File name:

1 (14)

Full analysis: https://app.any.run/tasks/6411aa09-0421-4b09-8ca4-b95fc22ad46b
Verdict: Malicious activity
Analysis date: March 24, 2025, 15:09:18
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections
MD5:

0AD92CA0C34A48B71B314040A8C58E40

SHA1:

39DDBE8C62ACD529CA4AA169D2271771A007F85A

SHA256:

900B169E6BA4287832B054D105DECCC345E92DE329BA15A212AEFA0B1E54B9A7

SSDEEP:

6144:VrNgt7IqQDjHA5yt37smv1fxdpBEovJGBn/WyS9Gzk/8SwjwpyAOEhs45KKpsBWt:VRsMlHA5Y3QuBbhanOyS9GIx4DxDsR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts itself from another location

      • 1 (14).exe (PID: 6816)
      • Unicorn-56132.exe (PID: 4244)
      • Unicorn-44238.exe (PID: 5204)
      • Unicorn-24372.exe (PID: 7020)
      • Unicorn-31130.exe (PID: 3020)
      • Unicorn-31130.exe (PID: 6540)
      • Unicorn-19432.exe (PID: 4868)
      • Unicorn-33167.exe (PID: 1132)
      • Unicorn-45878.exe (PID: 5280)
      • Unicorn-11295.exe (PID: 5384)
      • Unicorn-5430.exe (PID: 720)
      • Unicorn-36641.exe (PID: 1388)
      • Unicorn-36641.exe (PID: 632)
      • Unicorn-16775.exe (PID: 4380)
      • Unicorn-24446.exe (PID: 2552)
      • Unicorn-53589.exe (PID: 5964)
      • Unicorn-45878.exe (PID: 728)
      • Unicorn-29084.exe (PID: 2040)
      • Unicorn-3257.exe (PID: 1228)
      • Unicorn-64710.exe (PID: 1184)
      • Unicorn-39444.exe (PID: 5776)
      • Unicorn-7341.exe (PID: 300)
      • Unicorn-48374.exe (PID: 6708)
      • Unicorn-11425.exe (PID: 2692)
      • Unicorn-50412.exe (PID: 7180)
      • Unicorn-36676.exe (PID: 6344)
      • Unicorn-16775.exe (PID: 3332)
      • Unicorn-36676.exe (PID: 5256)
      • Unicorn-9801.exe (PID: 7312)
      • Unicorn-42151.exe (PID: 7328)
      • Unicorn-43735.exe (PID: 7344)
      • Unicorn-12878.exe (PID: 7292)
      • Unicorn-35458.exe (PID: 7392)
      • Unicorn-14937.exe (PID: 7408)
      • Unicorn-14653.exe (PID: 7428)
      • Unicorn-47911.exe (PID: 7364)
      • Unicorn-23376.exe (PID: 7444)
      • Unicorn-50412.exe (PID: 6228)
      • Unicorn-43434.exe (PID: 7468)
      • Unicorn-36226.exe (PID: 7512)
      • Unicorn-11425.exe (PID: 6108)
      • Unicorn-36226.exe (PID: 7504)
      • Unicorn-23974.exe (PID: 7496)
      • Unicorn-15806.exe (PID: 7572)
      • Unicorn-8192.exe (PID: 7488)
      • Unicorn-23901.exe (PID: 7712)
      • Unicorn-31180.exe (PID: 7592)
      • Unicorn-44949.exe (PID: 7620)
      • Unicorn-28612.exe (PID: 7684)
      • Unicorn-5783.exe (PID: 7736)
      • Unicorn-23901.exe (PID: 7704)
      • Unicorn-56646.exe (PID: 7608)
      • Unicorn-39548.exe (PID: 7668)
      • Unicorn-64814.exe (PID: 7628)
      • Unicorn-50023.exe (PID: 7824)
      • Unicorn-57222.exe (PID: 7844)
      • Unicorn-9728.exe (PID: 7872)
      • Unicorn-11211.exe (PID: 7884)
      • Unicorn-18035.exe (PID: 7696)
      • Unicorn-32526.exe (PID: 7808)
      • Unicorn-37113.exe (PID: 7980)
      • Unicorn-42038.exe (PID: 7924)
      • Unicorn-56646.exe (PID: 7600)
      • Unicorn-20444.exe (PID: 7676)
      • Unicorn-45281.exe (PID: 8028)
      • Unicorn-30340.exe (PID: 7932)
      • Unicorn-50206.exe (PID: 7944)
      • Unicorn-57798.exe (PID: 8008)
      • Unicorn-16958.exe (PID: 8000)
      • Unicorn-50185.exe (PID: 8040)
      • Unicorn-45738.exe (PID: 8104)
      • Unicorn-51337.exe (PID: 8172)
      • Unicorn-38124.exe (PID: 8096)
      • Unicorn-43692.exe (PID: 8124)
      • Unicorn-17150.exe (PID: 8088)
      • Unicorn-43168.exe (PID: 8164)
      • Unicorn-44652.exe (PID: 6988)
      • Unicorn-48081.exe (PID: 7000)
      • Unicorn-35274.exe (PID: 2340)
      • Unicorn-47142.exe (PID: 2644)
      • Unicorn-47697.exe (PID: 4180)
      • Unicorn-35082.exe (PID: 8212)
      • Unicorn-38974.exe (PID: 7864)
      • Unicorn-32142.exe (PID: 7544)
      • Unicorn-6109.exe (PID: 8200)
      • Unicorn-30889.exe (PID: 8272)
      • Unicorn-56654.exe (PID: 8332)
      • Unicorn-35636.exe (PID: 4980)
      • Unicorn-30889.exe (PID: 8264)
      • Unicorn-7816.exe (PID: 8340)
      • Unicorn-32704.exe (PID: 8316)
      • Unicorn-60162.exe (PID: 8416)
      • Unicorn-43805.exe (PID: 8256)
      • Unicorn-48102.exe (PID: 8528)
      • Unicorn-56270.exe (PID: 8568)
      • Unicorn-48102.exe (PID: 8512)
      • Unicorn-39742.exe (PID: 8432)
      • Unicorn-46440.exe (PID: 8324)
      • Unicorn-56422.exe (PID: 8388)
      • Unicorn-60162.exe (PID: 8424)
      • Unicorn-7816.exe (PID: 8308)
      • Unicorn-56277.exe (PID: 1764)
      • Unicorn-48102.exe (PID: 8520)
      • Unicorn-39669.exe (PID: 8596)
      • Unicorn-10391.exe (PID: 8604)
      • Unicorn-43826.exe (PID: 8444)
      • Unicorn-58308.exe (PID: 8620)
      • Unicorn-48300.exe (PID: 8668)
      • Unicorn-62392.exe (PID: 8612)
      • Unicorn-45947.exe (PID: 8712)
      • Unicorn-62061.exe (PID: 8772)
      • Unicorn-7452.exe (PID: 8744)
      • Unicorn-13052.exe (PID: 8752)
      • Unicorn-17136.exe (PID: 8736)
      • Unicorn-56965.exe (PID: 8660)
      • Unicorn-61433.exe (PID: 8840)
      • Unicorn-45938.exe (PID: 8804)
      • Unicorn-245.exe (PID: 8864)
      • Unicorn-18227.exe (PID: 8812)
      • Unicorn-38346.exe (PID: 8904)
      • Unicorn-45917.exe (PID: 8856)
      • Unicorn-36871.exe (PID: 8892)
      • Unicorn-5652.exe (PID: 8996)
      • Unicorn-27747.exe (PID: 8952)
      • Unicorn-46514.exe (PID: 8912)
      • Unicorn-46322.exe (PID: 9040)
      • Unicorn-14204.exe (PID: 9028)
      • Unicorn-136.exe (PID: 9072)
      • Unicorn-14204.exe (PID: 9024)
      • Unicorn-41781.exe (PID: 8980)
      • Unicorn-26670.exe (PID: 9096)
      • Unicorn-55066.exe (PID: 9152)
      • Unicorn-63048.exe (PID: 9124)
      • Unicorn-35200.exe (PID: 9144)
      • Unicorn-55066.exe (PID: 9160)
      • Unicorn-53212.exe (PID: 9200)
      • Unicorn-47090.exe (PID: 904)
      • Unicorn-6612.exe (PID: 8680)
      • Unicorn-59342.exe (PID: 9208)
      • Unicorn-19270.exe (PID: 9120)
      • Unicorn-36021.exe (PID: 4000)
      • Unicorn-24292.exe (PID: 9308)
      • Unicorn-48242.exe (PID: 9300)
      • Unicorn-44713.exe (PID: 9276)
      • Unicorn-38922.exe (PID: 5352)
      • Unicorn-35606.exe (PID: 9356)
      • Unicorn-31330.exe (PID: 9372)
      • Unicorn-8863.exe (PID: 9392)
      • Unicorn-32025.exe (PID: 9412)
      • Unicorn-53094.exe (PID: 9436)
      • Unicorn-49010.exe (PID: 9456)
      • Unicorn-32652.exe (PID: 9496)
      • Unicorn-16146.exe (PID: 9472)
      • Unicorn-32652.exe (PID: 9488)
      • Unicorn-17607.exe (PID: 9520)
      • Unicorn-23665.exe (PID: 9564)
    • Executable content was dropped or overwritten

      • 1 (14).exe (PID: 6816)
      • Unicorn-19432.exe (PID: 4868)
      • Unicorn-31130.exe (PID: 3020)
      • Unicorn-56132.exe (PID: 4244)
      • Unicorn-24372.exe (PID: 7020)
      • Unicorn-31130.exe (PID: 6540)
      • Unicorn-11295.exe (PID: 5384)
      • Unicorn-5430.exe (PID: 720)
      • Unicorn-45878.exe (PID: 728)
      • Unicorn-16775.exe (PID: 4380)
      • Unicorn-36641.exe (PID: 632)
      • Unicorn-44238.exe (PID: 5204)
      • Unicorn-33167.exe (PID: 1132)
      • Unicorn-16775.exe (PID: 3332)
      • Unicorn-24446.exe (PID: 2552)
      • Unicorn-45878.exe (PID: 5280)
      • Unicorn-53589.exe (PID: 5964)
      • Unicorn-29084.exe (PID: 2040)
      • Unicorn-64710.exe (PID: 1184)
      • Unicorn-3257.exe (PID: 1228)
      • Unicorn-39444.exe (PID: 5776)
      • Unicorn-11425.exe (PID: 6108)
      • Unicorn-48374.exe (PID: 6708)
      • Unicorn-50412.exe (PID: 6228)
      • Unicorn-56277.exe (PID: 1764)
      • Unicorn-12878.exe (PID: 7292)
      • Unicorn-36676.exe (PID: 6344)
      • Unicorn-42151.exe (PID: 7328)
      • Unicorn-43735.exe (PID: 7344)
      • Unicorn-47911.exe (PID: 7364)
      • Unicorn-9801.exe (PID: 7312)
      • Unicorn-35458.exe (PID: 7392)
      • Unicorn-14937.exe (PID: 7408)
      • Unicorn-14653.exe (PID: 7428)
      • Unicorn-23376.exe (PID: 7444)
      • Unicorn-36641.exe (PID: 1388)
      • Unicorn-43434.exe (PID: 7468)
      • Unicorn-23974.exe (PID: 7496)
      • Unicorn-36226.exe (PID: 7512)
      • Unicorn-32142.exe (PID: 7544)
      • Unicorn-36226.exe (PID: 7504)
      • Unicorn-15806.exe (PID: 7572)
      • Unicorn-7341.exe (PID: 300)
      • Unicorn-11425.exe (PID: 2692)
      • Unicorn-18035.exe (PID: 7696)
      • Unicorn-31180.exe (PID: 7592)
      • Unicorn-44949.exe (PID: 7620)
      • Unicorn-5783.exe (PID: 7736)
      • Unicorn-56646.exe (PID: 7600)
      • Unicorn-56646.exe (PID: 7608)
      • Unicorn-50412.exe (PID: 7180)
      • Unicorn-50023.exe (PID: 7824)
      • Unicorn-36676.exe (PID: 5256)
      • Unicorn-9728.exe (PID: 7872)
      • Unicorn-11211.exe (PID: 7884)
      • Unicorn-32526.exe (PID: 7808)
      • Unicorn-57222.exe (PID: 7844)
      • Unicorn-20444.exe (PID: 7676)
      • Unicorn-37113.exe (PID: 7980)
      • Unicorn-42038.exe (PID: 7924)
      • Unicorn-30340.exe (PID: 7932)
      • Unicorn-50206.exe (PID: 7944)
      • Unicorn-16958.exe (PID: 8000)
      • Unicorn-50185.exe (PID: 8040)
      • Unicorn-17150.exe (PID: 8088)
      • Unicorn-51337.exe (PID: 8172)
      • Unicorn-38124.exe (PID: 8096)
      • Unicorn-43692.exe (PID: 8124)
      • Unicorn-45738.exe (PID: 8104)
      • Unicorn-44652.exe (PID: 6988)
      • Unicorn-48081.exe (PID: 7000)
      • Unicorn-35274.exe (PID: 2340)
      • Unicorn-43168.exe (PID: 8164)
      • Unicorn-47142.exe (PID: 2644)
      • Unicorn-6109.exe (PID: 8200)
      • Unicorn-47697.exe (PID: 4180)
      • Unicorn-57798.exe (PID: 8008)
      • Unicorn-38974.exe (PID: 7864)
      • Unicorn-35636.exe (PID: 4980)
      • Unicorn-35082.exe (PID: 8212)
      • Unicorn-30889.exe (PID: 8272)
      • Unicorn-56654.exe (PID: 8332)
      • Unicorn-43805.exe (PID: 8256)
      • Unicorn-7816.exe (PID: 8340)
      • Unicorn-32704.exe (PID: 8316)
      • Unicorn-30889.exe (PID: 8264)
      • Unicorn-8192.exe (PID: 7488)
      • Unicorn-48102.exe (PID: 8512)
      • Unicorn-7816.exe (PID: 8308)
      • Unicorn-48102.exe (PID: 8528)
      • Unicorn-56270.exe (PID: 8568)
      • Unicorn-39742.exe (PID: 8432)
      • Unicorn-46440.exe (PID: 8324)
      • Unicorn-56422.exe (PID: 8388)
      • Unicorn-60162.exe (PID: 8424)
      • Unicorn-64814.exe (PID: 7628)
      • Unicorn-39548.exe (PID: 7668)
      • Unicorn-48102.exe (PID: 8520)
      • Unicorn-39669.exe (PID: 8596)
      • Unicorn-62392.exe (PID: 8612)
      • Unicorn-10391.exe (PID: 8604)
      • Unicorn-43826.exe (PID: 8444)
      • Unicorn-58308.exe (PID: 8620)
      • Unicorn-48300.exe (PID: 8668)
      • Unicorn-45947.exe (PID: 8712)
      • Unicorn-23901.exe (PID: 7704)
      • Unicorn-7452.exe (PID: 8744)
      • Unicorn-56965.exe (PID: 8660)
      • Unicorn-28612.exe (PID: 7684)
      • Unicorn-62061.exe (PID: 8772)
      • Unicorn-23901.exe (PID: 7712)
      • Unicorn-13052.exe (PID: 8752)
      • Unicorn-17136.exe (PID: 8736)
      • Unicorn-45917.exe (PID: 8856)
      • Unicorn-61433.exe (PID: 8840)
      • Unicorn-245.exe (PID: 8864)
      • Unicorn-18227.exe (PID: 8812)
      • Unicorn-38346.exe (PID: 8904)
      • Unicorn-46514.exe (PID: 8912)
      • Unicorn-5652.exe (PID: 8996)
      • Unicorn-27747.exe (PID: 8952)
      • Unicorn-41781.exe (PID: 8980)
      • Unicorn-36871.exe (PID: 8892)
      • Unicorn-46322.exe (PID: 9040)
      • Unicorn-14204.exe (PID: 9028)
      • Unicorn-136.exe (PID: 9072)
      • Unicorn-14204.exe (PID: 9024)
      • Unicorn-26670.exe (PID: 9096)
      • Unicorn-55066.exe (PID: 9152)
      • Unicorn-63048.exe (PID: 9124)
      • Unicorn-35200.exe (PID: 9144)
      • Unicorn-55066.exe (PID: 9160)
      • Unicorn-59342.exe (PID: 9208)
      • Unicorn-47090.exe (PID: 904)
      • Unicorn-19270.exe (PID: 9120)
      • Unicorn-38922.exe (PID: 5352)
      • Unicorn-53212.exe (PID: 9200)
      • Unicorn-25007.exe (PID: 9332)
      • Unicorn-36021.exe (PID: 4000)
      • Unicorn-44713.exe (PID: 9276)
      • Unicorn-24292.exe (PID: 9308)
      • Unicorn-48242.exe (PID: 9300)
      • Unicorn-31330.exe (PID: 9372)
      • Unicorn-8863.exe (PID: 9392)
      • Unicorn-32025.exe (PID: 9412)
      • Unicorn-35606.exe (PID: 9356)
      • Unicorn-32652.exe (PID: 9496)
      • Unicorn-16146.exe (PID: 9472)
      • Unicorn-32652.exe (PID: 9488)
      • Unicorn-49010.exe (PID: 9456)
      • Unicorn-53094.exe (PID: 9436)
      • Unicorn-25775.exe (PID: 9540)
      • Unicorn-23665.exe (PID: 9564)
      • Unicorn-17607.exe (PID: 9520)
      • Unicorn-35828.exe (PID: 9704)
      • Unicorn-42918.exe (PID: 9732)
      • Unicorn-9669.exe (PID: 9832)
      • Unicorn-64085.exe (PID: 9776)
      • Unicorn-15652.exe (PID: 9896)
      • Unicorn-39218.exe (PID: 9960)
      • Unicorn-35134.exe (PID: 9968)
      • Unicorn-38258.exe (PID: 9676)
      • Unicorn-55746.exe (PID: 10024)
      • Unicorn-50576.exe (PID: 10084)
      • Unicorn-36840.exe (PID: 10076)
      • Unicorn-23842.exe (PID: 10132)
      • Unicorn-3421.exe (PID: 10164)
      • Unicorn-57453.exe (PID: 10200)
      • Unicorn-40924.exe (PID: 10148)
      • Unicorn-45938.exe (PID: 8804)
      • Unicorn-3613.exe (PID: 10224)
      • Unicorn-11205.exe (PID: 6044)
      • Unicorn-27734.exe (PID: 4436)
      • Unicorn-3592.exe (PID: 5064)
      • Unicorn-52430.exe (PID: 10256)
      • Unicorn-36094.exe (PID: 10276)
      • Unicorn-36094.exe (PID: 10284)
      • Unicorn-6612.exe (PID: 8680)
      • Unicorn-65237.exe (PID: 10312)
      • Unicorn-43176.exe (PID: 10332)
      • Unicorn-21603.exe (PID: 4880)
      • Unicorn-9020.exe (PID: 10356)
      • Unicorn-12549.exe (PID: 10548)
      • Unicorn-41138.exe (PID: 10376)
      • Unicorn-63596.exe (PID: 10424)
      • Unicorn-37246.exe (PID: 10520)
      • Unicorn-13296.exe (PID: 10460)
      • Unicorn-53582.exe (PID: 10448)
      • Unicorn-41330.exe (PID: 10512)
      • Unicorn-12357.exe (PID: 10400)
      • Unicorn-16442.exe (PID: 10388)
      • Unicorn-29078.exe (PID: 10500)
      • Unicorn-22947.exe (PID: 10484)
      • Unicorn-10629.exe (PID: 10052)
      • Unicorn-57645.exe (PID: 10592)
      • Unicorn-45393.exe (PID: 10612)
      • Unicorn-61174.exe (PID: 10636)
      • Unicorn-45393.exe (PID: 10620)
      • Unicorn-49114.exe (PID: 10668)
      • Unicorn-8081.exe (PID: 10708)
      • Unicorn-48731.exe (PID: 10772)
      • Unicorn-45281.exe (PID: 8028)
      • Unicorn-41906.exe (PID: 10728)
      • Unicorn-62061.exe (PID: 10796)
      • Unicorn-9980.exe (PID: 10852)
      • Unicorn-62326.exe (PID: 10808)
      • Unicorn-25570.exe (PID: 10872)
      • Unicorn-24418.exe (PID: 10688)
      • Unicorn-31691.exe (PID: 10736)
      • Unicorn-46161.exe (PID: 10940)
      • Unicorn-20910.exe (PID: 10928)
      • Unicorn-8657.exe (PID: 10972)
      • Unicorn-58050.exe (PID: 11012)
      • Unicorn-58745.exe (PID: 11072)
      • Unicorn-4956.exe (PID: 11088)
      • Unicorn-44644.exe (PID: 10980)
      • Unicorn-13125.exe (PID: 10764)
      • Unicorn-57096.exe (PID: 10948)
      • Unicorn-4308.exe (PID: 10988)
      • Unicorn-13628.exe (PID: 11104)
      • Unicorn-22062.exe (PID: 11124)
      • Unicorn-1641.exe (PID: 11132)
      • Unicorn-36160.exe (PID: 11228)
      • Unicorn-9239.exe (PID: 11172)
      • Unicorn-36736.exe (PID: 11164)
      • Unicorn-17937.exe (PID: 11200)
      • Unicorn-46353.exe (PID: 11056)
    • Executes application which crashes

      • Unicorn-9332.exe (PID: 13632)
  • INFO

    • Checks supported languages

      • 1 (14).exe (PID: 6816)
      • Unicorn-56132.exe (PID: 4244)
      • Unicorn-24372.exe (PID: 7020)
      • Unicorn-31130.exe (PID: 6540)
      • Unicorn-33167.exe (PID: 1132)
      • Unicorn-45878.exe (PID: 5280)
      • Unicorn-44238.exe (PID: 5204)
      • Unicorn-29084.exe (PID: 2040)
      • Unicorn-3257.exe (PID: 1228)
      • Unicorn-16775.exe (PID: 3332)
      • Unicorn-11295.exe (PID: 5384)
      • Unicorn-36641.exe (PID: 632)
      • Unicorn-39444.exe (PID: 5776)
      • Unicorn-7341.exe (PID: 300)
      • Unicorn-48374.exe (PID: 6708)
      • Unicorn-50412.exe (PID: 7180)
      • Unicorn-36676.exe (PID: 6344)
      • Unicorn-14653.exe (PID: 7428)
      • Unicorn-23376.exe (PID: 7444)
      • Unicorn-8192.exe (PID: 7488)
      • Unicorn-36226.exe (PID: 7504)
      • Unicorn-32142.exe (PID: 7544)
      • Unicorn-44949.exe (PID: 7620)
      • Unicorn-64814.exe (PID: 7628)
      • Unicorn-23901.exe (PID: 7712)
      • Unicorn-5783.exe (PID: 7736)
      • Unicorn-23901.exe (PID: 7704)
      • Unicorn-57222.exe (PID: 7844)
      • Unicorn-20444.exe (PID: 7676)
      • Unicorn-37113.exe (PID: 7980)
      • Unicorn-38124.exe (PID: 8096)
      • Unicorn-44652.exe (PID: 6988)
      • Unicorn-47697.exe (PID: 4180)
      • Unicorn-35082.exe (PID: 8212)
      • Unicorn-43805.exe (PID: 8256)
      • Unicorn-39742.exe (PID: 8432)
      • Unicorn-46440.exe (PID: 8324)
      • Unicorn-48102.exe (PID: 8528)
      • Unicorn-43826.exe (PID: 8444)
      • Unicorn-39669.exe (PID: 8596)
      • Unicorn-45947.exe (PID: 8712)
      • Unicorn-36871.exe (PID: 8892)
      • Unicorn-27747.exe (PID: 8952)
      • Unicorn-245.exe (PID: 8864)
      • Unicorn-14204.exe (PID: 9028)
      • Unicorn-6612.exe (PID: 8680)
      • Unicorn-25007.exe (PID: 9332)
      • Unicorn-16146.exe (PID: 9472)
      • Unicorn-9669.exe (PID: 9832)
      • Unicorn-42918.exe (PID: 9732)
      • Unicorn-10629.exe (PID: 10052)
      • Unicorn-50576.exe (PID: 10084)
      • Unicorn-36840.exe (PID: 10076)
      • Unicorn-23842.exe (PID: 10132)
      • Unicorn-3421.exe (PID: 10164)
      • Unicorn-36094.exe (PID: 10276)
      • Unicorn-21603.exe (PID: 4880)
      • Unicorn-29078.exe (PID: 10500)
      • Unicorn-13296.exe (PID: 10460)
      • Unicorn-37246.exe (PID: 10520)
      • Unicorn-57645.exe (PID: 10592)
      • Unicorn-49114.exe (PID: 10668)
      • Unicorn-45393.exe (PID: 10620)
      • Unicorn-24418.exe (PID: 10688)
      • Unicorn-31691.exe (PID: 10736)
      • Unicorn-62061.exe (PID: 10796)
      • Unicorn-9980.exe (PID: 10852)
      • Unicorn-20910.exe (PID: 10928)
      • Unicorn-8657.exe (PID: 10972)
      • Unicorn-58050.exe (PID: 11012)
      • Unicorn-36160.exe (PID: 11228)
      • Unicorn-36736.exe (PID: 11164)
      • Unicorn-7012.exe (PID: 11452)
      • Unicorn-12269.exe (PID: 11776)
      • Unicorn-23453.exe (PID: 11640)
      • Unicorn-3644.exe (PID: 11672)
      • Unicorn-34919.exe (PID: 11708)
      • Unicorn-38258.exe (PID: 9676)
      • Unicorn-45113.exe (PID: 11872)
      • Unicorn-22829.exe (PID: 11944)
      • Unicorn-12845.exe (PID: 11968)
      • Unicorn-62793.exe (PID: 12072)
      • Unicorn-4293.exe (PID: 12232)
      • Unicorn-6523.exe (PID: 5084)
      • Unicorn-50562.exe (PID: 12308)
      • Unicorn-50562.exe (PID: 12316)
      • Unicorn-54023.exe (PID: 12536)
      • Unicorn-12335.exe (PID: 12580)
      • Unicorn-11833.exe (PID: 12932)
      • Unicorn-36146.exe (PID: 13040)
      • Unicorn-21694.exe (PID: 4012)
      • Unicorn-55113.exe (PID: 4212)
      • Unicorn-27947.exe (PID: 13204)
      • Unicorn-51168.exe (PID: 13240)
      • Unicorn-41548.exe (PID: 13556)
      • Unicorn-35268.exe (PID: 13596)
      • Unicorn-49004.exe (PID: 13608)
      • Unicorn-31376.exe (PID: 13640)
      • Unicorn-19700.exe (PID: 13916)
      • Unicorn-9586.exe (PID: 14036)
      • Unicorn-40750.exe (PID: 14224)
      • Unicorn-15060.exe (PID: 14360)
      • Unicorn-15259.exe (PID: 14416)
      • Unicorn-12108.exe (PID: 14592)
      • Unicorn-52129.exe (PID: 14656)
    • The sample compiled with chinese language support

      • 1 (14).exe (PID: 6816)
      • Unicorn-56132.exe (PID: 4244)
      • Unicorn-24372.exe (PID: 7020)
      • Unicorn-31130.exe (PID: 3020)
      • Unicorn-19432.exe (PID: 4868)
      • Unicorn-31130.exe (PID: 6540)
      • Unicorn-11295.exe (PID: 5384)
      • Unicorn-5430.exe (PID: 720)
      • Unicorn-16775.exe (PID: 3332)
      • Unicorn-36641.exe (PID: 632)
      • Unicorn-33167.exe (PID: 1132)
      • Unicorn-44238.exe (PID: 5204)
      • Unicorn-16775.exe (PID: 4380)
      • Unicorn-24446.exe (PID: 2552)
      • Unicorn-45878.exe (PID: 5280)
      • Unicorn-53589.exe (PID: 5964)
      • Unicorn-45878.exe (PID: 728)
      • Unicorn-64710.exe (PID: 1184)
      • Unicorn-3257.exe (PID: 1228)
      • Unicorn-39444.exe (PID: 5776)
      • Unicorn-11425.exe (PID: 6108)
      • Unicorn-48374.exe (PID: 6708)
      • Unicorn-56277.exe (PID: 1764)
      • Unicorn-50412.exe (PID: 6228)
      • Unicorn-36676.exe (PID: 6344)
      • Unicorn-12878.exe (PID: 7292)
      • Unicorn-9801.exe (PID: 7312)
      • Unicorn-42151.exe (PID: 7328)
      • Unicorn-43735.exe (PID: 7344)
      • Unicorn-35458.exe (PID: 7392)
      • Unicorn-14937.exe (PID: 7408)
      • Unicorn-29084.exe (PID: 2040)
      • Unicorn-14653.exe (PID: 7428)
      • Unicorn-47911.exe (PID: 7364)
      • Unicorn-36641.exe (PID: 1388)
      • Unicorn-43434.exe (PID: 7468)
      • Unicorn-23376.exe (PID: 7444)
      • Unicorn-23974.exe (PID: 7496)
      • Unicorn-32142.exe (PID: 7544)
      • Unicorn-36226.exe (PID: 7512)
      • Unicorn-36226.exe (PID: 7504)
      • Unicorn-7341.exe (PID: 300)
      • Unicorn-11425.exe (PID: 2692)
      • Unicorn-15806.exe (PID: 7572)
      • Unicorn-5783.exe (PID: 7736)
      • Unicorn-18035.exe (PID: 7696)
      • Unicorn-31180.exe (PID: 7592)
      • Unicorn-44949.exe (PID: 7620)
      • Unicorn-56646.exe (PID: 7600)
      • Unicorn-56646.exe (PID: 7608)
      • Unicorn-50412.exe (PID: 7180)
      • Unicorn-50023.exe (PID: 7824)
      • Unicorn-36676.exe (PID: 5256)
      • Unicorn-57222.exe (PID: 7844)
      • Unicorn-9728.exe (PID: 7872)
      • Unicorn-11211.exe (PID: 7884)
      • Unicorn-32526.exe (PID: 7808)
      • Unicorn-20444.exe (PID: 7676)
      • Unicorn-37113.exe (PID: 7980)
      • Unicorn-42038.exe (PID: 7924)
      • Unicorn-30340.exe (PID: 7932)
      • Unicorn-50206.exe (PID: 7944)
      • Unicorn-57798.exe (PID: 8008)
      • Unicorn-16958.exe (PID: 8000)
      • Unicorn-50185.exe (PID: 8040)
      • Unicorn-45738.exe (PID: 8104)
      • Unicorn-17150.exe (PID: 8088)
      • Unicorn-51337.exe (PID: 8172)
      • Unicorn-38124.exe (PID: 8096)
      • Unicorn-43692.exe (PID: 8124)
      • Unicorn-43168.exe (PID: 8164)
      • Unicorn-44652.exe (PID: 6988)
      • Unicorn-48081.exe (PID: 7000)
      • Unicorn-35274.exe (PID: 2340)
      • Unicorn-47142.exe (PID: 2644)
      • Unicorn-47697.exe (PID: 4180)
      • Unicorn-6109.exe (PID: 8200)
      • Unicorn-35082.exe (PID: 8212)
      • Unicorn-38974.exe (PID: 7864)
      • Unicorn-30889.exe (PID: 8272)
      • Unicorn-56654.exe (PID: 8332)
      • Unicorn-35636.exe (PID: 4980)
      • Unicorn-43805.exe (PID: 8256)
      • Unicorn-30889.exe (PID: 8264)
      • Unicorn-7816.exe (PID: 8340)
      • Unicorn-32704.exe (PID: 8316)
      • Unicorn-48102.exe (PID: 8528)
      • Unicorn-48102.exe (PID: 8512)
      • Unicorn-56270.exe (PID: 8568)
      • Unicorn-8192.exe (PID: 7488)
      • Unicorn-39742.exe (PID: 8432)
      • Unicorn-46440.exe (PID: 8324)
      • Unicorn-56422.exe (PID: 8388)
      • Unicorn-60162.exe (PID: 8424)
      • Unicorn-7816.exe (PID: 8308)
      • Unicorn-48102.exe (PID: 8520)
      • Unicorn-39669.exe (PID: 8596)
      • Unicorn-62392.exe (PID: 8612)
      • Unicorn-64814.exe (PID: 7628)
      • Unicorn-39548.exe (PID: 7668)
      • Unicorn-10391.exe (PID: 8604)
      • Unicorn-43826.exe (PID: 8444)
      • Unicorn-58308.exe (PID: 8620)
      • Unicorn-48300.exe (PID: 8668)
      • Unicorn-28612.exe (PID: 7684)
      • Unicorn-45947.exe (PID: 8712)
      • Unicorn-62061.exe (PID: 8772)
      • Unicorn-23901.exe (PID: 7704)
      • Unicorn-7452.exe (PID: 8744)
      • Unicorn-23901.exe (PID: 7712)
      • Unicorn-56965.exe (PID: 8660)
      • Unicorn-13052.exe (PID: 8752)
      • Unicorn-17136.exe (PID: 8736)
      • Unicorn-61433.exe (PID: 8840)
      • Unicorn-245.exe (PID: 8864)
      • Unicorn-18227.exe (PID: 8812)
      • Unicorn-38346.exe (PID: 8904)
      • Unicorn-45917.exe (PID: 8856)
      • Unicorn-46514.exe (PID: 8912)
      • Unicorn-5652.exe (PID: 8996)
      • Unicorn-27747.exe (PID: 8952)
      • Unicorn-41781.exe (PID: 8980)
      • Unicorn-36871.exe (PID: 8892)
      • Unicorn-46322.exe (PID: 9040)
      • Unicorn-14204.exe (PID: 9028)
      • Unicorn-136.exe (PID: 9072)
      • Unicorn-14204.exe (PID: 9024)
      • Unicorn-26670.exe (PID: 9096)
      • Unicorn-55066.exe (PID: 9152)
      • Unicorn-55066.exe (PID: 9160)
      • Unicorn-63048.exe (PID: 9124)
      • Unicorn-35200.exe (PID: 9144)
      • Unicorn-53212.exe (PID: 9200)
      • Unicorn-47090.exe (PID: 904)
      • Unicorn-59342.exe (PID: 9208)
      • Unicorn-19270.exe (PID: 9120)
      • Unicorn-38922.exe (PID: 5352)
      • Unicorn-36021.exe (PID: 4000)
      • Unicorn-48242.exe (PID: 9300)
      • Unicorn-24292.exe (PID: 9308)
      • Unicorn-44713.exe (PID: 9276)
      • Unicorn-25007.exe (PID: 9332)
      • Unicorn-35606.exe (PID: 9356)
      • Unicorn-31330.exe (PID: 9372)
      • Unicorn-32025.exe (PID: 9412)
      • Unicorn-8863.exe (PID: 9392)
      • Unicorn-49010.exe (PID: 9456)
      • Unicorn-53094.exe (PID: 9436)
      • Unicorn-32652.exe (PID: 9496)
      • Unicorn-16146.exe (PID: 9472)
      • Unicorn-32652.exe (PID: 9488)
      • Unicorn-17607.exe (PID: 9520)
      • Unicorn-25775.exe (PID: 9540)
      • Unicorn-23665.exe (PID: 9564)
      • Unicorn-38258.exe (PID: 9676)
      • Unicorn-35828.exe (PID: 9704)
      • Unicorn-42918.exe (PID: 9732)
      • Unicorn-9669.exe (PID: 9832)
      • Unicorn-64085.exe (PID: 9776)
      • Unicorn-15652.exe (PID: 9896)
      • Unicorn-39218.exe (PID: 9960)
      • Unicorn-23842.exe (PID: 10132)
      • Unicorn-35134.exe (PID: 9968)
      • Unicorn-55746.exe (PID: 10024)
      • Unicorn-50576.exe (PID: 10084)
      • Unicorn-36840.exe (PID: 10076)
      • Unicorn-3421.exe (PID: 10164)
      • Unicorn-57453.exe (PID: 10200)
      • Unicorn-40924.exe (PID: 10148)
      • Unicorn-45938.exe (PID: 8804)
      • Unicorn-21603.exe (PID: 4880)
      • Unicorn-27734.exe (PID: 4436)
      • Unicorn-11205.exe (PID: 6044)
      • Unicorn-52430.exe (PID: 10256)
      • Unicorn-36094.exe (PID: 10284)
      • Unicorn-36094.exe (PID: 10276)
      • Unicorn-6612.exe (PID: 8680)
      • Unicorn-65237.exe (PID: 10312)
      • Unicorn-3613.exe (PID: 10224)
      • Unicorn-3592.exe (PID: 5064)
      • Unicorn-43176.exe (PID: 10332)
      • Unicorn-12357.exe (PID: 10400)
      • Unicorn-16442.exe (PID: 10388)
      • Unicorn-12549.exe (PID: 10548)
      • Unicorn-41138.exe (PID: 10376)
      • Unicorn-63596.exe (PID: 10424)
      • Unicorn-13296.exe (PID: 10460)
      • Unicorn-37246.exe (PID: 10520)
      • Unicorn-53582.exe (PID: 10448)
      • Unicorn-9020.exe (PID: 10356)
      • Unicorn-45393.exe (PID: 10612)
      • Unicorn-29078.exe (PID: 10500)
      • Unicorn-10629.exe (PID: 10052)
      • Unicorn-22947.exe (PID: 10484)
      • Unicorn-57645.exe (PID: 10592)
      • Unicorn-45393.exe (PID: 10620)
      • Unicorn-49114.exe (PID: 10668)
      • Unicorn-41330.exe (PID: 10512)
      • Unicorn-61174.exe (PID: 10636)
      • Unicorn-48731.exe (PID: 10772)
      • Unicorn-45281.exe (PID: 8028)
      • Unicorn-41906.exe (PID: 10728)
      • Unicorn-31691.exe (PID: 10736)
      • Unicorn-62061.exe (PID: 10796)
      • Unicorn-62326.exe (PID: 10808)
      • Unicorn-9980.exe (PID: 10852)
      • Unicorn-8081.exe (PID: 10708)
      • Unicorn-24418.exe (PID: 10688)
      • Unicorn-13125.exe (PID: 10764)
      • Unicorn-46161.exe (PID: 10940)
      • Unicorn-57096.exe (PID: 10948)
      • Unicorn-8657.exe (PID: 10972)
      • Unicorn-58050.exe (PID: 11012)
      • Unicorn-20910.exe (PID: 10928)
      • Unicorn-4956.exe (PID: 11088)
      • Unicorn-25570.exe (PID: 10872)
      • Unicorn-58745.exe (PID: 11072)
      • Unicorn-4308.exe (PID: 10988)
      • Unicorn-36160.exe (PID: 11228)
      • Unicorn-22062.exe (PID: 11124)
      • Unicorn-36736.exe (PID: 11164)
      • Unicorn-17937.exe (PID: 11200)
      • Unicorn-9239.exe (PID: 11172)
      • Unicorn-44644.exe (PID: 10980)
      • Unicorn-46353.exe (PID: 11056)
      • Unicorn-13628.exe (PID: 11104)
    • Reads the computer name

      • 1 (14).exe (PID: 6816)
      • Unicorn-56132.exe (PID: 4244)
      • Unicorn-33167.exe (PID: 1132)
      • Unicorn-5430.exe (PID: 720)
      • Unicorn-36641.exe (PID: 632)
      • Unicorn-11425.exe (PID: 6108)
      • Unicorn-50412.exe (PID: 6228)
      • Unicorn-64710.exe (PID: 1184)
      • Unicorn-39444.exe (PID: 5776)
      • Unicorn-43735.exe (PID: 7344)
      • Unicorn-9801.exe (PID: 7312)
      • Unicorn-23974.exe (PID: 7496)
      • Unicorn-31180.exe (PID: 7592)
      • Unicorn-36226.exe (PID: 7512)
      • Unicorn-23901.exe (PID: 7704)
      • Unicorn-20444.exe (PID: 7676)
      • Unicorn-56646.exe (PID: 7600)
      • Unicorn-50023.exe (PID: 7824)
      • Unicorn-32526.exe (PID: 7808)
      • Unicorn-30340.exe (PID: 7932)
      • Unicorn-57798.exe (PID: 8008)
      • Unicorn-45738.exe (PID: 8104)
      • Unicorn-48081.exe (PID: 7000)
      • Unicorn-43805.exe (PID: 8256)
      • Unicorn-7816.exe (PID: 8340)
      • Unicorn-48102.exe (PID: 8512)
      • Unicorn-58308.exe (PID: 8620)
      • Unicorn-10391.exe (PID: 8604)
      • Unicorn-56270.exe (PID: 8568)
      • Unicorn-56965.exe (PID: 8660)
      • Unicorn-45947.exe (PID: 8712)
      • Unicorn-45917.exe (PID: 8856)
      • Unicorn-45938.exe (PID: 8804)
      • Unicorn-26670.exe (PID: 9096)
      • Unicorn-19270.exe (PID: 9120)
      • Unicorn-38922.exe (PID: 5352)
      • Unicorn-17607.exe (PID: 9520)
      • Unicorn-23665.exe (PID: 9564)
    • Create files in a temporary directory

      • Unicorn-24372.exe (PID: 7020)
      • 1 (14).exe (PID: 6816)
      • Unicorn-56132.exe (PID: 4244)
      • Unicorn-31130.exe (PID: 3020)
      • Unicorn-11295.exe (PID: 5384)
      • Unicorn-45878.exe (PID: 728)
      • Unicorn-36641.exe (PID: 632)
      • Unicorn-45878.exe (PID: 5280)
      • Unicorn-31130.exe (PID: 6540)
      • Unicorn-53589.exe (PID: 5964)
      • Unicorn-3257.exe (PID: 1228)
      • Unicorn-29084.exe (PID: 2040)
      • Unicorn-39444.exe (PID: 5776)
      • Unicorn-11425.exe (PID: 6108)
      • Unicorn-36676.exe (PID: 6344)
      • Unicorn-19432.exe (PID: 4868)
      • Unicorn-12878.exe (PID: 7292)
      • Unicorn-43735.exe (PID: 7344)
      • Unicorn-42151.exe (PID: 7328)
      • Unicorn-24446.exe (PID: 2552)
      • Unicorn-47911.exe (PID: 7364)
      • Unicorn-14937.exe (PID: 7408)
      • Unicorn-14653.exe (PID: 7428)
      • Unicorn-23376.exe (PID: 7444)
      • Unicorn-35458.exe (PID: 7392)
      • Unicorn-56277.exe (PID: 1764)
      • Unicorn-50412.exe (PID: 6228)
      • Unicorn-36641.exe (PID: 1388)
      • Unicorn-43434.exe (PID: 7468)
      • Unicorn-64710.exe (PID: 1184)
      • Unicorn-36226.exe (PID: 7512)
      • Unicorn-36226.exe (PID: 7504)
      • Unicorn-48374.exe (PID: 6708)
      • Unicorn-11425.exe (PID: 2692)
      • Unicorn-5430.exe (PID: 720)
      • Unicorn-15806.exe (PID: 7572)
      • Unicorn-5783.exe (PID: 7736)
      • Unicorn-56646.exe (PID: 7600)
      • Unicorn-33167.exe (PID: 1132)
      • Unicorn-44238.exe (PID: 5204)
      • Unicorn-16775.exe (PID: 3332)
      • Unicorn-16775.exe (PID: 4380)
      • Unicorn-56646.exe (PID: 7608)
      • Unicorn-50023.exe (PID: 7824)
      • Unicorn-32526.exe (PID: 7808)
      • Unicorn-50412.exe (PID: 7180)
      • Unicorn-18035.exe (PID: 7696)
      • Unicorn-57222.exe (PID: 7844)
      • Unicorn-20444.exe (PID: 7676)
      • Unicorn-42038.exe (PID: 7924)
      • Unicorn-16958.exe (PID: 8000)
      • Unicorn-45738.exe (PID: 8104)
      • Unicorn-43168.exe (PID: 8164)
      • Unicorn-47142.exe (PID: 2644)
      • Unicorn-30889.exe (PID: 8272)
      • Unicorn-43805.exe (PID: 8256)
      • Unicorn-35636.exe (PID: 4980)
      • Unicorn-7816.exe (PID: 8340)
      • Unicorn-56270.exe (PID: 8568)
      • Unicorn-48102.exe (PID: 8512)
      • Unicorn-7341.exe (PID: 300)
      • Unicorn-7816.exe (PID: 8308)
      • Unicorn-56422.exe (PID: 8388)
      • Unicorn-48102.exe (PID: 8520)
      • Unicorn-48300.exe (PID: 8668)
      • Unicorn-45947.exe (PID: 8712)
      • Unicorn-36676.exe (PID: 5256)
      • Unicorn-9728.exe (PID: 7872)
      • Unicorn-14204.exe (PID: 9028)
      • Unicorn-23974.exe (PID: 7496)
      • Unicorn-38124.exe (PID: 8096)
      • Unicorn-44652.exe (PID: 6988)
      • Unicorn-17150.exe (PID: 8088)
      • Unicorn-35274.exe (PID: 2340)
      • Unicorn-10391.exe (PID: 8604)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:01:19 13:34:56+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 176128
InitializedDataSize: 299008
UninitializedDataSize: -
EntryPoint: 0x13d4
OSVersion: 4
ImageVersion: 1
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: UEFI
ProductName: Kawaii-Unicorn
FileVersion: 1
ProductVersion: 1
InternalName: Kawaii-Unicorn
OriginalFileName: Kawaii-Unicorn.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
537
Monitored processes
404
Malicious processes
58
Suspicious processes
65

Behavior graph

Click at the process to see the details
start 1 (14).exe sppextcomobj.exe no specs slui.exe no specs unicorn-56132.exe unicorn-24372.exe unicorn-44238.exe unicorn-31130.exe unicorn-31130.exe unicorn-33167.exe unicorn-19432.exe unicorn-45878.exe unicorn-45878.exe unicorn-16775.exe unicorn-16775.exe unicorn-5430.exe unicorn-36641.exe unicorn-11295.exe unicorn-36641.exe unicorn-24446.exe unicorn-53589.exe unicorn-29084.exe unicorn-3257.exe unicorn-64710.exe unicorn-7341.exe unicorn-11425.exe unicorn-11425.exe unicorn-39444.exe unicorn-48374.exe unicorn-56277.exe unicorn-36676.exe unicorn-50412.exe unicorn-36676.exe unicorn-50412.exe unicorn-12878.exe unicorn-9801.exe unicorn-42151.exe unicorn-43735.exe unicorn-47911.exe unicorn-35458.exe unicorn-14937.exe unicorn-14653.exe unicorn-23376.exe unicorn-43434.exe unicorn-8192.exe unicorn-23974.exe unicorn-36226.exe unicorn-36226.exe unicorn-32142.exe unicorn-15806.exe unicorn-31180.exe unicorn-56646.exe unicorn-56646.exe unicorn-44949.exe unicorn-64814.exe unicorn-39548.exe unicorn-20444.exe unicorn-28612.exe unicorn-18035.exe unicorn-23901.exe unicorn-23901.exe unicorn-5783.exe unicorn-32526.exe unicorn-50023.exe unicorn-57222.exe unicorn-29594.exe no specs unicorn-9728.exe unicorn-11211.exe unicorn-42038.exe unicorn-30340.exe unicorn-50206.exe unicorn-37113.exe unicorn-16958.exe unicorn-57798.exe unicorn-45281.exe unicorn-50185.exe unicorn-17150.exe unicorn-38124.exe unicorn-45738.exe unicorn-43692.exe unicorn-43168.exe unicorn-51337.exe unicorn-44652.exe unicorn-35274.exe unicorn-48081.exe unicorn-47142.exe unicorn-38974.exe unicorn-47697.exe unicorn-35636.exe unicorn-6109.exe unicorn-35082.exe unicorn-43805.exe unicorn-30889.exe unicorn-30889.exe unicorn-7816.exe unicorn-32704.exe unicorn-46440.exe unicorn-56654.exe unicorn-7816.exe unicorn-56422.exe unicorn-60162.exe no specs unicorn-60162.exe unicorn-39742.exe unicorn-43826.exe unicorn-48102.exe unicorn-48102.exe unicorn-48102.exe unicorn-56270.exe unicorn-39669.exe unicorn-10391.exe unicorn-62392.exe unicorn-58308.exe unicorn-56965.exe unicorn-48300.exe unicorn-45947.exe unicorn-17136.exe unicorn-7452.exe unicorn-13052.exe unicorn-62061.exe unicorn-45938.exe unicorn-18227.exe unicorn-61433.exe unicorn-45917.exe unicorn-245.exe unicorn-36871.exe unicorn-38346.exe unicorn-46514.exe unicorn-27747.exe unicorn-41781.exe unicorn-5652.exe unicorn-14204.exe unicorn-14204.exe unicorn-46322.exe unicorn-136.exe unicorn-26670.exe unicorn-63048.exe unicorn-35200.exe unicorn-55066.exe unicorn-55066.exe unicorn-53212.exe unicorn-59342.exe unicorn-47090.exe unicorn-38922.exe unicorn-6612.exe unicorn-36021.exe unicorn-19270.exe unicorn-44713.exe unicorn-48242.exe unicorn-24292.exe unicorn-25007.exe unicorn-35606.exe unicorn-31330.exe unicorn-8863.exe unicorn-32025.exe unicorn-53094.exe unicorn-49010.exe unicorn-16146.exe unicorn-32652.exe unicorn-32652.exe unicorn-17607.exe unicorn-25775.exe unicorn-23665.exe unicorn-38258.exe unicorn-35828.exe unicorn-42918.exe unicorn-64085.exe unicorn-9669.exe unicorn-15652.exe unicorn-39218.exe unicorn-35134.exe unicorn-55746.exe unicorn-10629.exe unicorn-36840.exe unicorn-50576.exe unicorn-23842.exe unicorn-40924.exe unicorn-3421.exe unicorn-57453.exe unicorn-3613.exe unicorn-21603.exe unicorn-27734.exe unicorn-11205.exe unicorn-3592.exe unicorn-52430.exe unicorn-36094.exe unicorn-36094.exe unicorn-65237.exe unicorn-43176.exe unicorn-9020.exe unicorn-41138.exe unicorn-16442.exe unicorn-12357.exe unicorn-63596.exe unicorn-53582.exe unicorn-13296.exe unicorn-22947.exe unicorn-29078.exe unicorn-41330.exe unicorn-37246.exe unicorn-12549.exe unicorn-57645.exe unicorn-45393.exe unicorn-45393.exe unicorn-61174.exe unicorn-49114.exe unicorn-24418.exe unicorn-8081.exe unicorn-41906.exe unicorn-31691.exe unicorn-13125.exe unicorn-48731.exe unicorn-58797.exe no specs unicorn-62061.exe unicorn-62326.exe unicorn-9980.exe unicorn-25570.exe unicorn-20910.exe unicorn-46161.exe unicorn-57096.exe unicorn-8657.exe unicorn-44644.exe unicorn-4308.exe unicorn-58050.exe unicorn-46353.exe unicorn-58745.exe unicorn-4956.exe unicorn-13628.exe unicorn-22062.exe unicorn-1641.exe unicorn-36736.exe unicorn-9239.exe unicorn-17937.exe unicorn-36160.exe unicorn-36160.exe no specs unicorn-13701.exe no specs unicorn-18902.exe no specs unicorn-14625.exe no specs unicorn-14625.exe no specs unicorn-41552.exe no specs unicorn-19094.exe no specs unicorn-31346.exe no specs unicorn-30007.exe no specs unicorn-18518.exe no specs unicorn-59913.exe no specs unicorn-59358.exe no specs unicorn-2928.exe no specs unicorn-7012.exe no specs unicorn-56021.exe no specs unicorn-38236.exe no specs unicorn-61257.exe no specs unicorn-27454.exe no specs unicorn-2757.exe no specs unicorn-15009.exe no specs unicorn-23562.exe no specs unicorn-23453.exe no specs unicorn-36774.exe no specs unicorn-3644.exe no specs unicorn-3147.exe no specs unicorn-34919.exe no specs unicorn-36866.exe no specs unicorn-57941.exe no specs unicorn-57941.exe no specs unicorn-6139.exe no specs unicorn-12269.exe no specs unicorn-45113.exe no specs unicorn-32498.exe no specs unicorn-12076.exe no specs unicorn-58054.exe no specs unicorn-22829.exe no specs unicorn-22829.exe no specs unicorn-12845.exe no specs unicorn-41818.exe no specs unicorn-25482.exe no specs unicorn-16856.exe no specs unicorn-62793.exe no specs unicorn-62793.exe no specs unicorn-34204.exe no specs unicorn-35112.exe no specs unicorn-23944.exe no specs unicorn-3416.exe no specs unicorn-4293.exe no specs unicorn-37712.exe no specs unicorn-6523.exe no specs unicorn-6523.exe no specs unicorn-58325.exe no specs unicorn-50562.exe no specs unicorn-50562.exe no specs unicorn-26058.exe no specs unicorn-13613.exe no specs unicorn-46405.exe no specs unicorn-42586.exe no specs unicorn-42071.exe no specs unicorn-22144.exe no specs unicorn-8880.exe no specs unicorn-21896.exe no specs unicorn-21267.exe no specs unicorn-54023.exe no specs unicorn-26826.exe no specs unicorn-51885.exe no specs unicorn-12335.exe no specs unicorn-31102.exe no specs unicorn-30837.exe no specs unicorn-58621.exe no specs unicorn-49115.exe no specs unicorn-42970.exe no specs unicorn-59389.exe no specs unicorn-60458.exe no specs unicorn-40208.exe no specs unicorn-11833.exe no specs unicorn-11760.exe no specs unicorn-12196.exe no specs unicorn-36146.exe no specs unicorn-15533.exe no specs unicorn-63804.exe no specs unicorn-54345.exe no specs unicorn-4324.exe no specs unicorn-27947.exe no specs unicorn-51168.exe no specs unicorn-38030.exe no specs unicorn-21694.exe no specs unicorn-26332.exe no specs unicorn-38584.exe no specs unicorn-17802.exe no specs unicorn-55113.exe no specs unicorn-9441.exe no specs unicorn-17287.exe no specs unicorn-12876.exe no specs unicorn-7011.exe no specs unicorn-58066.exe no specs unicorn-34116.exe no specs unicorn-27623.exe no specs unicorn-59005.exe no specs unicorn-7094.exe no specs unicorn-47521.exe no specs unicorn-63302.exe no specs unicorn-41548.exe no specs unicorn-21947.exe no specs unicorn-35268.exe no specs unicorn-49004.exe no specs unicorn-9332.exe unicorn-31376.exe no specs unicorn-1200.exe no specs unicorn-18548.exe no specs unicorn-18548.exe no specs unicorn-60872.exe no specs unicorn-52704.exe no specs unicorn-49467.exe no specs unicorn-49467.exe no specs unicorn-49467.exe no specs unicorn-5476.exe no specs unicorn-5741.exe no specs unicorn-23784.exe no specs unicorn-39301.exe no specs unicorn-33435.exe no specs unicorn-19700.exe no specs unicorn-19700.exe no specs unicorn-25459.exe no specs unicorn-60925.exe no specs unicorn-9123.exe no specs unicorn-21375.exe no specs unicorn-9586.exe no specs unicorn-36228.exe no specs werfault.exe no specs unicorn-51112.exe no specs unicorn-59337.exe no specs unicorn-39736.exe no specs unicorn-14414.exe no specs unicorn-43550.exe no specs unicorn-29814.exe no specs unicorn-40750.exe no specs unicorn-7256.exe no specs unicorn-4463.exe no specs unicorn-24552.exe no specs unicorn-36804.exe no specs unicorn-34395.exe no specs unicorn-15060.exe no specs unicorn-4324.exe no specs unicorn-4324.exe no specs unicorn-15789.exe no specs unicorn-15259.exe no specs unicorn-33819.exe no specs unicorn-59608.exe no specs unicorn-64222.exe no specs unicorn-47356.exe no specs unicorn-12108.exe no specs unicorn-61309.exe no specs unicorn-52129.exe no specs unicorn-3003.exe no specs unicorn-7468.exe no specs unicorn-36945.exe no specs unicorn-36945.exe no specs unicorn-24936.exe no specs unicorn-41272.exe no specs unicorn-41272.exe no specs unicorn-41272.exe no specs unicorn-3696.exe no specs unicorn-26088.exe no specs unicorn-22004.exe no specs unicorn-40908.exe no specs unicorn-43908.exe no specs unicorn-43908.exe no specs unicorn-30172.exe no specs unicorn-27763.exe no specs unicorn-50785.exe no specs unicorn-3067.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
300C:\Users\admin\AppData\Local\Temp\Unicorn-7341.exeC:\Users\admin\AppData\Local\Temp\Unicorn-7341.exe
Unicorn-16775.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-7341.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
632C:\Users\admin\AppData\Local\Temp\Unicorn-36641.exeC:\Users\admin\AppData\Local\Temp\Unicorn-36641.exe
Unicorn-19432.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-36641.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
720C:\Users\admin\AppData\Local\Temp\Unicorn-5430.exeC:\Users\admin\AppData\Local\Temp\Unicorn-5430.exe
Unicorn-56132.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-5430.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
728C:\Users\admin\AppData\Local\Temp\Unicorn-45878.exeC:\Users\admin\AppData\Local\Temp\Unicorn-45878.exe
Unicorn-31130.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-45878.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
780C:\Users\admin\AppData\Local\Temp\Unicorn-38584.exeC:\Users\admin\AppData\Local\Temp\Unicorn-38584.exeUnicorn-6109.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-38584.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
904C:\Users\admin\AppData\Local\Temp\Unicorn-47090.exeC:\Users\admin\AppData\Local\Temp\Unicorn-47090.exe
Unicorn-16958.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-47090.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
924C:\Users\admin\AppData\Local\Temp\Unicorn-14625.exeC:\Users\admin\AppData\Local\Temp\Unicorn-14625.exeUnicorn-245.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-14625.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1132C:\Users\admin\AppData\Local\Temp\Unicorn-33167.exeC:\Users\admin\AppData\Local\Temp\Unicorn-33167.exe
1 (14).exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-33167.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1184C:\Users\admin\AppData\Local\Temp\Unicorn-64710.exeC:\Users\admin\AppData\Local\Temp\Unicorn-64710.exe
Unicorn-5430.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-64710.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1228C:\Users\admin\AppData\Local\Temp\Unicorn-3257.exeC:\Users\admin\AppData\Local\Temp\Unicorn-3257.exe
Unicorn-11295.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-3257.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
Total events
9 702
Read events
9 702
Write events
0
Delete events
0

Modification events

No data
Executable files
1 081
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
68161 (14).exeC:\Users\admin\AppData\Local\Temp\Unicorn-33167.exeexecutable
MD5:B3C4A586AE76221B07E403AFF2213585
SHA256:1A852A5B58020058D5E320998D4C8A5EDEFF350158F693CA06B6BAE697E0EA1F
4244Unicorn-56132.exeC:\Users\admin\AppData\Local\Temp\Unicorn-5430.exeexecutable
MD5:D3CE3270D44D532E6C76DA3592D647AD
SHA256:5FDB325C0828C5BE1EF6AD75A16220430555627DD73A64E03C1C6972DF267436
4244Unicorn-56132.exeC:\Users\admin\AppData\Local\Temp\Unicorn-19432.exeexecutable
MD5:52FB9C66123F06EDD38C37927A263CF6
SHA256:1870A83A932D8CDE22FE20819BF37689254E680AA21DE8970B88BE8DCD607C41
7020Unicorn-24372.exeC:\Users\admin\AppData\Local\Temp\Unicorn-16775.exeexecutable
MD5:26F5902F4E7D018312F92E7E0DC5FE04
SHA256:4ECB707EAD96D990724B3C36FA04C5E6E2FD0B6A5EE3F3AB6C4906B59DAAC1BF
3020Unicorn-31130.exeC:\Users\admin\AppData\Local\Temp\Unicorn-45878.exeexecutable
MD5:B0BDEB6DAFA8BFC01E0B6D8CAD7C0F2F
SHA256:F81887041481FABA4BE1760B71E86B3E58BA8FB5D4F175792BFF15A43A8B0730
728Unicorn-45878.exeC:\Users\admin\AppData\Local\Temp\Unicorn-24446.exeexecutable
MD5:B7159456F2883B20029A4DE24B79153C
SHA256:300486BFBE7ED64211FBCDE6F599A80B78614C3B461D5D08D7F603A0BDAC2E26
4868Unicorn-19432.exeC:\Users\admin\AppData\Local\Temp\Unicorn-36641.exeexecutable
MD5:04D2ED3329D507729BD627C723D0E422
SHA256:6D00BA341C77ED4F31482FA9A60BC9AF9A125046EFDA1368CE34E2BFFF21FE49
632Unicorn-36641.exeC:\Users\admin\AppData\Local\Temp\Unicorn-48374.exeexecutable
MD5:3408615029E34EF25832DE768B00BC2D
SHA256:F6812D6E7A56E9ECC22D7B9544A1F2A9AC6727A5C087BE65966F57C4C865BB6D
5384Unicorn-11295.exeC:\Users\admin\AppData\Local\Temp\Unicorn-3257.exeexecutable
MD5:477389D6198E94D251C73BF38234DA57
SHA256:DAC4267F2558251B8A7705660C900C94A4386F595D1283F79CA25125187F47E0
720Unicorn-5430.exeC:\Users\admin\AppData\Local\Temp\Unicorn-64710.exeexecutable
MD5:871B24D1F328C384D3759978E94A6E8B
SHA256:DB5F2CC6AED99A3C6123CF54EEF3C62048A5B8D62A1C2DC487F959272C19949D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
21
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
23.54.109.203:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
1244
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1244
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1188
backgroundTaskHost.exe
GET
200
23.54.109.203:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
20.190.160.17:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
23.54.109.203:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2112
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1188
backgroundTaskHost.exe
20.103.156.88:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1188
backgroundTaskHost.exe
23.54.109.203:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.206.78
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 20.190.160.17
  • 20.190.160.22
  • 20.190.160.67
  • 20.190.160.4
  • 20.190.160.2
  • 40.126.32.134
  • 20.190.160.65
  • 20.190.160.128
whitelisted
ocsp.digicert.com
  • 23.54.109.203
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 20.73.194.208
whitelisted
arc.msn.com
  • 20.103.156.88
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted

Threats

No threats detected
No debug info