File name:

1 (219)

Full analysis: https://app.any.run/tasks/f36cb2b6-a352-4fc5-b763-9acb034f3588
Verdict: Malicious activity
Analysis date: March 24, 2025, 15:53:51
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections
MD5:

4F083A0E5C12EA2EC17EB0FE3AF351F0

SHA1:

F04D250E806D3A0F89A6ADE0B7212B579E660D5F

SHA256:

ADE538A2E2AB6E8263345354D667C0C31A5F21C723DF58791866AAC35854EB23

SSDEEP:

6144:K7mgsJWc8DWHA5iTmkeWigax5tpFWvJGBJ/x1eUA8k/8SwjwpyAvhhzHj7A0FK5a:KaVouHA5+mnFpghaJJ1eUAwx4DxmDsR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Unicorn-28178.exe (PID: 5204)
      • Unicorn-52948.exe (PID: 5392)
      • 1 (219).exe (PID: 6668)
      • Unicorn-63420.exe (PID: 2108)
      • Unicorn-1111.exe (PID: 6324)
      • Unicorn-34530.exe (PID: 1568)
      • Unicorn-28037.exe (PID: 2268)
      • Unicorn-5890.exe (PID: 5868)
      • Unicorn-62512.exe (PID: 516)
      • Unicorn-28304.exe (PID: 1672)
      • Unicorn-41708.exe (PID: 6872)
      • Unicorn-46420.exe (PID: 5984)
      • Unicorn-5506.exe (PID: 4120)
      • Unicorn-41708.exe (PID: 4068)
      • Unicorn-41791.exe (PID: 4180)
      • Unicorn-48444.exe (PID: 4464)
      • Unicorn-16164.exe (PID: 5408)
      • Unicorn-13249.exe (PID: 5380)
      • Unicorn-31459.exe (PID: 6228)
      • Unicorn-56382.exe (PID: 5596)
      • Unicorn-11858.exe (PID: 4844)
      • Unicorn-53104.exe (PID: 7184)
      • Unicorn-3773.exe (PID: 7232)
      • Unicorn-9056.exe (PID: 7176)
      • Unicorn-27814.exe (PID: 7252)
      • Unicorn-33945.exe (PID: 7268)
      • Unicorn-35315.exe (PID: 7324)
      • Unicorn-35315.exe (PID: 7340)
      • Unicorn-17779.exe (PID: 7364)
      • Unicorn-34529.exe (PID: 7332)
      • Unicorn-25014.exe (PID: 7260)
      • Unicorn-25107.exe (PID: 5228)
      • Unicorn-42772.exe (PID: 7476)
      • Unicorn-1054.exe (PID: 7504)
      • Unicorn-24116.exe (PID: 7532)
      • Unicorn-7857.exe (PID: 7212)
      • Unicorn-63083.exe (PID: 7548)
      • Unicorn-57909.exe (PID: 7496)
      • Unicorn-39408.exe (PID: 7628)
      • Unicorn-24826.exe (PID: 7580)
      • Unicorn-23888.exe (PID: 7680)
      • Unicorn-25455.exe (PID: 7604)
      • Unicorn-13180.exe (PID: 7620)
      • Unicorn-56844.exe (PID: 7712)
      • Unicorn-46638.exe (PID: 7612)
      • Unicorn-44692.exe (PID: 7564)
      • Unicorn-46638.exe (PID: 7596)
      • Unicorn-63851.exe (PID: 7736)
      • Unicorn-30903.exe (PID: 7888)
      • Unicorn-43239.exe (PID: 7704)
      • Unicorn-43108.exe (PID: 7744)
      • Unicorn-31034.exe (PID: 7808)
      • Unicorn-32907.exe (PID: 7768)
      • Unicorn-13249.exe (PID: 5576)
      • Unicorn-20405.exe (PID: 7828)
      • Unicorn-21925.exe (PID: 4988)
      • Unicorn-48738.exe (PID: 7800)
      • Unicorn-18459.exe (PID: 7776)
      • Unicorn-33945.exe (PID: 7276)
      • Unicorn-8667.exe (PID: 7792)
      • Unicorn-30903.exe (PID: 7880)
      • Unicorn-39155.exe (PID: 7696)
      • Unicorn-55538.exe (PID: 8080)
      • Unicorn-19851.exe (PID: 7756)
      • Unicorn-29450.exe (PID: 8116)
      • Unicorn-13327.exe (PID: 4112)
      • Unicorn-32103.exe (PID: 7848)
      • Unicorn-10265.exe (PID: 4620)
      • Unicorn-22464.exe (PID: 6964)
      • Unicorn-9140.exe (PID: 4228)
      • Unicorn-55320.exe (PID: 472)
      • Unicorn-26924.exe (PID: 1912)
      • Unicorn-30301.exe (PID: 6972)
      • Unicorn-11940.exe (PID: 4652)
      • Unicorn-61646.exe (PID: 8336)
      • Unicorn-35388.exe (PID: 8308)
      • Unicorn-37142.exe (PID: 8352)
      • Unicorn-25536.exe (PID: 8196)
      • Unicorn-58584.exe (PID: 8236)
      • Unicorn-29257.exe (PID: 8300)
      • Unicorn-42086.exe (PID: 8384)
      • Unicorn-1660.exe (PID: 7936)
      • Unicorn-2414.exe (PID: 8424)
      • Unicorn-57721.exe (PID: 7720)
      • Unicorn-48086.exe (PID: 8408)
      • Unicorn-60338.exe (PID: 8396)
      • Unicorn-8143.exe (PID: 8572)
      • Unicorn-16046.exe (PID: 8564)
      • Unicorn-60084.exe (PID: 8480)
      • Unicorn-37235.exe (PID: 8996)
      • Unicorn-17495.exe (PID: 1244)
      • Unicorn-54914.exe (PID: 8804)
      • Unicorn-15928.exe (PID: 8684)
      • Unicorn-56960.exe (PID: 8860)
      • Unicorn-37235.exe (PID: 8988)
      • Unicorn-56960.exe (PID: 8852)
      • Unicorn-45647.exe (PID: 8652)
      • Unicorn-35580.exe (PID: 8508)
      • Unicorn-38325.exe (PID: 7784)
      • Unicorn-7525.exe (PID: 7920)
      • Unicorn-35507.exe (PID: 8552)
      • Unicorn-34618.exe (PID: 8468)
      • Unicorn-22534.exe (PID: 8672)
      • Unicorn-23393.exe (PID: 9008)
      • Unicorn-56960.exe (PID: 8820)
      • Unicorn-53836.exe (PID: 9196)
      • Unicorn-27111.exe (PID: 8776)
      • Unicorn-28372.exe (PID: 8828)
      • Unicorn-40624.exe (PID: 8888)
      • Unicorn-46332.exe (PID: 8836)
      • Unicorn-59958.exe (PID: 8952)
      • Unicorn-40624.exe (PID: 8876)
      • Unicorn-7245.exe (PID: 8768)
      • Unicorn-27665.exe (PID: 8708)
      • Unicorn-65512.exe (PID: 8660)
      • Unicorn-44277.exe (PID: 8896)
      • Unicorn-25746.exe (PID: 9024)
      • Unicorn-27111.exe (PID: 8752)
      • Unicorn-7759.exe (PID: 8692)
      • Unicorn-14811.exe (PID: 9016)
      • Unicorn-12995.exe (PID: 8928)
      • Unicorn-17080.exe (PID: 8912)
      • Unicorn-40624.exe (PID: 8944)
      • Unicorn-53836.exe (PID: 9204)
      • Unicorn-12035.exe (PID: 8796)
      • Unicorn-63851.exe (PID: 7728)
      • Unicorn-32456.exe (PID: 8760)
      • Unicorn-38469.exe (PID: 8964)
      • Unicorn-2798.exe (PID: 8788)
      • Unicorn-660.exe (PID: 8920)
      • Unicorn-5382.exe (PID: 8904)
    • Starts itself from another location

      • Unicorn-28178.exe (PID: 5204)
      • 1 (219).exe (PID: 6668)
      • Unicorn-63420.exe (PID: 2108)
      • Unicorn-52948.exe (PID: 5392)
      • Unicorn-1111.exe (PID: 6324)
      • Unicorn-34530.exe (PID: 1568)
      • Unicorn-46420.exe (PID: 5984)
      • Unicorn-28037.exe (PID: 2268)
      • Unicorn-28304.exe (PID: 1672)
      • Unicorn-5890.exe (PID: 5868)
      • Unicorn-25107.exe (PID: 5228)
      • Unicorn-41708.exe (PID: 4068)
      • Unicorn-41708.exe (PID: 6872)
      • Unicorn-5506.exe (PID: 4120)
      • Unicorn-62512.exe (PID: 516)
      • Unicorn-56382.exe (PID: 5596)
      • Unicorn-41791.exe (PID: 4180)
      • Unicorn-21925.exe (PID: 4988)
      • Unicorn-48444.exe (PID: 4464)
      • Unicorn-16164.exe (PID: 5408)
      • Unicorn-13249.exe (PID: 5380)
      • Unicorn-31459.exe (PID: 6228)
      • Unicorn-13249.exe (PID: 5576)
      • Unicorn-11858.exe (PID: 4844)
      • Unicorn-53104.exe (PID: 7184)
      • Unicorn-9056.exe (PID: 7176)
      • Unicorn-3773.exe (PID: 7232)
      • Unicorn-27814.exe (PID: 7252)
      • Unicorn-33945.exe (PID: 7276)
      • Unicorn-35315.exe (PID: 7324)
      • Unicorn-33945.exe (PID: 7268)
      • Unicorn-17779.exe (PID: 7364)
      • Unicorn-35315.exe (PID: 7340)
      • Unicorn-34529.exe (PID: 7332)
      • Unicorn-25014.exe (PID: 7260)
      • Unicorn-42772.exe (PID: 7476)
      • Unicorn-1054.exe (PID: 7504)
      • Unicorn-24116.exe (PID: 7532)
      • Unicorn-7857.exe (PID: 7212)
      • Unicorn-63083.exe (PID: 7548)
      • Unicorn-57909.exe (PID: 7496)
      • Unicorn-39408.exe (PID: 7628)
      • Unicorn-24826.exe (PID: 7580)
      • Unicorn-44692.exe (PID: 7564)
      • Unicorn-23888.exe (PID: 7680)
      • Unicorn-25455.exe (PID: 7604)
      • Unicorn-13180.exe (PID: 7620)
      • Unicorn-56844.exe (PID: 7712)
      • Unicorn-46638.exe (PID: 7612)
      • Unicorn-31034.exe (PID: 7808)
      • Unicorn-46638.exe (PID: 7596)
      • Unicorn-30903.exe (PID: 7888)
      • Unicorn-43239.exe (PID: 7704)
      • Unicorn-63851.exe (PID: 7736)
      • Unicorn-43108.exe (PID: 7744)
      • Unicorn-63851.exe (PID: 7728)
      • Unicorn-20405.exe (PID: 7828)
      • Unicorn-18459.exe (PID: 7776)
      • Unicorn-57721.exe (PID: 7720)
      • Unicorn-8667.exe (PID: 7792)
      • Unicorn-39155.exe (PID: 7696)
      • Unicorn-40271.exe (PID: 7840)
      • Unicorn-48738.exe (PID: 7800)
      • Unicorn-32907.exe (PID: 7768)
      • Unicorn-1660.exe (PID: 7936)
      • Unicorn-7525.exe (PID: 7920)
      • Unicorn-30903.exe (PID: 7880)
      • Unicorn-19851.exe (PID: 7756)
      • Unicorn-29450.exe (PID: 8116)
      • Unicorn-13327.exe (PID: 4112)
      • Unicorn-38325.exe (PID: 7784)
      • Unicorn-55538.exe (PID: 8080)
      • Unicorn-22464.exe (PID: 6964)
      • Unicorn-10265.exe (PID: 4620)
      • Unicorn-32103.exe (PID: 7848)
      • Unicorn-9140.exe (PID: 4228)
      • Unicorn-17495.exe (PID: 1244)
      • Unicorn-55320.exe (PID: 472)
      • Unicorn-26924.exe (PID: 1912)
      • Unicorn-30301.exe (PID: 6972)
      • Unicorn-11940.exe (PID: 4652)
      • Unicorn-25536.exe (PID: 8196)
      • Unicorn-61646.exe (PID: 8336)
      • Unicorn-35388.exe (PID: 8308)
      • Unicorn-29257.exe (PID: 8300)
      • Unicorn-37142.exe (PID: 8352)
      • Unicorn-58584.exe (PID: 8236)
      • Unicorn-42086.exe (PID: 8384)
      • Unicorn-48086.exe (PID: 8408)
      • Unicorn-2414.exe (PID: 8424)
      • Unicorn-60084.exe (PID: 8480)
      • Unicorn-60338.exe (PID: 8396)
      • Unicorn-16046.exe (PID: 8564)
  • INFO

    • Reads the computer name

      • Unicorn-52948.exe (PID: 5392)
      • 1 (219).exe (PID: 6668)
      • Unicorn-63420.exe (PID: 2108)
      • Unicorn-1111.exe (PID: 6324)
      • Unicorn-28178.exe (PID: 5204)
      • Unicorn-34530.exe (PID: 1568)
      • Unicorn-5890.exe (PID: 5868)
      • Unicorn-28304.exe (PID: 1672)
      • Unicorn-62512.exe (PID: 516)
      • Unicorn-28037.exe (PID: 2268)
      • Unicorn-46420.exe (PID: 5984)
      • Unicorn-41708.exe (PID: 4068)
      • Unicorn-41708.exe (PID: 6872)
      • Unicorn-21925.exe (PID: 4988)
      • Unicorn-41791.exe (PID: 4180)
      • Unicorn-16164.exe (PID: 5408)
      • Unicorn-31459.exe (PID: 6228)
      • Unicorn-3773.exe (PID: 7232)
      • Unicorn-35315.exe (PID: 7324)
      • Unicorn-34529.exe (PID: 7332)
      • Unicorn-42772.exe (PID: 7476)
      • Unicorn-27814.exe (PID: 7252)
      • Unicorn-57909.exe (PID: 7496)
      • Unicorn-24116.exe (PID: 7532)
      • Unicorn-63083.exe (PID: 7548)
      • Unicorn-39408.exe (PID: 7628)
      • Unicorn-46638.exe (PID: 7612)
      • Unicorn-1660.exe (PID: 7936)
      • Unicorn-32907.exe (PID: 7768)
      • Unicorn-57721.exe (PID: 7720)
      • Unicorn-40271.exe (PID: 7840)
      • Unicorn-39155.exe (PID: 7696)
      • Unicorn-31034.exe (PID: 7808)
      • Unicorn-13327.exe (PID: 4112)
      • Unicorn-30301.exe (PID: 6972)
      • Unicorn-25536.exe (PID: 8196)
      • Unicorn-37142.exe (PID: 8352)
      • Unicorn-35388.exe (PID: 8308)
      • Unicorn-60338.exe (PID: 8396)
    • The sample compiled with chinese language support

      • 1 (219).exe (PID: 6668)
      • Unicorn-35315.exe (PID: 7340)
      • Unicorn-60338.exe (PID: 8396)
      • Unicorn-35507.exe (PID: 8552)
      • Unicorn-34530.exe (PID: 1568)
      • Unicorn-13249.exe (PID: 5380)
      • Unicorn-5382.exe (PID: 8904)
      • Unicorn-16164.exe (PID: 5408)
      • Unicorn-25107.exe (PID: 5228)
      • Unicorn-60084.exe (PID: 8480)
      • Unicorn-27665.exe (PID: 8708)
      • Unicorn-42772.exe (PID: 7476)
      • Unicorn-30301.exe (PID: 6972)
      • Unicorn-44277.exe (PID: 8896)
      • Unicorn-33945.exe (PID: 7268)
      • Unicorn-10265.exe (PID: 4620)
      • Unicorn-35315.exe (PID: 7324)
    • Checks supported languages

      • 1 (219).exe (PID: 6668)
      • Unicorn-52948.exe (PID: 5392)
      • Unicorn-63420.exe (PID: 2108)
      • Unicorn-28178.exe (PID: 5204)
      • Unicorn-34530.exe (PID: 1568)
      • Unicorn-28037.exe (PID: 2268)
      • Unicorn-28304.exe (PID: 1672)
      • Unicorn-56382.exe (PID: 5596)
      • Unicorn-62512.exe (PID: 516)
      • Unicorn-41708.exe (PID: 6872)
      • Unicorn-46420.exe (PID: 5984)
      • Unicorn-5890.exe (PID: 5868)
      • Unicorn-41708.exe (PID: 4068)
      • Unicorn-21925.exe (PID: 4988)
      • Unicorn-48444.exe (PID: 4464)
      • Unicorn-16164.exe (PID: 5408)
      • Unicorn-11858.exe (PID: 4844)
      • Unicorn-7857.exe (PID: 7212)
      • Unicorn-27814.exe (PID: 7252)
      • Unicorn-33945.exe (PID: 7276)
      • Unicorn-25014.exe (PID: 7260)
      • Unicorn-13249.exe (PID: 5380)
      • Unicorn-31459.exe (PID: 6228)
      • Unicorn-35315.exe (PID: 7340)
      • Unicorn-35315.exe (PID: 7324)
      • Unicorn-34529.exe (PID: 7332)
      • Unicorn-42772.exe (PID: 7476)
      • Unicorn-33945.exe (PID: 7268)
      • Unicorn-24116.exe (PID: 7532)
      • Unicorn-44692.exe (PID: 7564)
      • Unicorn-24826.exe (PID: 7580)
      • Unicorn-39408.exe (PID: 7628)
      • Unicorn-25455.exe (PID: 7604)
      • Unicorn-46638.exe (PID: 7596)
      • Unicorn-23888.exe (PID: 7680)
      • Unicorn-43108.exe (PID: 7744)
      • Unicorn-56844.exe (PID: 7712)
      • Unicorn-20405.exe (PID: 7828)
      • Unicorn-57721.exe (PID: 7720)
      • Unicorn-7525.exe (PID: 7920)
      • Unicorn-18459.exe (PID: 7776)
      • Unicorn-30903.exe (PID: 7880)
      • Unicorn-19851.exe (PID: 7756)
      • Unicorn-32907.exe (PID: 7768)
      • Unicorn-63851.exe (PID: 7728)
      • Unicorn-38325.exe (PID: 7784)
      • Unicorn-8667.exe (PID: 7792)
      • Unicorn-40271.exe (PID: 7840)
      • Unicorn-48738.exe (PID: 7800)
      • Unicorn-32103.exe (PID: 7848)
      • Unicorn-55538.exe (PID: 8080)
      • Unicorn-55320.exe (PID: 472)
      • Unicorn-13327.exe (PID: 4112)
      • Unicorn-22464.exe (PID: 6964)
      • Unicorn-17495.exe (PID: 1244)
      • Unicorn-30301.exe (PID: 6972)
      • Unicorn-29450.exe (PID: 8116)
      • Unicorn-26924.exe (PID: 1912)
      • Unicorn-10265.exe (PID: 4620)
      • Unicorn-25536.exe (PID: 8196)
      • Unicorn-58584.exe (PID: 8236)
      • Unicorn-29257.exe (PID: 8300)
      • Unicorn-42086.exe (PID: 8384)
      • Unicorn-35580.exe (PID: 8508)
      • Unicorn-34618.exe (PID: 8468)
      • Unicorn-8143.exe (PID: 8572)
      • Unicorn-65512.exe (PID: 8660)
      • Unicorn-7759.exe (PID: 8692)
      • Unicorn-12035.exe (PID: 8796)
      • Unicorn-56960.exe (PID: 8860)
      • Unicorn-40624.exe (PID: 8876)
      • Unicorn-37235.exe (PID: 8988)
      • Unicorn-14811.exe (PID: 9016)
      • Unicorn-38469.exe (PID: 8964)
      • Unicorn-5382.exe (PID: 8904)
      • Unicorn-53836.exe (PID: 9204)
      • Unicorn-9295.exe (PID: 9232)
      • Unicorn-16757.exe (PID: 9240)
      • Unicorn-58283.exe (PID: 2084)
      • Unicorn-4505.exe (PID: 2332)
      • Unicorn-62973.exe (PID: 9224)
      • Unicorn-7802.exe (PID: 9260)
      • Unicorn-6865.exe (PID: 9344)
      • Unicorn-4065.exe (PID: 3032)
      • Unicorn-37369.exe (PID: 1748)
      • Unicorn-59264.exe (PID: 9520)
      • Unicorn-10639.exe (PID: 9504)
      • Unicorn-49752.exe (PID: 9252)
      • Unicorn-58963.exe (PID: 9352)
      • Unicorn-58194.exe (PID: 9360)
      • Unicorn-5403.exe (PID: 9276)
      • Unicorn-1385.exe (PID: 9648)
      • Unicorn-59850.exe (PID: 9544)
      • Unicorn-60800.exe (PID: 9680)
      • Unicorn-45987.exe (PID: 10052)
      • Unicorn-10374.exe (PID: 9456)
      • Unicorn-46903.exe (PID: 9536)
      • Unicorn-52694.exe (PID: 9552)
      • Unicorn-41659.exe (PID: 10180)
      • Unicorn-54904.exe (PID: 3396)
      • Unicorn-17420.exe (PID: 8148)
      • Unicorn-45716.exe (PID: 3888)
      • Unicorn-40477.exe (PID: 456)
      • Unicorn-21565.exe (PID: 2616)
      • Unicorn-2307.exe (PID: 10868)
      • Unicorn-1685.exe (PID: 10540)
      • Unicorn-56860.exe (PID: 10596)
      • Unicorn-59111.exe (PID: 10676)
      • Unicorn-38856.exe (PID: 10560)
      • Unicorn-21503.exe (PID: 10876)
      • Unicorn-25120.exe (PID: 10636)
      • Unicorn-7222.exe (PID: 10288)
      • Unicorn-52147.exe (PID: 10320)
      • Unicorn-18842.exe (PID: 10712)
      • Unicorn-57549.exe (PID: 11232)
      • Unicorn-47483.exe (PID: 11364)
      • Unicorn-65198.exe (PID: 11392)
      • Unicorn-64678.exe (PID: 11516)
      • Unicorn-35020.exe (PID: 11532)
      • Unicorn-21285.exe (PID: 11612)
      • Unicorn-1680.exe (PID: 11088)
      • Unicorn-3334.exe (PID: 11128)
      • Unicorn-48726.exe (PID: 11216)
      • Unicorn-5747.exe (PID: 7492)
      • Unicorn-13531.exe (PID: 11440)
      • Unicorn-14674.exe (PID: 12040)
      • Unicorn-50642.exe (PID: 11788)
      • Unicorn-42525.exe (PID: 11892)
    • Create files in a temporary directory

      • Unicorn-28178.exe (PID: 5204)
      • Unicorn-52948.exe (PID: 5392)
      • 1 (219).exe (PID: 6668)
      • Unicorn-34530.exe (PID: 1568)
      • Unicorn-28037.exe (PID: 2268)
      • Unicorn-28304.exe (PID: 1672)
      • Unicorn-1111.exe (PID: 6324)
      • Unicorn-63420.exe (PID: 2108)
      • Unicorn-62512.exe (PID: 516)
      • Unicorn-41708.exe (PID: 4068)
      • Unicorn-5506.exe (PID: 4120)
      • Unicorn-16164.exe (PID: 5408)
      • Unicorn-13249.exe (PID: 5380)
      • Unicorn-56382.exe (PID: 5596)
      • Unicorn-31459.exe (PID: 6228)
      • Unicorn-11858.exe (PID: 4844)
      • Unicorn-53104.exe (PID: 7184)
      • Unicorn-3773.exe (PID: 7232)
      • Unicorn-9056.exe (PID: 7176)
      • Unicorn-27814.exe (PID: 7252)
      • Unicorn-46420.exe (PID: 5984)
      • Unicorn-25014.exe (PID: 7260)
      • Unicorn-35315.exe (PID: 7340)
      • Unicorn-17779.exe (PID: 7364)
      • Unicorn-41791.exe (PID: 4180)
      • Unicorn-25107.exe (PID: 5228)
      • Unicorn-35315.exe (PID: 7324)
      • Unicorn-42772.exe (PID: 7476)
      • Unicorn-48444.exe (PID: 4464)
      • Unicorn-1054.exe (PID: 7504)
      • Unicorn-5890.exe (PID: 5868)
      • Unicorn-41708.exe (PID: 6872)
      • Unicorn-63083.exe (PID: 7548)
      • Unicorn-7857.exe (PID: 7212)
      • Unicorn-24826.exe (PID: 7580)
      • Unicorn-39408.exe (PID: 7628)
      • Unicorn-23888.exe (PID: 7680)
      • Unicorn-13180.exe (PID: 7620)
      • Unicorn-46638.exe (PID: 7596)
      • Unicorn-30903.exe (PID: 7888)
      • Unicorn-63851.exe (PID: 7736)
      • Unicorn-43239.exe (PID: 7704)
      • Unicorn-13249.exe (PID: 5576)
      • Unicorn-43108.exe (PID: 7744)
      • Unicorn-31034.exe (PID: 7808)
      • Unicorn-18459.exe (PID: 7776)
      • Unicorn-20405.exe (PID: 7828)
      • Unicorn-21925.exe (PID: 4988)
      • Unicorn-48738.exe (PID: 7800)
      • Unicorn-39155.exe (PID: 7696)
      • Unicorn-19851.exe (PID: 7756)
      • Unicorn-30903.exe (PID: 7880)
      • Unicorn-33945.exe (PID: 7276)
      • Unicorn-29450.exe (PID: 8116)
      • Unicorn-32103.exe (PID: 7848)
      • Unicorn-33945.exe (PID: 7268)
      • Unicorn-34529.exe (PID: 7332)
      • Unicorn-55538.exe (PID: 8080)
      • Unicorn-57909.exe (PID: 7496)
      • Unicorn-17495.exe (PID: 1244)
      • Unicorn-30301.exe (PID: 6972)
      • Unicorn-11940.exe (PID: 4652)
      • Unicorn-9140.exe (PID: 4228)
      • Unicorn-26924.exe (PID: 1912)
      • Unicorn-13327.exe (PID: 4112)
      • Unicorn-22464.exe (PID: 6964)
      • Unicorn-10265.exe (PID: 4620)
      • Unicorn-25536.exe (PID: 8196)
      • Unicorn-61646.exe (PID: 8336)
      • Unicorn-44692.exe (PID: 7564)
      • Unicorn-37142.exe (PID: 8352)
      • Unicorn-42086.exe (PID: 8384)
      • Unicorn-25455.exe (PID: 7604)
      • Unicorn-46638.exe (PID: 7612)
      • Unicorn-7525.exe (PID: 7920)
      • Unicorn-40271.exe (PID: 7840)
      • Unicorn-8667.exe (PID: 7792)
      • Unicorn-24116.exe (PID: 7532)
      • Unicorn-60084.exe (PID: 8480)
      • Unicorn-16046.exe (PID: 8564)
      • Unicorn-60338.exe (PID: 8396)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Microsoft Visual Basic 6 (90.6)
.exe | Win32 Executable (generic) (4.9)
.exe | Generic Win/DOS Executable (2.2)
.exe | DOS Executable Generic (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:01:20 00:32:00+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 176128
InitializedDataSize: 299008
UninitializedDataSize: -
EntryPoint: 0x13d4
OSVersion: 4
ImageVersion: 1
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: UEFI
ProductName: Kawaii-Unicorn
FileVersion: 1
ProductVersion: 1
InternalName: Kawaii-Unicorn
OriginalFileName: Kawaii-Unicorn.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
399
Monitored processes
265
Malicious processes
44
Suspicious processes
38

Behavior graph

Click at the process to see the details
start 1 (219).exe sppextcomobj.exe no specs slui.exe no specs unicorn-52948.exe unicorn-63420.exe unicorn-28178.exe unicorn-1111.exe unicorn-34530.exe unicorn-28037.exe unicorn-46420.exe unicorn-28304.exe unicorn-5890.exe unicorn-62512.exe unicorn-56382.exe unicorn-41708.exe unicorn-41708.exe unicorn-5506.exe unicorn-25107.exe unicorn-21925.exe unicorn-41791.exe unicorn-48444.exe unicorn-16164.exe unicorn-13249.exe unicorn-13249.exe unicorn-31459.exe unicorn-11858.exe unicorn-9056.exe unicorn-53104.exe unicorn-7857.exe unicorn-3773.exe unicorn-27814.exe unicorn-25014.exe unicorn-33945.exe unicorn-33945.exe unicorn-35315.exe unicorn-34529.exe unicorn-35315.exe unicorn-17779.exe unicorn-42772.exe unicorn-57909.exe unicorn-1054.exe unicorn-24116.exe unicorn-63083.exe unicorn-44692.exe unicorn-24826.exe unicorn-46638.exe unicorn-25455.exe unicorn-46638.exe unicorn-13180.exe unicorn-39408.exe unicorn-23888.exe unicorn-39155.exe unicorn-43239.exe unicorn-56844.exe unicorn-57721.exe unicorn-63851.exe unicorn-63851.exe unicorn-43108.exe unicorn-19851.exe unicorn-32907.exe unicorn-18459.exe unicorn-38325.exe unicorn-8667.exe unicorn-48738.exe unicorn-31034.exe unicorn-20405.exe unicorn-40271.exe no specs unicorn-32103.exe unicorn-30903.exe unicorn-30903.exe unicorn-7525.exe unicorn-1660.exe unicorn-55538.exe unicorn-29450.exe unicorn-13327.exe unicorn-22464.exe unicorn-17495.exe unicorn-30301.exe unicorn-55320.exe unicorn-41292.exe no specs unicorn-9140.exe unicorn-11940.exe unicorn-26924.exe unicorn-10265.exe unicorn-25536.exe unicorn-58584.exe unicorn-29257.exe unicorn-35388.exe unicorn-61646.exe unicorn-37142.exe unicorn-42086.exe unicorn-60338.exe unicorn-48086.exe unicorn-2414.exe unicorn-34618.exe unicorn-60084.exe unicorn-35580.exe unicorn-35507.exe unicorn-16046.exe unicorn-8143.exe unicorn-45647.exe unicorn-65512.exe unicorn-22534.exe unicorn-15928.exe unicorn-7759.exe unicorn-27665.exe unicorn-27111.exe unicorn-32456.exe unicorn-7245.exe unicorn-27111.exe unicorn-2798.exe unicorn-12035.exe unicorn-54914.exe unicorn-56960.exe unicorn-28372.exe unicorn-46332.exe unicorn-56960.exe unicorn-56960.exe unicorn-40624.exe unicorn-40624.exe unicorn-44277.exe unicorn-5382.exe unicorn-17080.exe unicorn-660.exe unicorn-12995.exe unicorn-40624.exe unicorn-59958.exe unicorn-38469.exe unicorn-37235.exe unicorn-37235.exe unicorn-23393.exe unicorn-14811.exe unicorn-25746.exe unicorn-53836.exe unicorn-53836.exe unicorn-37369.exe no specs unicorn-37369.exe no specs unicorn-4505.exe no specs unicorn-4065.exe no specs unicorn-44791.exe no specs unicorn-58283.exe no specs unicorn-62973.exe no specs unicorn-9295.exe no specs unicorn-16757.exe no specs unicorn-49752.exe no specs unicorn-7802.exe no specs unicorn-5403.exe no specs unicorn-42714.exe no specs unicorn-6809.exe no specs unicorn-6865.exe no specs unicorn-58963.exe no specs unicorn-58194.exe no specs unicorn-10374.exe no specs unicorn-56040.exe no specs unicorn-63732.exe no specs unicorn-47567.exe no specs unicorn-10639.exe no specs unicorn-10639.exe no specs unicorn-65486.exe no specs unicorn-59264.exe no specs unicorn-43893.exe no specs unicorn-46903.exe no specs unicorn-59850.exe no specs unicorn-52694.exe no specs unicorn-1385.exe no specs unicorn-60800.exe no specs unicorn-36174.exe no specs unicorn-55463.exe no specs unicorn-57492.exe no specs unicorn-45987.exe no specs unicorn-45987.exe no specs unicorn-24113.exe no specs unicorn-39895.exe no specs unicorn-41659.exe no specs unicorn-63091.exe no specs unicorn-17420.exe no specs unicorn-49215.exe no specs unicorn-53719.exe no specs unicorn-23157.exe no specs unicorn-31980.exe no specs unicorn-45716.exe no specs unicorn-54904.exe no specs unicorn-31186.exe no specs unicorn-31186.exe no specs unicorn-40477.exe no specs unicorn-32500.exe no specs unicorn-21565.exe no specs unicorn-41431.exe no specs unicorn-20957.exe no specs unicorn-7222.exe no specs unicorn-52147.exe no specs unicorn-52147.exe no specs unicorn-52147.exe no specs unicorn-44393.exe no specs unicorn-33864.exe no specs unicorn-60507.exe no specs unicorn-10922.exe no specs unicorn-55847.exe no specs unicorn-19504.exe no specs unicorn-5769.exe no specs unicorn-24657.exe no specs unicorn-1685.exe no specs unicorn-25370.exe no specs unicorn-38856.exe no specs unicorn-47679.exe no specs unicorn-56860.exe no specs unicorn-61606.exe no specs unicorn-61606.exe no specs unicorn-27508.exe no specs unicorn-25120.exe no specs unicorn-25120.exe no specs unicorn-1685.exe no specs unicorn-59111.exe no specs unicorn-18842.exe no specs unicorn-39510.exe no specs unicorn-39510.exe no specs unicorn-38883.exe no specs unicorn-2307.exe no specs unicorn-21503.exe no specs unicorn-21503.exe no specs unicorn-1680.exe no specs unicorn-3334.exe no specs unicorn-3334.exe no specs unicorn-15669.exe no specs unicorn-15669.exe no specs unicorn-21534.exe no specs unicorn-48726.exe no specs unicorn-48726.exe no specs unicorn-57549.exe no specs unicorn-57549.exe no specs unicorn-57549.exe no specs unicorn-57549.exe no specs unicorn-5747.exe no specs unicorn-5747.exe no specs unicorn-29390.exe no specs unicorn-43573.exe no specs unicorn-47483.exe no specs unicorn-45598.exe no specs unicorn-65198.exe no specs unicorn-57063.exe no specs unicorn-13531.exe no specs unicorn-9090.exe no specs unicorn-61878.exe no specs unicorn-20731.exe no specs unicorn-64678.exe no specs unicorn-35020.exe no specs unicorn-50943.exe no specs unicorn-55524.exe no specs unicorn-42610.exe no specs unicorn-17533.exe no specs unicorn-21285.exe no specs unicorn-17092.exe no specs unicorn-50642.exe no specs unicorn-57768.exe no specs unicorn-51239.exe no specs unicorn-19966.exe no specs unicorn-42525.exe no specs unicorn-42525.exe no specs unicorn-41063.exe no specs unicorn-14674.exe no specs unicorn-34540.exe no specs unicorn-8949.exe no specs unicorn-22925.exe no specs unicorn-3412.exe no specs unicorn-30461.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
456C:\Users\admin\AppData\Local\Temp\Unicorn-40477.exeC:\Users\admin\AppData\Local\Temp\Unicorn-40477.exeUnicorn-34530.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-40477.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
472C:\Users\admin\AppData\Local\Temp\Unicorn-55320.exeC:\Users\admin\AppData\Local\Temp\Unicorn-55320.exe
Unicorn-24116.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-55320.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
516C:\Users\admin\AppData\Local\Temp\Unicorn-62512.exeC:\Users\admin\AppData\Local\Temp\Unicorn-62512.exe
Unicorn-34530.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-62512.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
720C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
1244C:\Users\admin\AppData\Local\Temp\Unicorn-17495.exeC:\Users\admin\AppData\Local\Temp\Unicorn-17495.exe
Unicorn-1054.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-17495.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1568C:\Users\admin\AppData\Local\Temp\Unicorn-34530.exeC:\Users\admin\AppData\Local\Temp\Unicorn-34530.exe
Unicorn-52948.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-34530.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1672C:\Users\admin\AppData\Local\Temp\Unicorn-28304.exeC:\Users\admin\AppData\Local\Temp\Unicorn-28304.exe
Unicorn-1111.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-28304.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1748C:\Users\admin\AppData\Local\Temp\Unicorn-37369.exeC:\Users\admin\AppData\Local\Temp\Unicorn-37369.exeUnicorn-3773.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-37369.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1912C:\Users\admin\AppData\Local\Temp\Unicorn-26924.exeC:\Users\admin\AppData\Local\Temp\Unicorn-26924.exe
Unicorn-63083.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-26924.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
2084C:\Users\admin\AppData\Local\Temp\Unicorn-58283.exeC:\Users\admin\AppData\Local\Temp\Unicorn-58283.exeUnicorn-33945.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-58283.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
Total events
5 557
Read events
5 557
Write events
0
Delete events
0

Modification events

No data
Executable files
628
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
66681 (219).exeC:\Users\admin\AppData\Local\Temp\Unicorn-52948.exeexecutable
MD5:7062B25546AF6FE5749D2BB7C012C923
SHA256:CE9227ABF450B258FD7BACD72D437C08F5CE3BCCD44258F3360132A72B294E86
6324Unicorn-1111.exeC:\Users\admin\AppData\Local\Temp\Unicorn-28304.exeexecutable
MD5:F95BA1211A67EBF068EB65B0815B4137
SHA256:CBC005E1B894684D20690F94C47993D6308546CFA9468FAB0249019EBB03BF1F
66681 (219).exeC:\Users\admin\AppData\Local\Temp\Unicorn-28037.exeexecutable
MD5:EBC8670C8695848BC965800547B00095
SHA256:D540B7686A964C97163F979DD3801D3D9F78A9B010D9144910D307892FF5B201
1672Unicorn-28304.exeC:\Users\admin\AppData\Local\Temp\Unicorn-41791.exeexecutable
MD5:831E2B57AA0116F91AE9A25B7A5D9BE0
SHA256:EE56945AA090D0E032785CFEEDB6A86380E84C406D0B9078F5C4C0421DA9556E
66681 (219).exeC:\Users\admin\AppData\Local\Temp\Unicorn-28178.exeexecutable
MD5:648D118AD2B42D53C8CC57138BC24956
SHA256:A91BAB4A5F43E929235B35F772E1B1E6FDA2B7461DCE5FC3F23F3228DC57C072
66681 (219).exeC:\Users\admin\AppData\Local\Temp\Unicorn-25107.exeexecutable
MD5:95FBBCBB6E648041754704A53D81F4C6
SHA256:B5E79D5EE81E9B0652C598751077DB25A237838E5EF0EBE30DB2C918731627CE
6324Unicorn-1111.exeC:\Users\admin\AppData\Local\Temp\Unicorn-21925.exeexecutable
MD5:28A4B02518918E94078E1C1062238B85
SHA256:0C042F5E134A887C9BC3D20E9022CF6F692F757101283D5180300D14DBED4CE1
5392Unicorn-52948.exeC:\Users\admin\AppData\Local\Temp\Unicorn-34530.exeexecutable
MD5:89DFE1DBE13F53EE5F35C0EA1CB8485B
SHA256:6FFA08C19CB17A884905B5500241624AB0069EC9D61A1F577253FDE787EDC29E
2108Unicorn-63420.exeC:\Users\admin\AppData\Local\Temp\Unicorn-5890.exeexecutable
MD5:054E35A90934383D842BC74A148FD038
SHA256:F1D5B4501217F9C287DF130C45D12F40505499C29E20ACAE456EE1E305431CC0
5204Unicorn-28178.exeC:\Users\admin\AppData\Local\Temp\Unicorn-5506.exeexecutable
MD5:2467F3401E131B0330155FBC3B996131
SHA256:FEC56A49529CBD7B9BDBAE58CDD00A5DAB321699B1AC4A116E48EC74B6D475E5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
24
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.175:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6516
backgroundTaskHost.exe
GET
200
23.54.109.203:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6544
svchost.exe
GET
200
23.54.109.203:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8044
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
8044
SIHClient.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.175:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
3216
svchost.exe
20.197.71.89:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
SG
whitelisted
6544
svchost.exe
40.126.32.74:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
23.54.109.203:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1244
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6516
backgroundTaskHost.exe
20.31.169.57:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6516
backgroundTaskHost.exe
23.54.109.203:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.238
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.48.23.175
  • 23.48.23.162
  • 23.48.23.176
  • 23.48.23.160
  • 23.48.23.155
  • 23.48.23.170
  • 23.48.23.161
  • 23.48.23.153
  • 23.48.23.168
whitelisted
client.wns.windows.com
  • 20.197.71.89
  • 40.113.110.67
whitelisted
login.live.com
  • 40.126.32.74
  • 20.190.160.128
  • 20.190.160.5
  • 20.190.160.64
  • 40.126.32.140
  • 40.126.32.138
  • 20.190.160.131
  • 40.126.32.134
whitelisted
ocsp.digicert.com
  • 23.54.109.203
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
www.microsoft.com
  • 23.52.120.96
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted

Threats

No threats detected
No debug info