID: 9612)
      • Unicorn-37408.exe (PID: 9896)
      • Unicorn-22116.exe (PID: 9644)
      • Unicorn-43268.exe (PID: 9708)
      • Unicorn-8820.exe (PID: 9848)
      • Unicorn-58213.exe (PID: 9700)
      • Unicorn-24602.exe (PID: 9832)
      • Unicorn-57942.exe (PID: 9992)
      • Unicorn-57274.exe (PID: 9908)
      • Unicorn-13371.exe (PID: 9276)
      • Unicorn-6957.exe (PID: 9312)
      • Unicorn-34538.exe (PID: 9252)
      • Unicorn-54112.exe (PID: 9372)
      • Unicorn-48301.exe (PID: 9400)
      • Unicorn-63511.exe (PID: 9424)
      • Unicorn-2043.exe (PID: 9948)
      • Unicorn-26548.exe (PID: 9924)
      • Unicorn-45498.exe (PID: 10080)
      • Unicorn-59988.exe (PID: 9976)
      • Unicorn-29161.exe (PID: 10100)
      • Unicorn-62026.exe (PID: 10040)
      • Unicorn-29646.exe (PID: 10204)
      • Unicorn-34284.exe (PID: 10276)
      • Unicorn-64627.exe (PID: 10024)
      • Unicorn-30751.exe (PID: 10124)
      • Unicorn-48020.exe (PID: 10264)
      • Unicorn-48120.exe (PID: 9904)
      • Unicorn-4657.exe (PID: 10060)
      • Unicorn-29624.exe (PID: 10160)
      • Unicorn-13864.exe (PID: 10216)
      • Unicorn-38998.exe (PID: 10568)
      • Unicorn-21020.exe (PID: 10404)
      • Unicorn-48675.exe (PID: 10332)
      • Unicorn-26116.exe (PID: 10380)
      • Unicorn-45982.exe (PID: 10356)
      • Unicorn-22462.exe (PID: 10560)
      • Unicorn-11555.exe (PID: 10844)
      • Unicorn-633.exe (PID: 10592)
      • Unicorn-44639.exe (PID: 10512)
      • Unicorn-53958.exe (PID: 10672)
      • Unicorn-44591.exe (PID: 10228)
      • Unicorn-13864.exe (PID: 10212)
      • Unicorn-34284.exe (PID: 10272)
      • Unicorn-56096.exe (PID: 10432)
      • Unicorn-60927.exe (PID: 10388)
      • Unicorn-45790.exe (PID: 10696)
      • Unicorn-20516.exe (PID: 10364)
      • Unicorn-33538.exe (PID: 10472)
      • Unicorn-8768.exe (PID: 10504)
      • Unicorn-52012.exe (PID: 10416)
      • Unicorn-23232.exe (PID: 10604)
      • Unicorn-37714.exe (PID: 10544)
      • Unicorn-13693.exe (PID: 10764)
      • Unicorn-36252.exe (PID: 10732)
      • Unicorn-29838.exe (PID: 10884)
      • Unicorn-13693.exe (PID: 10756)
      • Unicorn-20278.exe (PID: 10932)
      • Unicorn-52396.exe (PID: 10860)
      • Unicorn-36060.exe (PID: 10944)
      • Unicorn-50258.exe (PID: 11032)
      • Unicorn-26116.exe (PID: 10372)
      • Unicorn-27892.exe (PID: 10820)
      • Unicorn-17778.exe (PID: 10784)
      • Unicorn-37714.exe (PID: 10548)
      • Unicorn-58426.exe (PID: 10992)
      • Unicorn-62510.exe (PID: 10984)
      • Unicorn-14056.exe (PID: 10892)
      • Unicorn-1149.exe (PID: 11000)
      • Unicorn-34498.exe (PID: 11104)
      • Unicorn-62510.exe (PID: 11016)
      • Unicorn-64648.exe (PID: 10908)
      • Unicorn-103.exe (PID: 10664)
      • Unicorn-28084.exe (PID: 11224)
      • Unicorn-14990.exe (PID: 10396)
      • Unicorn-38560.exe (PID: 10968)
      • Unicorn-25567.exe (PID: 11112)
      • Unicorn-62702.exe (PID: 10812)
      • Unicorn-60464.exe (PID: 10976)
      • Unicorn-11726.exe (PID: 10324)
      • Unicorn-40720.exe (PID: 11156)
      • Unicorn-53335.exe (PID: 11244)
      • Unicorn-18354.exe (PID: 11444)
      • Unicorn-33920.exe (PID: 11320)
      • Unicorn-37574.exe (PID: 11276)
      • Unicorn-51218.exe (PID: 11372)
      • Unicorn-57248.exe (PID: 11404)
      • Unicorn-22438.exe (PID: 11380)
      • Unicorn-57175.exe (PID: 11300)
      • Unicorn-22529.exe (PID: 11336)
      • Unicorn-37382.exe (PID: 11396)
      • Unicorn-14269.exe (PID: 11436)
      • Unicorn-26613.exe (PID: 11344)
      • Unicorn-21020.exe (PID: 10448)
      • Unicorn-53335.exe (PID: 11252)
      • Unicorn-33490.exe (PID: 11268)
      • Unicorn-1533.exe (PID: 11260)
      • Unicorn-37958.exe (PID: 11492)
      • Unicorn-31736.exe (PID: 11536)
      • Unicorn-49940.exe (PID: 11660)
      • Unicorn-15208.exe (PID: 11580)
      • Unicorn-57559.exe (PID: 11500)
      • Unicorn-51337.exe (PID: 11548)
      • Unicorn-31544.exe (PID: 11616)
      • Unicorn-45280.exe (PID: 11624)
    • Executes application which crashes

      • Unicorn-62857.exe (PID: 6176)
      • Unicorn-29376.exe (PID: 7724)
      • Unicorn-42588.exe (PID: 8160)
      • Unicorn-42588.exe (PID: 6880)
  • INFO

    • Reads the computer name

      • Unicorn-50356.exe (PID: 7140)
      • Unicorn-195.exe (PID: 6352)
      • 6abb0a7186075b7f4888c072f86e9f164b6a501b320c5d4280669b3460173140.exe (PID: 5100)
      • Unicorn-3848.exe (PID: 5236)
      • Unicorn-3039.exe (PID: 6960)
      • Unicorn-37850.exe (PID: 1452)
      • Unicorn-26152.exe (PID: 7148)
      • Unicorn-39888.exe (PID: 6184)
      • Unicorn-45032.exe (PID: 6168)
      • Unicorn-51254.exe (PID: 4680)
      • Unicorn-662.exe (PID: 4436)
      • Unicorn-63241.exe (PID: 860)
      • Unicorn-24612.exe (PID: 6160)
      • Unicorn-57376.exe (PID: 3156)
      • Unicorn-24612.exe (PID: 6224)
      • Unicorn-21488.exe (PID: 1700)
      • Unicorn-662.exe (PID: 4208)
      • Unicorn-16588.exe (PID: 6148)
      • Unicorn-5727.exe (PID: 2280)
      • Unicorn-26239.exe (PID: 300)
      • Unicorn-50844.exe (PID: 6252)
      • Unicorn-50844.exe (PID: 6028)
      • Unicorn-26239.exe (PID: 6676)
      • Unicorn-63096.exe (PID: 5516)
      • Unicorn-32370.exe (PID: 6704)
      • Unicorn-63096.exe (PID: 700)
      • Unicorn-63096.exe (PID: 5828)
      • Unicorn-49261.exe (PID: 5220)
      • Unicorn-29469.exe (PID: 5588)
      • Unicorn-38135.exe (PID: 7036)
      • Unicorn-18534.exe (PID: 7040)
      • Unicorn-49858.exe (PID: 5900)
      • Unicorn-5488.exe (PID: 3396)
      • Unicorn-28840.exe (PID: 7112)
      • Unicorn-33330.exe (PID: 1248)
      • Unicorn-33229.exe (PID: 616)
      • Unicorn-31192.exe (PID: 6336)
      • Unicorn-37990.exe (PID: 5160)
      • Unicorn-30376.exe (PID: 5512)
      • Unicorn-44112.exe (PID: 4236)
      • Unicorn-35852.exe (PID: 4568)
      • Unicorn-34460.exe (PID: 6324)
      • Unicorn-33714.exe (PID: 4448)
      • Unicorn-33714.exe (PID: 7100)
      • Unicorn-4933.exe (PID: 6000)
      • Unicorn-4933.exe (PID: 7128)
      • Unicorn-19516.exe (PID: 4232)
      • Unicorn-11902.exe (PID: 1332)
      • Unicorn-9017.exe (PID: 3972)
      • Unicorn-43828.exe (PID: 824)
      • Unicorn-16920.exe (PID: 4996)
      • Unicorn-23962.exe (PID: 4164)
      • Unicorn-36836.exe (PID: 5948)
      • Unicorn-56172.exe (PID: 6360)
      • Unicorn-16920.exe (PID: 6760)
      • Unicorn-17277.exe (PID: 6808)
      • Unicorn-23962.exe (PID: 5644)
      • Unicorn-62857.exe (PID: 6176)
      • Unicorn-43828.exe (PID: 6888)
      • Unicorn-53372.exe (PID: 7104)
      • Unicorn-17186.exe (PID: 6900)
      • Unicorn-64995.exe (PID: 712)
      • Unicorn-9977.exe (PID: 7236)
      • Unicorn-59178.exe (PID: 7280)
      • Unicorn-18237.exe (PID: 7288)
      • Unicorn-35022.exe (PID: 7336)
      • Unicorn-49967.exe (PID: 7356)
      • Unicorn-5976.exe (PID: 7396)
      • Unicorn-24716.exe (PID: 7372)
      • Unicorn-2712.exe (PID: 7416)
      • Unicorn-55250.exe (PID: 7456)
      • Unicorn-2712.exe (PID: 7424)
      • Unicorn-10444.exe (PID: 7564)
      • Unicorn-43574.exe (PID: 7520)
      • Unicorn-57964.exe (PID: 7468)
      • Unicorn-37352.exe (PID: 7508)
      • Unicorn-55726.exe (PID: 7544)
      • Unicorn-60294.exe (PID: 7604)
      • Unicorn-40044.exe (PID: 7492)
    • Checks supported languages

      • Unicorn-3848.exe (PID: 5236)
      • Unicorn-50356.exe (PID: 7140)
      • Unicorn-195.exe (PID: 6352)
      • 6abb0a7186075b7f4888c072f86e9f164b6a501b320c5d4280669b3460173140.exe (PID: 5100)
      • Unicorn-37850.exe (PID: 1452)
      • Unicorn-3039.exe (PID: 6960)
      • Unicorn-39888.exe (PID: 6184)
      • Unicorn-26152.exe (PID: 7148)
      • Unicorn-662.exe (PID: 4208)
      • Unicorn-45032.exe (PID: 6168)
      • Unicorn-51254.exe (PID: 4680)
      • Unicorn-662.exe (PID: 4436)
      • Unicorn-63241.exe (PID: 860)
      • Unicorn-24612.exe (PID: 6224)
      • Unicorn-24612.exe (PID: 6160)
      • Unicorn-57376.exe (PID: 3156)
      • Unicorn-21488.exe (PID: 1700)
      • Unicorn-16588.exe (PID: 6148)
      • Unicorn-5727.exe (PID: 2280)
      • Unicorn-28840.exe (PID: 7112)
      • Unicorn-50844.exe (PID: 6252)
      • Unicorn-50844.exe (PID: 6028)
      • Unicorn-26239.exe (PID: 300)
      • Unicorn-32370.exe (PID: 6704)
      • Unicorn-26239.exe (PID: 6676)
      • Unicorn-63096.exe (PID: 5516)
      • Unicorn-63096.exe (PID: 5828)
      • Unicorn-63096.exe (PID: 700)
      • Unicorn-49261.exe (PID: 5220)
      • Unicorn-18534.exe (PID: 7040)
      • Unicorn-29469.exe (PID: 5588)
      • Unicorn-38135.exe (PID: 7036)
      • Unicorn-49858.exe (PID: 5900)
      • Unicorn-5488.exe (PID: 3396)
      • Unicorn-33330.exe (PID: 1248)
      • Unicorn-33229.exe (PID: 616)
      • Unicorn-31192.exe (PID: 6336)
      • Unicorn-37990.exe (PID: 5160)
      • Unicorn-30376.exe (PID: 5512)
      • Unicorn-44112.exe (PID: 4236)
      • Unicorn-35852.exe (PID: 4568)
      • Unicorn-34460.exe (PID: 6324)
      • Unicorn-11902.exe (PID: 1332)
      • Unicorn-33714.exe (PID: 7100)
      • Unicorn-33714.exe (PID: 4448)
      • Unicorn-4933.exe (PID: 6000)
      • Unicorn-4933.exe (PID: 7128)
      • Unicorn-19516.exe (PID: 4232)
      • Unicorn-23962.exe (PID: 4164)
      • Unicorn-43828.exe (PID: 824)
      • Unicorn-16920.exe (PID: 4996)
      • Unicorn-17186.exe (PID: 6900)
      • Unicorn-62857.exe (PID: 6176)
      • Unicorn-16920.exe (PID: 6760)
      • Unicorn-43828.exe (PID: 6888)
      • Unicorn-23962.exe (PID: 5644)
      • Unicorn-64995.exe (PID: 712)
      • Unicorn-17277.exe (PID: 6808)
      • Unicorn-53372.exe (PID: 7104)
      • Unicorn-9017.exe (PID: 3972)
      • Unicorn-36836.exe (PID: 5948)
      • Unicorn-9977.exe (PID: 7236)
      • Unicorn-18237.exe (PID: 7288)
      • Unicorn-59178.exe (PID: 7280)
      • Unicorn-56172.exe (PID: 6360)
      • Unicorn-5976.exe (PID: 7396)
      • Unicorn-24716.exe (PID: 7372)
      • Unicorn-2712.exe (PID: 7416)
      • Unicorn-2712.exe (PID: 7424)
      • Unicorn-35022.exe (PID: 7336)
      • Unicorn-49967.exe (PID: 7356)
      • Unicorn-37352.exe (PID: 7508)
      • Unicorn-55250.exe (PID: 7456)
      • Unicorn-57964.exe (PID: 7468)
      • Unicorn-40044.exe (PID: 7492)
      • Unicorn-55726.exe (PID: 7544)
      • Unicorn-43574.exe (PID: 7520)
      • Unicorn-60294.exe (PID: 7604)
      • Unicorn-43958.exe (PID: 7636)
      • Unicorn-58903.exe (PID: 7660)
      • Unicorn-10444.exe (PID: 7564)
      • Unicorn-31605.exe (PID: 7624)
      • Unicorn-58156.exe (PID: 7680)
      • Unicorn-60194.exe (PID: 7696)
      • Unicorn-3480.exe (PID: 7716)
      • Unicorn-10993.exe (PID: 7748)
      • Unicorn-5255.exe (PID: 7824)
      • Unicorn-29376.exe (PID: 7724)
      • Unicorn-54456.exe (PID: 7888)
      • Unicorn-23730.exe (PID: 7880)
      • Unicorn-59095.exe (PID: 7912)
      • Unicorn-63179.exe (PID: 7932)
      • Unicorn-1726.exe (PID: 7960)
      • Unicorn-47419.exe (PID: 7984)
      • Unicorn-1726.exe (PID: 7952)
      • Unicorn-42204.exe (PID: 7844)
      • Unicorn-42204.exe (PID: 7852)
      • Unicorn-48810.exe (PID: 8028)
      • Unicorn-58924.exe (PID: 8044)
      • Unicorn-58924.exe (PID: 8052)
      • Unicorn-63008.exe (PID: 8064)
      • Unicorn-24205.exe (PID: 8012)
      • Unicorn-50756.exe (PID: 8108)
      • Unicorn-4248.exe (PID: 8116)
      • Unicorn-46672.exe (PID: 8092)
      • Unicorn-50756.exe (PID: 8100)
      • Unicorn-24114.exe (PID: 8136)
      • Unicorn-26060.exe (PID: 8124)
      • Unicorn-42588.exe (PID: 8160)
      • Unicorn-42588.exe (PID: 6880)
      • Unicorn-15845.exe (PID: 8200)
      • Unicorn-793.exe (PID: 8188)
      • Unicorn-48618.exe (PID: 7264)
      • Unicorn-34895.exe (PID: 8284)
      • Unicorn-50656.exe (PID: 3008)
      • Unicorn-46572.exe (PID: 4904)
      • Unicorn-17892.exe (PID: 3916)
      • Unicorn-63319.exe (PID: 8276)
      • Unicorn-38118.exe (PID: 8268)
      • Unicorn-55184.exe (PID: 8260)
      • Unicorn-43718.exe (PID: 8292)
      • Unicorn-11675.exe (PID: 8328)
      • Unicorn-43718.exe (PID: 8300)
      • Unicorn-29158.exe (PID: 8392)
      • Unicorn-16256.exe (PID: 8320)
      • Unicorn-63968.exe (PID: 8412)
      • Unicorn-47632.exe (PID: 8440)
      • Unicorn-7154.exe (PID: 8452)
      • Unicorn-22671.exe (PID: 8492)
      • Unicorn-57554.exe (PID: 8548)
      • Unicorn-42348.exe (PID: 8564)
      • Unicorn-15322.exe (PID: 8476)
      • Unicorn-37710.exe (PID: 8556)
      • Unicorn-49962.exe (PID: 8624)
      • Unicorn-38894.exe (PID: 8668)
      • Unicorn-36126.exe (PID: 8692)
      • Unicorn-49770.exe (PID: 8760)
      • Unicorn-29825.exe (PID: 8804)
      • Unicorn-35956.exe (PID: 8812)
      • Unicorn-39656.exe (PID: 8604)
      • Unicorn-9021.exe (PID: 8632)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Microsoft Visual Basic 6 (90.6)
.exe | Win32 Executable (generic) (4.9)
.exe | Generic Win/DOS Executable (2.2)
.exe | DOS Executable Generic (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:01:20 00:32:00+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 176128
InitializedDataSize: 299008
UninitializedDataSize: -
EntryPoint: 0x13d4
OSVersion: 4
ImageVersion: 1
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: UEFI
ProductName: Kawaii-Unicorn
FileVersion: 1
ProductVersion: 1
InternalName: Kawaii-Unicorn
Icornexe: D
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
572
Monitored processes
446
Malicious processes
71
Suspicious processes
59

Behavior graph

Click at the process to see the details
start 6abb0a7186075b7f4888c072f86e9f164b6a501b320c5d4280669b3460173140.exe unicorn-195.exe unicorn-50356.exe unicorn-3848.exe unicorn-37850.exe unicorn-3039.exe unicorn-26152.exe unicorn-39888.exe unicorn-45032.exe unicorn-51254.exe unicorn-662.exe unicorn-662.exe unicorn-24612.exe unicorn-24612.exe unicorn-63241.exe unicorn-57376.exe unicorn-21488.exe unicorn-16588.exe unicorn-5727.exe unicorn-28840.exe unicorn-50844.exe unicorn-50844.exe unicorn-26239.exe unicorn-26239.exe unicorn-32370.exe unicorn-63096.exe unicorn-63096.exe unicorn-63096.exe unicorn-49261.exe unicorn-18534.exe unicorn-29469.exe unicorn-38135.exe unicorn-49858.exe unicorn-5488.exe unicorn-33330.exe unicorn-33229.exe unicorn-31192.exe unicorn-37990.exe unicorn-44112.exe unicorn-30376.exe unicorn-35852.exe unicorn-34460.exe unicorn-19516.exe unicorn-11902.exe unicorn-29630.exe no specs unicorn-29630.exe no specs unicorn-33714.exe unicorn-33714.exe unicorn-4933.exe unicorn-4933.exe unicorn-9017.exe unicorn-23962.exe unicorn-23962.exe unicorn-43828.exe unicorn-43828.exe unicorn-16920.exe unicorn-16920.exe unicorn-17186.exe unicorn-62857.exe unicorn-64995.exe unicorn-17277.exe unicorn-53372.exe unicorn-36836.exe unicorn-56172.exe unicorn-9977.exe unicorn-63817.exe no specs unicorn-59178.exe unicorn-18237.exe unicorn-35022.exe unicorn-49967.exe unicorn-24716.exe unicorn-5976.exe unicorn-2712.exe unicorn-2712.exe unicorn-55250.exe unicorn-57964.exe unicorn-40044.exe unicorn-37352.exe unicorn-43574.exe unicorn-55726.exe unicorn-10444.exe unicorn-60294.exe unicorn-31605.exe unicorn-43958.exe unicorn-58903.exe unicorn-58156.exe unicorn-60194.exe unicorn-3480.exe unicorn-29376.exe unicorn-10993.exe unicorn-5255.exe unicorn-42204.exe unicorn-42204.exe unicorn-23730.exe unicorn-54456.exe unicorn-59095.exe unicorn-63179.exe no specs unicorn-1726.exe unicorn-1726.exe unicorn-47419.exe unicorn-24205.exe unicorn-48810.exe unicorn-58924.exe unicorn-58924.exe unicorn-63008.exe unicorn-46672.exe unicorn-50756.exe unicorn-50756.exe unicorn-4248.exe unicorn-26060.exe unicorn-24114.exe unicorn-42588.exe unicorn-793.exe unicorn-42588.exe unicorn-48618.exe unicorn-46572.exe unicorn-17892.exe unicorn-50656.exe unicorn-15845.exe unicorn-55184.exe unicorn-38118.exe unicorn-63319.exe unicorn-34895.exe unicorn-43718.exe unicorn-43718.exe unicorn-16256.exe unicorn-11675.exe unicorn-29158.exe unicorn-63968.exe unicorn-47632.exe unicorn-7154.exe unicorn-15322.exe unicorn-22671.exe unicorn-57554.exe unicorn-37710.exe unicorn-42348.exe unicorn-39656.exe unicorn-49962.exe unicorn-9021.exe unicorn-38894.exe unicorn-36126.exe unicorn-49770.exe unicorn-29825.exe unicorn-35956.exe unicorn-21465.exe unicorn-9121.exe unicorn-23512.exe unicorn-62982.exe unicorn-12390.exe unicorn-18420.exe unicorn-36894.exe unicorn-5421.exe unicorn-58706.exe unicorn-26610.exe unicorn-54436.exe unicorn-5997.exe unicorn-522.exe unicorn-20287.exe unicorn-32183.exe unicorn-47414.exe unicorn-43692.exe unicorn-6189.exe unicorn-15125.exe unicorn-33408.exe unicorn-6500.exe unicorn-8711.exe unicorn-49744.exe unicorn-21055.exe unicorn-21518.exe unicorn-45971.exe unicorn-34538.exe unicorn-13371.exe unicorn-6957.exe unicorn-41768.exe unicorn-54112.exe unicorn-48301.exe unicorn-63511.exe unicorn-9863.exe unicorn-22116.exe unicorn-22116.exe unicorn-58213.exe unicorn-43268.exe werfault.exe unicorn-24602.exe unicorn-35462.exe unicorn-8820.exe unicorn-37408.exe unicorn-57274.exe unicorn-26548.exe unicorn-2043.exe unicorn-59988.exe unicorn-57942.exe unicorn-64627.exe unicorn-62026.exe unicorn-4657.exe unicorn-45498.exe unicorn-29161.exe unicorn-30751.exe unicorn-29624.exe unicorn-29646.exe unicorn-13864.exe unicorn-13864.exe unicorn-44591.exe unicorn-48120.exe unicorn-48020.exe unicorn-34284.exe unicorn-34284.exe unicorn-11726.exe unicorn-48675.exe unicorn-45982.exe unicorn-20516.exe unicorn-26116.exe unicorn-26116.exe unicorn-60927.exe unicorn-14990.exe unicorn-21020.exe unicorn-52012.exe unicorn-56096.exe unicorn-21020.exe unicorn-33538.exe unicorn-8768.exe unicorn-44639.exe unicorn-37714.exe unicorn-37714.exe unicorn-22462.exe unicorn-38998.exe unicorn-633.exe unicorn-23232.exe unicorn-103.exe unicorn-53958.exe unicorn-45790.exe unicorn-36252.exe no specs unicorn-36252.exe unicorn-13693.exe unicorn-13693.exe unicorn-17778.exe unicorn-62702.exe unicorn-27892.exe unicorn-11555.exe unicorn-52396.exe unicorn-29838.exe unicorn-14056.exe unicorn-64648.exe unicorn-20278.exe unicorn-36060.exe unicorn-38560.exe unicorn-60464.exe unicorn-62510.exe unicorn-58426.exe unicorn-1149.exe unicorn-62510.exe unicorn-50258.exe unicorn-34498.exe unicorn-25567.exe unicorn-40720.exe unicorn-28084.exe unicorn-53335.exe unicorn-53335.exe unicorn-1533.exe unicorn-33490.exe unicorn-37574.exe unicorn-57175.exe unicorn-33920.exe unicorn-22529.exe unicorn-26613.exe unicorn-51218.exe unicorn-22438.exe unicorn-37382.exe unicorn-57248.exe unicorn-14269.exe unicorn-18354.exe unicorn-37958.exe unicorn-57559.exe unicorn-31736.exe unicorn-51337.exe unicorn-15208.exe unicorn-31544.exe unicorn-45280.exe unicorn-49940.exe unicorn-58108.exe no specs unicorn-54679.exe no specs unicorn-42234.exe no specs unicorn-44181.exe no specs unicorn-42664.exe no specs unicorn-18306.exe no specs unicorn-32041.exe no specs unicorn-38172.exe no specs unicorn-19698.exe no specs unicorn-15613.exe no specs unicorn-64357.exe no specs unicorn-61914.exe no specs werfault.exe no specs unicorn-21452.exe no specs unicorn-64430.exe no specs unicorn-9199.exe no specs unicorn-32312.exe no specs unicorn-7829.exe no specs unicorn-62960.exe no specs unicorn-63615.exe no specs unicorn-28058.exe no specs unicorn-30750.exe no specs unicorn-50430.exe no specs unicorn-32718.exe no specs unicorn-39494.exe no specs unicorn-3672.exe no specs unicorn-49609.exe no specs unicorn-49609.exe no specs unicorn-42924.exe no specs unicorn-13289.exe no specs unicorn-20173.exe no specs unicorn-63807.exe no specs unicorn-49438.exe no specs unicorn-4876.exe no specs unicorn-26423.exe no specs unicorn-5505.exe no specs unicorn-49914.exe no specs unicorn-56044.exe no specs unicorn-56428.exe no specs unicorn-21618.exe no specs unicorn-26256.exe no specs unicorn-54845.exe no specs unicorn-54845.exe no specs unicorn-39800.exe no specs unicorn-26064.exe no specs unicorn-50014.exe no specs unicorn-34345.exe no specs unicorn-7703.exe no specs unicorn-59505.exe no specs werfault.exe no specs werfault.exe no specs unicorn-30069.exe no specs unicorn-22556.exe no specs unicorn-46506.exe no specs unicorn-30724.exe no specs unicorn-65535.exe no specs unicorn-28586.exe no specs unicorn-48187.exe no specs unicorn-11503.exe no specs unicorn-40184.exe no specs unicorn-56931.exe no specs unicorn-61015.exe no specs unicorn-65099.exe no specs unicorn-38722.exe no specs unicorn-52847.exe no specs unicorn-7233.exe no specs unicorn-28315.exe no specs unicorn-42706.exe no specs unicorn-42706.exe no specs unicorn-28970.exe no specs unicorn-42706.exe no specs unicorn-24140.exe no specs unicorn-27959.exe no specs unicorn-8358.exe no specs unicorn-28224.exe no specs unicorn-30261.exe no specs unicorn-30261.exe no specs unicorn-11887.exe no specs unicorn-13925.exe no specs unicorn-13925.exe no specs unicorn-58195.exe no specs unicorn-8207.exe no specs unicorn-14561.exe no specs unicorn-14561.exe no specs unicorn-15845.exe no specs unicorn-11761.exe no specs unicorn-4910.exe no specs unicorn-19300.exe no specs unicorn-25330.exe no specs unicorn-36265.exe no specs unicorn-36265.exe no specs unicorn-53099.exe no specs unicorn-44964.exe no specs unicorn-18098.exe no specs unicorn-38204.exe no specs unicorn-47718.exe no specs unicorn-1210.exe no specs unicorn-27852.exe no specs unicorn-25760.exe no specs unicorn-37390.exe no specs unicorn-6664.exe no specs unicorn-3013.exe no specs unicorn-31360.exe no specs unicorn-58003.exe no specs unicorn-39528.exe no specs unicorn-42242.exe no specs unicorn-60525.exe no specs unicorn-8723.exe no specs unicorn-25138.exe no specs unicorn-46327.exe no specs unicorn-1952.exe no specs unicorn-20975.exe no specs unicorn-25138.exe no specs unicorn-48273.exe no specs unicorn-59970.exe no specs unicorn-12450.exe no specs unicorn-27660.exe no specs unicorn-58387.exe no specs unicorn-6585.exe no specs unicorn-10504.exe no specs unicorn-1018.exe no specs unicorn-15408.exe no specs unicorn-21630.exe no specs unicorn-48702.exe no specs unicorn-2964.exe no specs unicorn-13291.exe no specs unicorn-1039.exe no specs unicorn-7069.exe no specs unicorn-52741.exe no specs unicorn-17184.exe no specs unicorn-25087.exe no specs unicorn-19221.exe no specs unicorn-19221.exe no specs unicorn-56170.exe no specs unicorn-64338.exe no specs unicorn-6115.exe no specs unicorn-64014.exe no specs unicorn-13410.exe no specs unicorn-52305.exe no specs unicorn-62611.exe no specs unicorn-20452.exe no specs unicorn-20452.exe no specs unicorn-48386.exe no specs unicorn-34650.exe no specs unicorn-18314.exe no specs unicorn-18314.exe no specs unicorn-6499.exe no specs unicorn-9299.exe no specs unicorn-26403.exe no specs unicorn-36618.exe no specs unicorn-31771.exe no specs unicorn-13959.exe no specs unicorn-40410.exe no specs unicorn-19632.exe no specs unicorn-34023.exe no specs unicorn-53073.exe no specs unicorn-51292.exe no specs unicorn-4229.exe no specs unicorn-6175.exe no specs unicorn-40662.exe no specs unicorn-32726.exe no specs unicorn-44878.exe no specs unicorn-50743.exe no specs unicorn-4500.exe no specs unicorn-45533.exe no specs unicorn-45533.exe no specs unicorn-21657.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
300C:\Users\admin\Desktop\Unicorn-26239.exeC:\Users\admin\Desktop\Unicorn-26239.exe
Unicorn-3848.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\desktop\unicorn-26239.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
616C:\Users\admin\Desktop\Unicorn-33229.exeC:\Users\admin\Desktop\Unicorn-33229.exe
Unicorn-37850.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\desktop\unicorn-33229.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
700C:\Users\admin\Desktop\Unicorn-63096.exeC:\Users\admin\Desktop\Unicorn-63096.exe
Unicorn-24612.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\desktop\unicorn-63096.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
712C:\Users\admin\Desktop\Unicorn-64995.exeC:\Users\admin\Desktop\Unicorn-64995.exe
Unicorn-57376.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\desktop\unicorn-64995.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
824C:\Users\admin\Desktop\Unicorn-43828.exeC:\Users\admin\Desktop\Unicorn-43828.exe
Unicorn-29469.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\desktop\unicorn-43828.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
860C:\Users\admin\Desktop\Unicorn-63241.exeC:\Users\admin\Desktop\Unicorn-63241.exe
6abb0a7186075b7f4888c072f86e9f164b6a501b320c5d4280669b3460173140.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\desktop\unicorn-63241.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1048C:\Users\admin\Desktop\Unicorn-49744.exeC:\Users\admin\Desktop\Unicorn-49744.exe
Unicorn-58156.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\desktop\unicorn-49744.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1248C:\Users\admin\Desktop\Unicorn-33330.exeC:\Users\admin\Desktop\Unicorn-33330.exe
Unicorn-16588.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\desktop\unicorn-33330.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1332C:\Users\admin\Desktop\Unicorn-11902.exeC:\Users\admin\Desktop\Unicorn-11902.exe
Unicorn-662.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\desktop\unicorn-11902.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1452C:\Users\admin\Desktop\Unicorn-37850.exeC:\Users\admin\Desktop\Unicorn-37850.exe
Unicorn-50356.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\desktop\unicorn-37850.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
Total events
21 019
Read events
21 019
Write events
0
Delete events
0

Modification events

No data
Executable files
1 521
Suspicious files
1
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
6960Unicorn-3039.exeC:\Users\admin\Desktop\Unicorn-51254.exeexecutable
MD5:C67B8AACBDBA98C9A6D5FB39CF260B99
SHA256:C4D588480CC21004D1BF7297AB58C42B243AF70A5517C4AF674307457C5F6F1D
6352Unicorn-195.exeC:\Users\admin\Desktop\Unicorn-50356.exeexecutable
MD5:A2B47D3E0F11CDE9C66514E39B4D2B4B
SHA256:8E5837E099BF8EA3B3BC7D1A2A460CFF8A66FD33D4E1D75DD87E2643FCBE1F86
6352Unicorn-195.exeC:\Users\admin\Desktop\Unicorn-26152.exeexecutable
MD5:65A2FA12E926D74DF19164ED980D8124
SHA256:BA8AC01D6A36C2A047C884EED982CA5A09DD9B6686EFB530CB293553B86C1816
51006abb0a7186075b7f4888c072f86e9f164b6a501b320c5d4280669b3460173140.exeC:\Users\admin\Desktop\Unicorn-3848.exeexecutable
MD5:C00391139F69440407BB882BB5EB6E1F
SHA256:260961373110CC67A5FA08C69F98EB4D1D0654F2388183259E2F07DA523E35EA
5236Unicorn-3848.exeC:\Users\admin\Desktop\Unicorn-3039.exeexecutable
MD5:AA8152206102F033A1AF9510E502CC31
SHA256:A4A3E27BDABEF458EFB4F1FA0C64FA2B4028E468D33F9253A84CC580AB547399
4680Unicorn-51254.exeC:\Users\admin\Desktop\Unicorn-5727.exeexecutable
MD5:CFC3BE9F2D60DEA47EE3D33E8CE3ABB7
SHA256:04FA0B2AE195E6934A9A0A514421FF29563C23572B61A92846FA4D13BFE528A2
51006abb0a7186075b7f4888c072f86e9f164b6a501b320c5d4280669b3460173140.exeC:\Users\admin\Desktop\Unicorn-63241.exeexecutable
MD5:14666C4F2F17E53D5ADA954C5087852E
SHA256:9B6E8B4EC1683F6B86FC792390C6BC8A1F9F72A80AB1C2A791699354ED7200D4
6352Unicorn-195.exeC:\Users\admin\Desktop\Unicorn-57376.exeexecutable
MD5:CC146A1B68845555F7A417799D52D4FC
SHA256:B8B89C6F0901B456E9E39B9414C47E89B93CF88397C2CD89C795143D937F6083
1452Unicorn-37850.exeC:\Users\admin\Desktop\Unicorn-16588.exeexecutable
MD5:76C69EC59FBCB842FD63F9E7D8159BB7
SHA256:733F549609DBFDB7ACB6952D7A85412ADAE8191A521E8D2358C340EEB2F0E432
6160Unicorn-24612.exeC:\Users\admin\Desktop\Unicorn-32370.exeexecutable
MD5:477C47DBE69C015DA47E5A61EC7D11D5
SHA256:EB86A5E1C29D58EC75B3167A0D29FED935ABCD863C1D298BA8A71A256D7FB13E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
27
DNS requests
8
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5640
RUXIMICS.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6944
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
23.53.40.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5640
RUXIMICS.exe
GET
200
23.53.40.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6944
svchost.exe
GET
200
23.53.40.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
184.86.251.18:443
Akamai International B.V.
DE
unknown
4
System
192.168.100.255:137
whitelisted
6944
svchost.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5488
MoUsoCoreWorker.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
5640
RUXIMICS.exe
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
6944
svchost.exe
23.53.40.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5488
MoUsoCoreWorker.exe
23.53.40.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5640
RUXIMICS.exe
23.53.40.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6944
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.251.141.46
whitelisted
crl.microsoft.com
  • 23.53.40.176
  • 23.53.40.178
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
watson.events.data.microsoft.com
  • 52.182.143.212
  • 20.42.65.92
  • 104.208.16.94
whitelisted
self.events.data.microsoft.com
  • 104.208.16.91
whitelisted

Threats

No threats detected
No debug info