| File name: | 1 (1323) |
| Full analysis: | https://app.any.run/tasks/4d40ce78-af4e-4c2d-9192-5fa104532049 |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2025, 12:40:02 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, 3 sections |
| MD5: | BE142479B1B6DF39B6983135C9716F10 |
| SHA1: | EE2C56F4AE426F22EBF776E387363800C9A6FE97 |
| SHA256: | 7D14C1BCBB39D14F4BD2527D961369315ADBF3E7053C88D8CB5A1478A409D088 |
| SSDEEP: | 6144:L7KKsPIJvDoLA5l9F4evFofk/tBQlvJGBH/WyXq2Ik/8SwjwpyAvEh/xlCN15W4a:L+BQqLA5DFzVBmhaHOyXq2jx4DxmDsR |
| .exe | | | Win32 Executable Microsoft Visual Basic 6 (90.6) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (4.9) |
| .exe | | | Generic Win/DOS Executable (2.2) |
| .exe | | | DOS Executable Generic (2.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:01:19 13:34:56+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit, No debug, Removable run from swap, Net run from swap, Uniprocessor only, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 299008 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13d4 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | UEFI |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 720 | C:\Users\admin\AppData\Local\Temp\Unicorn-1921.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-1921.exe | Unicorn-14008.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 960 | C:\Users\admin\AppData\Local\Temp\Unicorn-13333.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-13333.exe | — | Unicorn-21976.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1052 | C:\Users\admin\AppData\Local\Temp\Unicorn-32147.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-32147.exe | Unicorn-16055.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1072 | C:\Users\admin\AppData\Local\Temp\Unicorn-26449.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-26449.exe | 1 (1323).exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1180 | C:\Users\admin\AppData\Local\Temp\Unicorn-52110.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-52110.exe | 1 (1323).exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1184 | C:\Users\admin\AppData\Local\Temp\Unicorn-14378.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-14378.exe | Unicorn-48291.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1328 | C:\Users\admin\AppData\Local\Temp\Unicorn-2318.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-2318.exe | Unicorn-7258.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1388 | C:\Users\admin\AppData\Local\Temp\Unicorn-39961.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-39961.exe | Unicorn-24839.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1532 | C:\Users\admin\AppData\Local\Temp\Unicorn-16055.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-16055.exe | Unicorn-36537.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1600 | C:\Users\admin\AppData\Local\Temp\Unicorn-3473.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-3473.exe | Unicorn-61139.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1072 | Unicorn-26449.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-36537.exe | executable | |
MD5:300F8CB1DF9B512B8BC62FB89DB14573 | SHA256:A96B9BCDA651827CDD1E89C94E0261086DC82159BD1A4B78A7CEF7439D024E4D | |||
| 2320 | 1 (1323).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-26449.exe | executable | |
MD5:573B239E5F255D0A318DBA1F48B15A50 | SHA256:C1023C32CBFA3D53A4A7CC622A4B7B0AD712E8B8E3448062758CC44DB0CC28C3 | |||
| 1532 | Unicorn-16055.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-32147.exe | executable | |
MD5:06E5681B613A7CEC3FCEDBEA8357343E | SHA256:0649B4B09A83C9557E05F1C86B4D1574E26F0BE91E8F5CADA7B1C385483FE8C2 | |||
| 5608 | Unicorn-7258.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-2318.exe | executable | |
MD5:47D9A5CD3C01F619B2A8873E93AA3EFD | SHA256:DD9E7DAC63CFB8FBCB993C35D7B0C8777B10834509846C91663EE4F254A00756 | |||
| 1672 | Unicorn-24839.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-39961.exe | executable | |
MD5:F5C4C3D65A497A22B82C8E9200C85B0C | SHA256:BAD4E0A8BA224BA5C55DAB40C8CADFE51F92D6D8BC14129AB581F3DA342A6FAF | |||
| 2320 | 1 (1323).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-52110.exe | executable | |
MD5:C8863D8DE0677A07E278DFA043808E24 | SHA256:CDDE53991A05B01475D217E8D3EC5B260D0A265E5D7900AE229BED52F1E86E39 | |||
| 5548 | Unicorn-36537.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-57014.exe | executable | |
MD5:BABD0645D1561F15F8FB6F65B255D566 | SHA256:AC50F3FF3D68E4B5214F0AA3191313129468BD39AAB2F4C8E63AEF69FB04F4EC | |||
| 1052 | Unicorn-32147.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-62811.exe | executable | |
MD5:D150657EC49EDE11E653BDEEE7147F4C | SHA256:809E8C88F99CD6238A8E4094B5F09767674C0609CCA69D364C1E75B394BCCD98 | |||
| 1072 | Unicorn-26449.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-38077.exe | executable | |
MD5:87FE07A337A2A08633BAD1DB3836529D | SHA256:F9939BD65A6A05F06C5585E379288D190C9C972A7224398CF4BE908A70EB9683 | |||
| 6156 | Unicorn-44762.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-33839.exe | executable | |
MD5:3875B0A2047CAE347BC475B32D744E8F | SHA256:2EF0E13ABEA2338785DCE9ECCC0F86001045D6B3E74A96B99065D34A6157E48B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6544 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
4724 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.16.164.106:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
720 | SIHClient.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
720 | SIHClient.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.16.164.106:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
— | — | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2104 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2112 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3216 | svchost.exe | 40.115.3.253:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 40.126.32.140:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
4724 | backgroundTaskHost.exe | 20.223.35.26:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |