| File name: | 1 (619) |
| Full analysis: | https://app.any.run/tasks/57a06963-b4cc-49d9-bec2-22ce2742bab1 |
| Verdict: | Malicious activity |
| Analysis date: | March 25, 2025, 02:38:53 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections |
| MD5: | 58C5ADC977683C2BDB187C8D59109200 |
| SHA1: | 1A52B5CD8D5659A367AA2C69696CCFFDA99FFD04 |
| SHA256: | CABDD64D5FB4E6FDE2286E3552A541A757D25790C7FBB023D4F1327455591D80 |
| SSDEEP: | 3072:YjD50QQ/0DMCVqNkgkWNW5DwEzvpzgbZfpfuPh+oLcwuIV:YjD50QQMDmKDWMwYU9fpfuPh+oLcwuI |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:04:26 10:28:09+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 8192 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13b0 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| ComanyName: | aaaa |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 300 | C:\Users\admin\AppData\Local\Temp\Unicorn-47796.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-47796.exe | Unicorn-28084.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 616 | C:\Users\admin\AppData\Local\Temp\Unicorn-29834.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-29834.exe | 1 (619).exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 632 | C:\Users\admin\AppData\Local\Temp\Unicorn-49540.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-49540.exe | Unicorn-35269.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 856 | C:\Users\admin\AppData\Local\Temp\Unicorn-51076.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-51076.exe | Unicorn-51844.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 872 | C:\Users\admin\AppData\Local\Temp\Unicorn-48370.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-48370.exe | — | Unicorn-7604.exe | |||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 924 | C:\Users\admin\AppData\Local\Temp\Unicorn-1770.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-1770.exe | — | Unicorn-40324.exe | |||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1096 | C:\Users\admin\AppData\Local\Temp\Unicorn-16218.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-16218.exe | Unicorn-41908.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1116 | C:\Users\admin\AppData\Local\Temp\Unicorn-38629.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-38629.exe | — | Unicorn-27498.exe | |||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1164 | C:\Users\admin\AppData\Local\Temp\Unicorn-61947.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-61947.exe | Unicorn-41450.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1168 | C:\Users\admin\AppData\Local\Temp\Unicorn-15002.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-15002.exe | Unicorn-49170.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7368 | 1 (619).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-46843.exe | executable | |
MD5:9FEBD4A6B0FE20BE31958F0A459D7C8E | SHA256:A2138E089C6456E3FE05BF03720C61B3DE517EFF76149EC9946E34BE1C0B87FF | |||
| 8028 | Unicorn-25882.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-33605.exe | executable | |
MD5:71D5A979F22EF59E43F37D4E76E0ACFE | SHA256:6B924F1F960EC6A33F423465E20D7858C0C45F19BBCCAD056266EFC721ADDC71 | |||
| 7452 | Unicorn-59188.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-40978.exe | executable | |
MD5:8BF8B7F65EEF554A2F2CA33D6CC86F71 | SHA256:85579659E42FDB826B3D4444B3EE410B0BA2B154FEF63B5825A007B0BA601806 | |||
| 7368 | 1 (619).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-55186.exe | executable | |
MD5:D1173EB0BC4D41729177EF1C0FAE2FE7 | SHA256:A9C5B1BA42496E9951C2849CC155661E00044211C96353B9DD7B69870C505D7C | |||
| 7268 | Unicorn-41908.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-28084.exe | executable | |
MD5:B7503462D361E49A73A2C9A60A30B854 | SHA256:35793D2220B3CA430B94457122992E75480DAE6E3DB61EC2E6761E0CCA593B6B | |||
| 7452 | Unicorn-59188.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-41450.exe | executable | |
MD5:CA24B2E70075DB7E13C4BB6C511BD564 | SHA256:85000DA3AC2E264611576020D7D4A5621751E41BE55A11B1DF00D7F70961DF3A | |||
| 7228 | Unicorn-33605.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-36117.exe | executable | |
MD5:D3679863557ABCD834D375BEA19BDAAE | SHA256:5B50E1AC4DFF6AC782CF4923AC51AEFB8FB9CE5E76ECBD3F2089408AAC73EEED | |||
| 8028 | Unicorn-25882.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-65068.exe | executable | |
MD5:F2BB841D1F079EE0CED8E1776332D857 | SHA256:9B46121903C3AA5CBA69C18C2B13E0B94F85BB0A957D271C3D57B36C75911CDF | |||
| 5304 | Unicorn-41450.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-19397.exe | executable | |
MD5:96C7BA16AEB73C0C215E283757C8A045 | SHA256:1E71094ADC6D61B96DE375F62C2979553341CC2FA09B20437CFCED08713BAC73 | |||
| 7368 | 1 (619).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-59188.exe | executable | |
MD5:C4E714466862D971BE0919B86DFBDA16 | SHA256:F236045267B0C4AD5C2F1D9BCC82DE1AFC1FF3409E4DC5493CAF9548D27F331F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.216.77.28:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7628 | backgroundTaskHost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
5048 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5048 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2104 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 23.216.77.28:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3216 | svchost.exe | 20.197.71.89:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | SG | whitelisted |
6544 | svchost.exe | 20.190.159.4:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6544 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
2112 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |