| File name: | 1 (1164) |
| Full analysis: | https://app.any.run/tasks/01155c05-5f37-4e3f-87c5-e7ec916fe401 |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2025, 08:14:36 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, 3 sections |
| MD5: | 008019203639F9C839CEB013D4CF1660 |
| SHA1: | B0648AB412269F0236B2B7F4B9C1DF68DE5B00AC |
| SHA256: | 8B721CBD50439F9B0721814CD1BDC0CE37670B4211AD62FABD74015B8086AFF8 |
| SSDEEP: | 6144:NwK5tNIPkDvHA5dE40evtofxotB1lvJGBq//yeOCZk/8SwjwpyA4Eh2/0h4JGCgN:N9vecHA5W43nBHhaq3yeOCQx4QxmDsR |
| .exe | | | Win32 Executable Microsoft Visual Basic 6 (90.6) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (4.9) |
| .exe | | | Generic Win/DOS Executable (2.2) |
| .exe | | | DOS Executable Generic (2.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:01:19 13:34:56+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit, No debug, Removable run from swap, Net run from swap, Uniprocessor only, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 299008 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13d4 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | UEFI |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 616 | C:\Users\admin\AppData\Local\Temp\Unicorn-64864.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-64864.exe | — | Unicorn-2681.exe | |||||||||||
User: admin Integrity Level: MEDIUM | |||||||||||||||
| 664 | C:\Users\admin\AppData\Local\Temp\Unicorn-52741.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-52741.exe | — | Unicorn-16299.exe | |||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 684 | C:\Users\admin\AppData\Local\Temp\Unicorn-24411.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-24411.exe | — | Unicorn-3184.exe | |||||||||||
User: admin Integrity Level: MEDIUM | |||||||||||||||
| 780 | C:\Users\admin\AppData\Local\Temp\Unicorn-37832.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-37832.exe | Unicorn-48431.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 904 | C:\Users\admin\AppData\Local\Temp\Unicorn-47496.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-47496.exe | Unicorn-16299.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 1004 | C:\Users\admin\AppData\Local\Temp\Unicorn-44188.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-44188.exe | — | Unicorn-39384.exe | |||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 1012 | C:\Users\admin\AppData\Local\Temp\Unicorn-4424.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-4424.exe | Unicorn-44393.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 1052 | C:\Users\admin\AppData\Local\Temp\Unicorn-2016.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-2016.exe | Unicorn-14143.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 1056 | C:\Users\admin\AppData\Local\Temp\Unicorn-39903.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-39903.exe | Unicorn-9247.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 1128 | C:\Users\admin\AppData\Local\Temp\Unicorn-56531.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-56531.exe | Unicorn-52561.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7456 | Unicorn-35376.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-45760.exe | executable | |
MD5:DA92350B6AC1EEC3E738A5E99500F4EA | SHA256:4AABCF8646DDB5CDE19226BFA6D5F72BB7699DEE583F0CEEF4A04680340D7848 | |||
| 5680 | 1 (1164).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-62027.exe | executable | |
MD5:59569FAE6A0A241089F7A6312DEFEDA1 | SHA256:605953B7432C9E34384AFDFE1DAFB5197A8A5A986B92EDE0E8C90C12EBE8D0F3 | |||
| 5680 | 1 (1164).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-42422.exe | executable | |
MD5:13D5B11EA236716E6003DA96F8BB0CF0 | SHA256:6D12F05C1EF4EA93CFA1B71BEEB36F09FF2055968E8E543C4EABFA43143F7FFB | |||
| 7456 | Unicorn-35376.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-48292.exe | executable | |
MD5:07F3774B3A242E8CAB4737592C394B52 | SHA256:EE1B0613D9C316A8BEDA29654A9F721A36AE2B42B5EB921622AB5D82CCFF2A43 | |||
| 7760 | Unicorn-45760.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-17888.exe | executable | |
MD5:100068105B8A9DF0889F36CB28900AA8 | SHA256:BD1A613D2BB6DB30809FC2C5730E0B793B8953A240B93FA235F1CCADB4BC6F06 | |||
| 7792 | Unicorn-17888.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-52488.exe | executable | |
MD5:420E8BB39682E8600051247504CFDBB7 | SHA256:E952E18202D132F52772412092C572762393EB9C12193E44AE3CE14EA3069581 | |||
| 7872 | Unicorn-51432.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-39489.exe | executable | |
MD5:A8FA53F1AA1FACDC4CD5112E24A45CF6 | SHA256:BE9E970FDAC0A0C2585D902502EDCA2744EAE6C47A7BCC943714D33352029C91 | |||
| 7888 | Unicorn-16299.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-17289.exe | executable | |
MD5:D01854E92B11D3BBC1F774DFAA3FC9C3 | SHA256:88F47F345EE539BCB29DF5F1EC159CCDBA71F76EB39936182D589D4649A7579E | |||
| 7904 | Unicorn-9247.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-25649.exe | executable | |
MD5:E5C7BB0D7AAFFBD4AE9AC8E99B4345D2 | SHA256:EFD6A7A8B55187EE6D6FEF4A440D0832FB84E3DA0E2E51F9F91D6DC942749345 | |||
| 5680 | 1 (1164).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-35376.exe | executable | |
MD5:CEDBE7ACFC337ACD8F96144FA4A2EDA5 | SHA256:8B29AE480AA406FE4D7DC69459F453EECE580ADEE37AB78DBDF8EE8BFF5F050E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6544 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7492 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.16.164.81:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5084 | SIHClient.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
5084 | SIHClient.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.16.164.81:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2104 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3216 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 40.126.32.140:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
7492 | backgroundTaskHost.exe | 20.223.35.26:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
7492 | backgroundTaskHost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |