| File name: | 1 (588) |
| Full analysis: | https://app.any.run/tasks/43125ea9-9b11-4039-9a12-902bb20ca9be |
| Verdict: | Malicious activity |
| Analysis date: | March 25, 2025, 03:17:27 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections |
| MD5: | 048F5C7F380C45A1DE7EAC4C9613F700 |
| SHA1: | 7809E18EFEE02FBAA35455C6D1133182BED15D4D |
| SHA256: | A44BFE7969902EF85FC1C921663B00A777FF897A45F2A4C7266271BAD5B50209 |
| SSDEEP: | 3072:YjD50u0/sDbCVqNkikWNW54wEzupzGbZfpfuPh+oLcwuIr:YjD50u0kD/KZW5wdK9fpfuPh+oLcwuI |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:04:26 10:28:09+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 8192 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13b0 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| ComanyName: | aaaa |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 208 | C:\Users\admin\AppData\Local\Temp\Unicorn-28096.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-28096.exe | Unicorn-24585.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 536 | C:\Users\admin\AppData\Local\Temp\Unicorn-4047.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-4047.exe | — | Unicorn-9942.exe | |||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 664 | C:\Users\admin\AppData\Local\Temp\Unicorn-56615.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-56615.exe | Unicorn-3862.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 668 | C:\Users\admin\AppData\Local\Temp\Unicorn-53141.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-53141.exe | Unicorn-49573.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 732 | C:\Users\admin\AppData\Local\Temp\Unicorn-26687.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-26687.exe | — | Unicorn-23062.exe | |||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 780 | C:\Users\admin\AppData\Local\Temp\Unicorn-62169.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-62169.exe | Unicorn-31142.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 856 | C:\Users\admin\AppData\Local\Temp\Unicorn-33545.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-33545.exe | Unicorn-5983.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 960 | C:\Users\admin\AppData\Local\Temp\Unicorn-48521.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-48521.exe | Unicorn-19494.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1184 | C:\Users\admin\AppData\Local\Temp\Unicorn-48521.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-48521.exe | Unicorn-28160.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1240 | C:\Users\admin\AppData\Local\Temp\Unicorn-60000.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-60000.exe | Unicorn-6520.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5408 | Unicorn-49573.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-53141.exe | executable | |
MD5:6DF1A83C625DE1B5F880030FA4DB005B | SHA256:76E98F36828C79AE05A9166F3FA9E67C93DDC495E08B3A6B6AE78F883709139A | |||
| 668 | Unicorn-53141.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-37241.exe | executable | |
MD5:D77D67ACAE9C3F87E86B7B4E3DD44156 | SHA256:3AB7E8715CD6D186620FCA36AD1A65D357AACEE4F3C45B0062E3D059305C6E9B | |||
| 668 | Unicorn-53141.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-20271.exe | executable | |
MD5:0B60FD7D8A7EFAAF0FFBE96DF25F1151 | SHA256:F7FAF872BEE61EEFE2582FA89333E7D76A298F311F37B1A23C755909218C14B5 | |||
| 2136 | 1 (588).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-49573.exe | executable | |
MD5:ED081ED4C5474419FF082D7C2EA84343 | SHA256:9547157A3556ED449897A6EDE54DEDD144FC5E6A60AA903991710A55FAEA27D4 | |||
| 2136 | 1 (588).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-603.exe | executable | |
MD5:BE2480341ABCD9A893DB57F3D28AC87F | SHA256:D9B808559CAB6F9E9036657C9B0E5528AEF276E70A1CB2565B4F72F1EB8999CE | |||
| 4448 | Unicorn-603.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-23728.exe | executable | |
MD5:AB1CDCBEA9576C6A0B481D35777D842E | SHA256:BDD42A17E894EE6C835D1AE3680127A3D9A5ABEA7D4F7C5C10C33C3A29CC7352 | |||
| 5408 | Unicorn-49573.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-3862.exe | executable | |
MD5:1F153C01BB1D832BEE200420922C9CB2 | SHA256:0F3593D3E927CB35D71191A504E46D631AFB7E89B05CA199ED7E74C7ADBA2C9B | |||
| 2136 | 1 (588).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-47063.exe | executable | |
MD5:0D23A4194F64141E286E625EE16AFE25 | SHA256:434B39B93B490A80FD71D77DE14ED3A108E6B1E2F4C9A00F69E31751333B6CA0 | |||
| 7356 | Unicorn-37241.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-40329.exe | executable | |
MD5:34B324FB6E6808CECECC678D31CB0502 | SHA256:4D3487822EA91FE3F7BB71CC1125FC103EE43DD4CD84E239CB1EDBE4020574DF | |||
| 7384 | Unicorn-23728.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-39945.exe | executable | |
MD5:6B20E33684A63D4CEA569FECD6EFAE7C | SHA256:82D1B00501815DC80D8282C5B05120D4BAFEA22AFF32D501A3C2F90ADB0447BF | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.53.40.176:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
— | — | GET | 200 | 23.53.40.176:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
6544 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | unknown |
4688 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | unknown |
8476 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | unknown |
8476 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | unknown |
— | — | GET | 200 | 23.53.40.178:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
5496 | MoUsoCoreWorker.exe | 23.53.40.176:80 | crl.microsoft.com | Akamai International B.V. | DE | unknown |
— | — | 23.53.40.176:80 | crl.microsoft.com | Akamai International B.V. | DE | unknown |
5496 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
5216 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
3216 | svchost.exe | 40.115.3.253:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
6544 | svchost.exe | 20.190.160.130:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
6544 | svchost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| unknown |
settings-win.data.microsoft.com |
| unknown |
crl.microsoft.com |
| unknown |
client.wns.windows.com |
| unknown |
login.live.com |
| unknown |
ocsp.digicert.com |
| unknown |
arc.msn.com |
| unknown |
slscr.update.microsoft.com |
| unknown |
www.microsoft.com |
| unknown |
fe3cr.delivery.mp.microsoft.com |
| unknown |