| File name: | 1 (318) |
| Full analysis: | https://app.any.run/tasks/c34d0489-7571-47da-a1e6-908909bbd090 |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2025, 21:12:21 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections |
| MD5: | 6E9AA09E3149991E768B72F5064001B0 |
| SHA1: | FCBA795E99964BCE759B0203DE8D07ADE76ED083 |
| SHA256: | 76FBC6C061A18FEBB4625FFDE80906C45B892FDB015F5D4D98CE5F4DAC23553F |
| SSDEEP: | 6144:YniV9RI7ADVLI5c9VMG/2rfx5t3qlp8GBV/SyIDsRk/8SwjwpyAvEhpLLzE6sPla:YiDC0LI56Vdq3M+aV6yIDsax4DxmDsR |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:01:19 13:36:00+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 299008 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13d4 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | UEFI |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 516 | C:\Users\admin\AppData\Local\Temp\Unicorn-53625.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-53625.exe | 1 (318).exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 672 | C:\Users\admin\AppData\Local\Temp\Unicorn-54933.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-54933.exe | Unicorn-35198.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 856 | C:\Users\admin\AppData\Local\Temp\Unicorn-35198.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-35198.exe | Unicorn-41638.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 896 | C:\Users\admin\AppData\Local\Temp\Unicorn-56516.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-56516.exe | Unicorn-56962.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1040 | C:\Users\admin\AppData\Local\Temp\Unicorn-61264.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-61264.exe | Unicorn-27994.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1052 | C:\Users\admin\AppData\Local\Temp\Unicorn-9739.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-9739.exe | 1 (318).exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1096 | C:\Users\admin\AppData\Local\Temp\Unicorn-48498.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-48498.exe | Unicorn-31441.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1228 | C:\Users\admin\AppData\Local\Temp\Unicorn-29944.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-29944.exe | Unicorn-54471.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1272 | C:\Users\admin\AppData\Local\Temp\Unicorn-7381.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-7381.exe | Unicorn-46874.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1300 | C:\Users\admin\AppData\Local\Temp\Unicorn-31441.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-31441.exe | Unicorn-2001.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2320 | 1 (318).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-3900.exe | executable | |
MD5:C5A54D1EAACE24A16918283186D81302 | SHA256:FDCBF6C8AD3CFE0633EA9614907E7F5EECE2C6CA5B19F883CE32B99B8F4A636A | |||
| 5504 | Unicorn-3900.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-2001.exe | executable | |
MD5:F2968297D78213AB9558FD076417674D | SHA256:2A59D518F356A054ACC4D4423C8ADC48841A41242FFFDF7763C9EF9E4C8F805A | |||
| 2320 | 1 (318).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-54471.exe | executable | |
MD5:18FEA46DFB7AAAD9AEF30712B12E9497 | SHA256:9591722F489046A39D09B7D359AB0B7348F0DED08A1F4681DFE39B8B7E49AB27 | |||
| 5504 | Unicorn-3900.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-697.exe | executable | |
MD5:F41607652C2FE91F758474A0EBF7BBC9 | SHA256:EC542224D08E13C15B751F1B5F840113EFD74C9FC3E5F255E9FA6482153A306B | |||
| 3304 | Unicorn-54471.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-34024.exe | executable | |
MD5:7D4D84CA7C249912C7EC739701AC032C | SHA256:B9180EC5267C15FB2F3919929260A387DAB452C18BBEF63A1F61D8FB128334C4 | |||
| 3304 | Unicorn-54471.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-36594.exe | executable | |
MD5:44618703145287A2932654C09278D1A5 | SHA256:25816421D3F61983A87444A999C0C5857E91539D64FC4DE189A9B1CA5ACF859E | |||
| 3784 | Unicorn-2001.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-31441.exe | executable | |
MD5:389D643EED7B2577197876303266380C | SHA256:AB54FA7807991106A413BC999AC0D6BF38D416A745D22C6F071C01C9E08FCC17 | |||
| 5504 | Unicorn-3900.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-35202.exe | executable | |
MD5:E791200793107419677AFEFD5A078600 | SHA256:E4C2AC01AD4454D2D76AF3A13EC32D9136407583E76AE3B5449BBC3BF36D0C88 | |||
| 2320 | 1 (318).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-30463.exe | executable | |
MD5:A8F3858BFBF0C60547C975B411B1E6F7 | SHA256:0F283770D71D1128A238EA90449433A3EF6C86AF8798D42EB7786E42186BC268 | |||
| 3784 | Unicorn-2001.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-27994.exe | executable | |
MD5:2FD244A041D371836679B81B3515AF33 | SHA256:DEE6AF9F45202848C74A647897BC90521C22E333E3708EC8BFFDBB5DA6EA13CB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5328 | backgroundTaskHost.exe | GET | 200 | 23.54.109.203:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | unknown |
9020 | SIHClient.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | unknown |
— | — | GET | 200 | 23.48.23.177:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
6544 | svchost.exe | GET | 200 | 23.54.109.203:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | unknown |
9020 | SIHClient.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | unknown |
6544 | svchost.exe | GET | 200 | 23.54.109.203:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
— | — | 23.48.23.177:80 | crl.microsoft.com | Akamai International B.V. | DE | unknown |
5496 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
2104 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3216 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
6544 | svchost.exe | 40.126.31.69:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
6544 | svchost.exe | 23.54.109.203:80 | ocsp.digicert.com | AKAMAI-AS | DE | unknown |
5328 | backgroundTaskHost.exe | 20.74.47.205:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| unknown |
settings-win.data.microsoft.com |
| unknown |
crl.microsoft.com |
| unknown |
client.wns.windows.com |
| unknown |
login.live.com |
| unknown |
ocsp.digicert.com |
| unknown |
arc.msn.com |
| unknown |
slscr.update.microsoft.com |
| unknown |
www.microsoft.com |
| unknown |
fe3cr.delivery.mp.microsoft.com |
| unknown |