| File name: | 1 (219) |
| Full analysis: | https://app.any.run/tasks/f36cb2b6-a352-4fc5-b763-9acb034f3588 |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2025, 15:53:51 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections |
| MD5: | 4F083A0E5C12EA2EC17EB0FE3AF351F0 |
| SHA1: | F04D250E806D3A0F89A6ADE0B7212B579E660D5F |
| SHA256: | ADE538A2E2AB6E8263345354D667C0C31A5F21C723DF58791866AAC35854EB23 |
| SSDEEP: | 6144:K7mgsJWc8DWHA5iTmkeWigax5tpFWvJGBJ/x1eUA8k/8SwjwpyAvhhzHj7A0FK5a:KaVouHA5+mnFpghaJJ1eUAwx4DxmDsR |
| .exe | | | Win32 Executable Microsoft Visual Basic 6 (90.6) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (4.9) |
| .exe | | | Generic Win/DOS Executable (2.2) |
| .exe | | | DOS Executable Generic (2.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:01:20 00:32:00+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 299008 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13d4 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | UEFI |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 456 | C:\Users\admin\AppData\Local\Temp\Unicorn-40477.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-40477.exe | — | Unicorn-34530.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 472 | C:\Users\admin\AppData\Local\Temp\Unicorn-55320.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-55320.exe | Unicorn-24116.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 516 | C:\Users\admin\AppData\Local\Temp\Unicorn-62512.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-62512.exe | Unicorn-34530.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 720 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1244 | C:\Users\admin\AppData\Local\Temp\Unicorn-17495.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-17495.exe | Unicorn-1054.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1568 | C:\Users\admin\AppData\Local\Temp\Unicorn-34530.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-34530.exe | Unicorn-52948.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1672 | C:\Users\admin\AppData\Local\Temp\Unicorn-28304.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-28304.exe | Unicorn-1111.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1748 | C:\Users\admin\AppData\Local\Temp\Unicorn-37369.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-37369.exe | — | Unicorn-3773.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1912 | C:\Users\admin\AppData\Local\Temp\Unicorn-26924.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-26924.exe | Unicorn-63083.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 2084 | C:\Users\admin\AppData\Local\Temp\Unicorn-58283.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-58283.exe | — | Unicorn-33945.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6668 | 1 (219).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-52948.exe | executable | |
MD5:7062B25546AF6FE5749D2BB7C012C923 | SHA256:CE9227ABF450B258FD7BACD72D437C08F5CE3BCCD44258F3360132A72B294E86 | |||
| 6324 | Unicorn-1111.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-28304.exe | executable | |
MD5:F95BA1211A67EBF068EB65B0815B4137 | SHA256:CBC005E1B894684D20690F94C47993D6308546CFA9468FAB0249019EBB03BF1F | |||
| 6668 | 1 (219).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-28037.exe | executable | |
MD5:EBC8670C8695848BC965800547B00095 | SHA256:D540B7686A964C97163F979DD3801D3D9F78A9B010D9144910D307892FF5B201 | |||
| 1672 | Unicorn-28304.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-41791.exe | executable | |
MD5:831E2B57AA0116F91AE9A25B7A5D9BE0 | SHA256:EE56945AA090D0E032785CFEEDB6A86380E84C406D0B9078F5C4C0421DA9556E | |||
| 6668 | 1 (219).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-28178.exe | executable | |
MD5:648D118AD2B42D53C8CC57138BC24956 | SHA256:A91BAB4A5F43E929235B35F772E1B1E6FDA2B7461DCE5FC3F23F3228DC57C072 | |||
| 6668 | 1 (219).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-25107.exe | executable | |
MD5:95FBBCBB6E648041754704A53D81F4C6 | SHA256:B5E79D5EE81E9B0652C598751077DB25A237838E5EF0EBE30DB2C918731627CE | |||
| 6324 | Unicorn-1111.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-21925.exe | executable | |
MD5:28A4B02518918E94078E1C1062238B85 | SHA256:0C042F5E134A887C9BC3D20E9022CF6F692F757101283D5180300D14DBED4CE1 | |||
| 5392 | Unicorn-52948.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-34530.exe | executable | |
MD5:89DFE1DBE13F53EE5F35C0EA1CB8485B | SHA256:6FFA08C19CB17A884905B5500241624AB0069EC9D61A1F577253FDE787EDC29E | |||
| 2108 | Unicorn-63420.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-5890.exe | executable | |
MD5:054E35A90934383D842BC74A148FD038 | SHA256:F1D5B4501217F9C287DF130C45D12F40505499C29E20ACAE456EE1E305431CC0 | |||
| 5204 | Unicorn-28178.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-5506.exe | executable | |
MD5:2467F3401E131B0330155FBC3B996131 | SHA256:FEC56A49529CBD7B9BDBAE58CDD00A5DAB321699B1AC4A116E48EC74B6D475E5 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.48.23.175:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6516 | backgroundTaskHost.exe | GET | 200 | 23.54.109.203:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 23.54.109.203:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
8044 | SIHClient.exe | GET | 200 | 23.52.120.96:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
8044 | SIHClient.exe | GET | 200 | 23.52.120.96:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.48.23.175:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
3216 | svchost.exe | 20.197.71.89:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | SG | whitelisted |
6544 | svchost.exe | 40.126.32.74:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 23.54.109.203:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
2104 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1244 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6516 | backgroundTaskHost.exe | 20.31.169.57:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6516 | backgroundTaskHost.exe | 23.54.109.203:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |