| File name: | 1 (307) |
| Full analysis: | https://app.any.run/tasks/a681db19-cac3-4058-84f9-db5fb79426f3 |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2025, 17:48:33 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, 3 sections |
| MD5: | 6CCEDDD6E7F24FD4C0F914128BA4B2D0 |
| SHA1: | 226BB061BBE1D11F2EDDC4CA87C433A078EBFA6D |
| SHA256: | ACBC14B8EAD00C9BC0885ECC8BA0D73AEBB502EDD9848790496504D092577D5C |
| SSDEEP: | 6144:+7K0fsIIxD1HA5lJFpevR0Lx/tBtlvJGBC/WyeOagk/8SwjwpyAvEh6dZ8gdiKXa:++ibgHA5LFomBPhaCOyeOaBx4DxmDsR |
| .exe | | | Win32 Executable Microsoft Visual Basic 6 (90.6) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (4.9) |
| .exe | | | Generic Win/DOS Executable (2.2) |
| .exe | | | DOS Executable Generic (2.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:01:20 00:32:00+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit, No debug, Removable run from swap, Net run from swap, Uniprocessor only, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 299008 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13d4 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | UEFI |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 456 | C:\Users\admin\AppData\Local\Temp\Unicorn-16714.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-16714.exe | — | Unicorn-43042.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 496 | C:\Users\admin\AppData\Local\Temp\Unicorn-28597.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-28597.exe | Unicorn-15902.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 684 | C:\Users\admin\AppData\Local\Temp\Unicorn-10026.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-10026.exe | — | Unicorn-59865.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 856 | C:\Users\admin\AppData\Local\Temp\Unicorn-15438.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-15438.exe | Unicorn-64452.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1012 | C:\Users\admin\AppData\Local\Temp\Unicorn-49547.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-49547.exe | Unicorn-43936.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1020 | C:\Users\admin\AppData\Local\Temp\Unicorn-12719.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-12719.exe | Unicorn-23929.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1056 | C:\Users\admin\AppData\Local\Temp\Unicorn-51832.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-51832.exe | Unicorn-57135.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1096 | C:\Users\admin\AppData\Local\Temp\Unicorn-55677.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-55677.exe | Unicorn-53181.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1128 | C:\Users\admin\AppData\Local\Temp\Unicorn-11198.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-11198.exe | — | 1 (307).exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Exit code: 3221225785 Version: 1.00 Modules
| |||||||||||||||
| 1128 | C:\Users\admin\AppData\Local\Temp\Unicorn-586.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-586.exe | Unicorn-43936.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5588 | 1 (307).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-15902.exe | executable | |
MD5:3D4B8B079BB43CC4C3B6843E51C45132 | SHA256:649470836D43460EF1F4969989F952E2D2C827E07827B8CE334F121DDE154E20 | |||
| 1280 | Unicorn-43578.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-43936.exe | executable | |
MD5:E3E569F6B6C48CAE38B1C1C4D1FD6604 | SHA256:6DD92FDF011A0EA6D30E9C2F737AF3D141D2173EF4189D2862572DF0F0469A80 | |||
| 6132 | Unicorn-43936.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-17712.exe | executable | |
MD5:DB48CAAAC5570927302C0647326C15D7 | SHA256:EEBC7DBE8176C0C08A8FFFDB92A7C2337DC3DB7A909E6610BAED5B57D7324D0B | |||
| 1244 | Unicorn-15902.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-57135.exe | executable | |
MD5:F56C6A18A0B900976A13D658F4CCFB29 | SHA256:305DE0F10AB02D975B71F85B5BC16BD891C5B8271BBDFA4626F9F088B0C22602 | |||
| 1280 | Unicorn-43578.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-64452.exe | executable | |
MD5:01A171B003AA804D75B41CF6A50E74E4 | SHA256:C95C9D9292A710A5F749D0A6C82DB0E8F1A8BE175E194CD1EC87AA2FED1212F8 | |||
| 1244 | Unicorn-15902.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-18781.exe | executable | |
MD5:63583D3E035B0B7DBB7F34D2A6296EA7 | SHA256:445E00F6FCC261F64459E897FAAC5FAEF29E841B7DAEC8A6957E9C3F5DA640F4 | |||
| 6132 | Unicorn-43936.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-3658.exe | executable | |
MD5:0D9996516F6BF82BB53F328CAB1CD932 | SHA256:DB0EB1D9977A4BF1A9B46EEE9286DD6CBA87018CABF30B7ABFB306929C7AB3E8 | |||
| 2320 | Unicorn-17712.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-53181.exe | executable | |
MD5:B35DB044D1533F3F257690F6F55D4008 | SHA256:070852080A775E7FF8DFE6167E993F6818D9B86611CF3739BD151E4C094173B3 | |||
| 2432 | Unicorn-48530.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-15547.exe | executable | |
MD5:C50368EE50A65C0D7A7592A59460C645 | SHA256:8BCD49C8022BCE72689CDB696F7A1B30B07D20165784436A38F1BB8A30C21892 | |||
| 1280 | Unicorn-43578.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-46174.exe | executable | |
MD5:6537E58B4101700AEC9D16447A0ECAB8 | SHA256:382684E98AEE8A91DC67390422A24E0731E189612F7123AE76E85B08D3270D1E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.53.40.178:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 23.54.109.203:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
8036 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
8036 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5380 | backgroundTaskHost.exe | GET | 200 | 23.54.109.203:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.53.40.178:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4996 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3216 | svchost.exe | 40.115.3.253:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 40.126.31.131:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6544 | svchost.exe | 23.54.109.203:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
5380 | backgroundTaskHost.exe | 20.223.36.55:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5380 | backgroundTaskHost.exe | 23.54.109.203:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |