| File name: | 1 (608) |
| Full analysis: | https://app.any.run/tasks/aac44fb8-5141-4ab6-859b-3ea46ede3af4 |
| Verdict: | Malicious activity |
| Analysis date: | March 25, 2025, 02:51:25 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, 3 sections |
| MD5: | 54E856E1CCE0238147FD60D8C39DCC00 |
| SHA1: | 6716AAB9A74307ABAFE308618400A80523325B33 |
| SHA256: | 7137D7B3B1C68F55DCF2DBF401FFE424B8E4ED8F9475D3A05B332B26EE04E13D |
| SSDEEP: | 6144:PTKg4VHJoDoWA5l66he/Rafx5tBwcvJGBc/WyeO/gk/8SwjwpyAvEhIReqTnsPsa:PWJxBWA5E6giBDhacOyeO/xx4DxmDsR |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:01:19 13:34:56+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit, No debug, Removable run from swap, Net run from swap, Uniprocessor only, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 299008 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13d4 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | UEFI |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 516 | C:\Users\admin\AppData\Local\Temp\Unicorn-41579.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-41579.exe | Unicorn-58275.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 632 | C:\Users\admin\AppData\Local\Temp\Unicorn-898.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-898.exe | — | Unicorn-5954.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 | |||||||||||||||
| 644 | C:\Users\admin\AppData\Local\Temp\Unicorn-17682.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-17682.exe | Unicorn-41579.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 672 | C:\Users\admin\AppData\Local\Temp\Unicorn-49330.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-49330.exe | Unicorn-24923.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 856 | C:\Users\admin\AppData\Local\Temp\Unicorn-19483.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-19483.exe | Unicorn-16642.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 896 | C:\Users\admin\AppData\Local\Temp\Unicorn-42098.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-42098.exe | Unicorn-41145.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 960 | C:\Users\admin\AppData\Local\Temp\Unicorn-24923.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-24923.exe | 1 (608).exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1040 | C:\Users\admin\AppData\Local\Temp\Unicorn-63180.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-63180.exe | — | Unicorn-51123.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 | |||||||||||||||
| 1088 | C:\Users\admin\AppData\Local\Temp\Unicorn-9563.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-9563.exe | — | Unicorn-11736.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 | |||||||||||||||
| 1568 | C:\Users\admin\AppData\Local\Temp\Unicorn-19941.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-19941.exe | Unicorn-64841.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6268 | 1 (608).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-58275.exe | executable | |
MD5:01286BE0FB0DE975A0A6EC072142076D | SHA256:721677522C36D353964072705C4F2D546A69A252CF501A6C4462677392349B11 | |||
| 4336 | Unicorn-16642.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-13185.exe | executable | |
MD5:7709885FFD71A3F8C08A0A46560DF6C3 | SHA256:BCFCBAFDB90880F12713E7A4E3EEA0A79275966C1D9AD977D9990822B5BDCF57 | |||
| 5116 | Unicorn-32994.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-25243.exe | executable | |
MD5:EAE354844837C040B41B8905E8C477FC | SHA256:A525F8D1AAB477344C872478D1EA8A34C2D6B5BF78AA75418AFDF693B7FEF223 | |||
| 4336 | Unicorn-16642.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-45904.exe | executable | |
MD5:69AFAF6DAD1A8906329F5B35C489D78C | SHA256:7FC0D56829ADF230605277ED4CB8B2429FBCB64F26DE9B2605FD5CCEF9E415C8 | |||
| 6268 | 1 (608).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-24923.exe | executable | |
MD5:190848443B497DAFC4ED7091E41760D6 | SHA256:036432AD1B40B46E0B52352F1F52635FC87AA1AE7EE07A5B0A3DDDDE80B4F6AE | |||
| 960 | Unicorn-24923.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-49330.exe | executable | |
MD5:D30E09E3CA22430D0396F96A39F291B6 | SHA256:6711B718605370CFDEF2FD7AA89A58B0E37ECA7A98500EE9A240A2A77AE767C5 | |||
| 6808 | Unicorn-13185.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-32994.exe | executable | |
MD5:830F2095CED79B5975BAF88392DB011A | SHA256:14E7C0F471A2D41658F1792C9079C630FFF09A06C689D3CFDFF8D9873FC6BBDD | |||
| 6268 | 1 (608).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-16642.exe | executable | |
MD5:ED6FF9D733C24EEBB6201CE139284B3C | SHA256:55F90C79412C7FA7AF5B4321EB1D090E1FA788DE08193C650717E941F6F4FBEC | |||
| 5640 | Unicorn-61068.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-49154.exe | executable | |
MD5:AE92A145C41D5EA520D4EFA0FC4E6ABB | SHA256:142D00DDE170C326A54A865A196C5ACE63CB44949E0B4E75618A57A5B6F897E7 | |||
| 5892 | Unicorn-58275.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-32818.exe | executable | |
MD5:243D88ABA737EF644D077DAA6987711F | SHA256:71F67BD764C6475CA4E7CAEF846099474B86E0172A661A73BA835DFFC0BDFD46 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 2.16.164.72:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5404 | backgroundTaskHost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
8256 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
8256 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 2.16.164.72:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
2104 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 20.190.159.23:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6544 | svchost.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
3216 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5404 | backgroundTaskHost.exe | 20.31.169.57:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |