File name:

1 (345)

Full analysis: https://app.any.run/tasks/054f47e8-8632-491d-bea7-f9bd3e26be25
Verdict: Malicious activity
Analysis date: March 24, 2025, 20:41:18
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections
MD5:

7B5F1D2848EFA06A6B7C4D5A6667BB20

SHA1:

530624A698EC9A82C312EF1AF9D4DF8955BFAB15

SHA256:

DD268705BE3D1724EB418940D6A4F181D3206F17C5AF10DB4D03E1E0079ECA13

SSDEEP:

6144:V7agl6NvNDatO54/rNo9MjeAD3qRp8GBa/+weOpuk/vSwjwpyAvEhXbRkGNSLlxM:VuYMMtO5sruS3M+aaGweOpmx4DxmDsR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts itself from another location

      • 1 (345).exe (PID: 7000)
      • Unicorn-38377.exe (PID: 7848)
      • Unicorn-63313.exe (PID: 7396)
      • Unicorn-52213.exe (PID: 7828)
      • Unicorn-20501.exe (PID: 7904)
      • Unicorn-43059.exe (PID: 7868)
      • Unicorn-62088.exe (PID: 7888)
      • Unicorn-20400.exe (PID: 7920)
      • Unicorn-25605.exe (PID: 7980)
      • Unicorn-50109.exe (PID: 8016)
      • Unicorn-54193.exe (PID: 8040)
      • Unicorn-48063.exe (PID: 8032)
      • Unicorn-16045.exe (PID: 8000)
      • Unicorn-60150.exe (PID: 8096)
      • Unicorn-58277.exe (PID: 8056)
      • Unicorn-3601.exe (PID: 8048)
      • Unicorn-20535.exe (PID: 8144)
      • Unicorn-4753.exe (PID: 8164)
      • Unicorn-43761.exe (PID: 5680)
      • Unicorn-43093.exe (PID: 8184)
      • Unicorn-60005.exe (PID: 5728)
      • Unicorn-31417.exe (PID: 5376)
      • Unicorn-31417.exe (PID: 1180)
      • Unicorn-46362.exe (PID: 660)
      • Unicorn-690.exe (PID: 1660)
      • Unicorn-19719.exe (PID: 5056)
      • Unicorn-4509.exe (PID: 5608)
      • Unicorn-4774.exe (PID: 5556)
      • Unicorn-2728.exe (PID: 5640)
      • Unicorn-690.exe (PID: 2108)
      • Unicorn-65465.exe (PID: 3240)
      • Unicorn-33638.exe (PID: 7232)
      • Unicorn-28485.exe (PID: 7452)
      • Unicorn-21940.exe (PID: 732)
      • Unicorn-4857.exe (PID: 7336)
      • Unicorn-37207.exe (PID: 7332)
      • Unicorn-57073.exe (PID: 7208)
      • Unicorn-60892.exe (PID: 7524)
      • Unicorn-32660.exe (PID: 6584)
      • Unicorn-21748.exe (PID: 6656)
      • Unicorn-50166.exe (PID: 7760)
      • Unicorn-14540.exe (PID: 7660)
      • Unicorn-50851.exe (PID: 2516)
      • Unicorn-46658.exe (PID: 632)
      • Unicorn-46658.exe (PID: 1388)
      • Unicorn-54504.exe (PID: 4068)
      • Unicorn-2610.exe (PID: 856)
      • Unicorn-6694.exe (PID: 5800)
      • Unicorn-2702.exe (PID: 5984)
      • Unicorn-57841.exe (PID: 4188)
      • Unicorn-62994.exe (PID: 6228)
      • Unicorn-54530.exe (PID: 1052)
      • Unicorn-2610.exe (PID: 5228)
      • Unicorn-61925.exe (PID: 6080)
      • Unicorn-59879.exe (PID: 7288)
      • Unicorn-46144.exe (PID: 1132)
      • Unicorn-564.exe (PID: 5552)
      • Unicorn-38605.exe (PID: 7284)
      • Unicorn-62994.exe (PID: 7020)
      • Unicorn-61925.exe (PID: 2040)
      • Unicorn-46144.exe (PID: 7424)
      • Unicorn-207.exe (PID: 7428)
      • Unicorn-57327.exe (PID: 668)
      • Unicorn-42443.exe (PID: 5380)
      • Unicorn-41204.exe (PID: 7640)
      • Unicorn-42173.exe (PID: 7960)
      • Unicorn-61432.exe (PID: 976)
      • Unicorn-31967.exe (PID: 7212)
      • Unicorn-35728.exe (PID: 7816)
      • Unicorn-23607.exe (PID: 7384)
      • Unicorn-55594.exe (PID: 7948)
      • Unicorn-61110.exe (PID: 5324)
      • Unicorn-33097.exe (PID: 8252)
      • Unicorn-14461.exe (PID: 7600)
      • Unicorn-43954.exe (PID: 7552)
      • Unicorn-36051.exe (PID: 7216)
      • Unicorn-42081.exe (PID: 8208)
      • Unicorn-23607.exe (PID: 2100)
      • Unicorn-15438.exe (PID: 4336)
      • Unicorn-37997.exe (PID: 7584)
      • Unicorn-22215.exe (PID: 8200)
      • Unicorn-33150.exe (PID: 7480)
      • Unicorn-46833.exe (PID: 8240)
      • Unicorn-42657.exe (PID: 8280)
      • Unicorn-61494.exe (PID: 8312)
      • Unicorn-5992.exe (PID: 8440)
      • Unicorn-57815.exe (PID: 8452)
      • Unicorn-62454.exe (PID: 8488)
      • Unicorn-41479.exe (PID: 8480)
      • Unicorn-54286.exe (PID: 8532)
      • Unicorn-20675.exe (PID: 8604)
      • Unicorn-25335.exe (PID: 8748)
      • Unicorn-16975.exe (PID: 8864)
      • Unicorn-53072.exe (PID: 8912)
      • Unicorn-41598.exe (PID: 8692)
      • Unicorn-15568.exe (PID: 8940)
      • Unicorn-13430.exe (PID: 8984)
      • Unicorn-32459.exe (PID: 9012)
      • Unicorn-13430.exe (PID: 8976)
      • Unicorn-64769.exe (PID: 8960)
      • Unicorn-5817.exe (PID: 9064)
      • Unicorn-42019.exe (PID: 9048)
      • Unicorn-48796.exe (PID: 9096)
      • Unicorn-50742.exe (PID: 9104)
      • Unicorn-64577.exe (PID: 9084)
      • Unicorn-9154.exe (PID: 9128)
      • Unicorn-5070.exe (PID: 9112)
      • Unicorn-9154.exe (PID: 9120)
      • Unicorn-13238.exe (PID: 9136)
      • Unicorn-14561.exe (PID: 8644)
      • Unicorn-34427.exe (PID: 8736)
      • Unicorn-171.exe (PID: 8332)
      • Unicorn-25297.exe (PID: 8304)
      • Unicorn-13906.exe (PID: 6156)
      • Unicorn-24121.exe (PID: 8956)
      • Unicorn-14369.exe (PID: 7316)
      • Unicorn-50498.exe (PID: 8296)
      • Unicorn-21909.exe (PID: 8476)
      • Unicorn-17707.exe (PID: 9240)
      • Unicorn-34134.exe (PID: 9220)
      • Unicorn-28013.exe (PID: 9260)
      • Unicorn-49009.exe (PID: 9328)
      • Unicorn-62637.exe (PID: 9308)
      • Unicorn-49101.exe (PID: 9344)
      • Unicorn-24867.exe (PID: 9460)
      • Unicorn-20320.exe (PID: 9408)
      • Unicorn-40156.exe (PID: 9592)
      • Unicorn-40156.exe (PID: 9600)
      • Unicorn-12755.exe (PID: 9704)
      • Unicorn-4852.exe (PID: 9744)
      • Unicorn-19010.exe (PID: 9728)
      • Unicorn-44987.exe (PID: 8420)
      • Unicorn-58692.exe (PID: 9712)
      • Unicorn-49777.exe (PID: 9808)
      • Unicorn-51915.exe (PID: 9720)
      • Unicorn-768.exe (PID: 9800)
      • Unicorn-4852.exe (PID: 9756)
      • Unicorn-27773.exe (PID: 9920)
      • Unicorn-576.exe (PID: 9968)
      • Unicorn-62029.exe (PID: 9952)
      • Unicorn-9491.exe (PID: 9840)
      • Unicorn-33441.exe (PID: 9856)
      • Unicorn-23689.exe (PID: 9900)
      • Unicorn-41509.exe (PID: 9936)
      • Unicorn-14774.exe (PID: 10016)
      • Unicorn-39471.exe (PID: 9884)
      • Unicorn-25081.exe (PID: 10076)
      • Unicorn-5215.exe (PID: 10088)
      • Unicorn-57183.exe (PID: 9960)
      • Unicorn-49585.exe (PID: 10068)
      • Unicorn-43455.exe (PID: 10032)
      • Unicorn-49320.exe (PID: 10024)
      • Unicorn-28349.exe (PID: 10184)
      • Unicorn-60559.exe (PID: 10228)
      • Unicorn-37525.exe (PID: 9868)
      • Unicorn-576.exe (PID: 9988)
    • Executable content was dropped or overwritten

      • 1 (345).exe (PID: 7000)
      • Unicorn-63313.exe (PID: 7396)
      • Unicorn-52213.exe (PID: 7828)
      • Unicorn-38377.exe (PID: 7848)
      • Unicorn-43059.exe (PID: 7868)
      • Unicorn-20501.exe (PID: 7904)
      • Unicorn-62088.exe (PID: 7888)
      • Unicorn-20400.exe (PID: 7920)
      • Unicorn-25605.exe (PID: 7980)
      • Unicorn-16045.exe (PID: 8000)
      • Unicorn-50109.exe (PID: 8016)
      • Unicorn-48063.exe (PID: 8032)
      • Unicorn-3601.exe (PID: 8048)
      • Unicorn-60150.exe (PID: 8096)
      • Unicorn-4753.exe (PID: 8164)
      • Unicorn-20535.exe (PID: 8144)
      • Unicorn-43761.exe (PID: 5680)
      • Unicorn-43093.exe (PID: 8184)
      • Unicorn-60005.exe (PID: 5728)
      • Unicorn-31417.exe (PID: 5376)
      • Unicorn-54193.exe (PID: 8040)
      • Unicorn-19719.exe (PID: 5056)
      • Unicorn-690.exe (PID: 1660)
      • Unicorn-2728.exe (PID: 5640)
      • Unicorn-46362.exe (PID: 660)
      • Unicorn-54530.exe (PID: 1052)
      • Unicorn-58277.exe (PID: 8056)
      • Unicorn-690.exe (PID: 2108)
      • Unicorn-28485.exe (PID: 7452)
      • Unicorn-33638.exe (PID: 7232)
      • Unicorn-32660.exe (PID: 6584)
      • Unicorn-21940.exe (PID: 732)
      • Unicorn-4857.exe (PID: 7336)
      • Unicorn-37207.exe (PID: 7332)
      • Unicorn-57073.exe (PID: 7208)
      • Unicorn-50851.exe (PID: 2516)
      • Unicorn-21748.exe (PID: 6656)
      • Unicorn-50166.exe (PID: 7760)
      • Unicorn-14540.exe (PID: 7660)
      • Unicorn-46658.exe (PID: 1388)
      • Unicorn-46658.exe (PID: 632)
      • Unicorn-31417.exe (PID: 1180)
      • Unicorn-2702.exe (PID: 5984)
      • Unicorn-54504.exe (PID: 4068)
      • Unicorn-2610.exe (PID: 856)
      • Unicorn-4774.exe (PID: 5556)
      • Unicorn-6694.exe (PID: 5800)
      • Unicorn-61925.exe (PID: 6080)
      • Unicorn-57841.exe (PID: 4188)
      • Unicorn-2610.exe (PID: 5228)
      • Unicorn-4509.exe (PID: 5608)
      • Unicorn-59879.exe (PID: 7288)
      • Unicorn-564.exe (PID: 5552)
      • Unicorn-46144.exe (PID: 1132)
      • Unicorn-62994.exe (PID: 7020)
      • Unicorn-65465.exe (PID: 3240)
      • Unicorn-61925.exe (PID: 2040)
      • Unicorn-46144.exe (PID: 7424)
      • Unicorn-57327.exe (PID: 668)
      • Unicorn-207.exe (PID: 7428)
      • Unicorn-41204.exe (PID: 7640)
      • Unicorn-55594.exe (PID: 7948)
      • Unicorn-61432.exe (PID: 976)
      • Unicorn-42443.exe (PID: 5380)
      • Unicorn-35728.exe (PID: 7816)
      • Unicorn-23607.exe (PID: 7384)
      • Unicorn-33097.exe (PID: 8252)
      • Unicorn-61110.exe (PID: 5324)
      • Unicorn-60892.exe (PID: 7524)
      • Unicorn-43954.exe (PID: 7552)
      • Unicorn-14461.exe (PID: 7600)
      • Unicorn-42081.exe (PID: 8208)
      • Unicorn-15438.exe (PID: 4336)
      • Unicorn-36051.exe (PID: 7216)
      • Unicorn-22215.exe (PID: 8200)
      • Unicorn-33150.exe (PID: 7480)
      • Unicorn-37997.exe (PID: 7584)
      • Unicorn-46833.exe (PID: 8240)
      • Unicorn-42657.exe (PID: 8280)
      • Unicorn-61494.exe (PID: 8312)
      • Unicorn-44987.exe (PID: 8420)
      • Unicorn-5992.exe (PID: 8440)
      • Unicorn-62454.exe (PID: 8488)
      • Unicorn-54286.exe (PID: 8532)
      • Unicorn-57815.exe (PID: 8452)
      • Unicorn-41479.exe (PID: 8480)
      • Unicorn-25335.exe (PID: 8748)
      • Unicorn-12982.exe (PID: 8788)
      • Unicorn-41598.exe (PID: 8692)
      • Unicorn-20675.exe (PID: 8604)
      • Unicorn-16975.exe (PID: 8864)
      • Unicorn-53072.exe (PID: 8912)
      • Unicorn-15568.exe (PID: 8940)
      • Unicorn-13430.exe (PID: 8984)
      • Unicorn-32459.exe (PID: 9012)
      • Unicorn-13430.exe (PID: 8976)
      • Unicorn-64769.exe (PID: 8960)
      • Unicorn-42019.exe (PID: 9048)
      • Unicorn-48796.exe (PID: 9096)
      • Unicorn-62994.exe (PID: 6228)
      • Unicorn-5070.exe (PID: 9112)
      • Unicorn-5817.exe (PID: 9064)
      • Unicorn-64577.exe (PID: 9084)
      • Unicorn-50742.exe (PID: 9104)
      • Unicorn-9154.exe (PID: 9128)
      • Unicorn-9154.exe (PID: 9120)
      • Unicorn-13238.exe (PID: 9136)
      • Unicorn-171.exe (PID: 8332)
      • Unicorn-13906.exe (PID: 6156)
      • Unicorn-34427.exe (PID: 8736)
      • Unicorn-14561.exe (PID: 8644)
      • Unicorn-38605.exe (PID: 7284)
      • Unicorn-50498.exe (PID: 8296)
      • Unicorn-24121.exe (PID: 8956)
      • Unicorn-14369.exe (PID: 7316)
      • Unicorn-21909.exe (PID: 8476)
      • Unicorn-17707.exe (PID: 9240)
      • Unicorn-34134.exe (PID: 9220)
      • Unicorn-28013.exe (PID: 9260)
      • Unicorn-62637.exe (PID: 9308)
      • Unicorn-49101.exe (PID: 9344)
      • Unicorn-20320.exe (PID: 9408)
      • Unicorn-49009.exe (PID: 9328)
      • Unicorn-42173.exe (PID: 7960)
      • Unicorn-24867.exe (PID: 9460)
      • Unicorn-31967.exe (PID: 7212)
      • Unicorn-23607.exe (PID: 2100)
      • Unicorn-40156.exe (PID: 9592)
      • Unicorn-40156.exe (PID: 9600)
      • Unicorn-12755.exe (PID: 9704)
      • Unicorn-4852.exe (PID: 9744)
      • Unicorn-19010.exe (PID: 9728)
      • Unicorn-58692.exe (PID: 9712)
      • Unicorn-768.exe (PID: 9800)
      • Unicorn-9491.exe (PID: 9840)
      • Unicorn-4852.exe (PID: 9756)
      • Unicorn-49777.exe (PID: 9808)
      • Unicorn-27773.exe (PID: 9920)
      • Unicorn-39471.exe (PID: 9884)
      • Unicorn-576.exe (PID: 9968)
      • Unicorn-62029.exe (PID: 9952)
      • Unicorn-33441.exe (PID: 9856)
      • Unicorn-49320.exe (PID: 10024)
      • Unicorn-43455.exe (PID: 10032)
      • Unicorn-14774.exe (PID: 10016)
      • Unicorn-23689.exe (PID: 9900)
      • Unicorn-25081.exe (PID: 10076)
      • Unicorn-5215.exe (PID: 10088)
      • Unicorn-60559.exe (PID: 10228)
      • Unicorn-37525.exe (PID: 9868)
      • Unicorn-576.exe (PID: 9988)
      • Unicorn-4560.exe (PID: 10004)
      • Unicorn-12013.exe (PID: 10220)
      • Unicorn-48215.exe (PID: 10176)
      • Unicorn-37909.exe (PID: 9296)
      • Unicorn-20611.exe (PID: 8592)
      • Unicorn-30103.exe (PID: 9524)
      • Unicorn-28349.exe (PID: 10184)
      • Unicorn-54992.exe (PID: 10148)
      • Unicorn-5428.exe (PID: 8904)
      • Unicorn-1436.exe (PID: 9640)
      • Unicorn-24022.exe (PID: 7764)
      • Unicorn-26979.exe (PID: 9368)
      • Unicorn-65319.exe (PID: 9668)
      • Unicorn-24287.exe (PID: 6876)
      • Unicorn-55489.exe (PID: 10328)
      • Unicorn-7758.exe (PID: 10256)
      • Unicorn-14456.exe (PID: 10316)
      • Unicorn-45838.exe (PID: 10336)
      • Unicorn-6751.exe (PID: 10408)
      • Unicorn-23109.exe (PID: 10428)
      • Unicorn-29476.exe (PID: 8900)
      • Unicorn-9704.exe (PID: 8380)
      • Unicorn-47639.exe (PID: 9928)
      • Unicorn-28349.exe (PID: 10168)
      • Unicorn-60659.exe (PID: 9680)
      • Unicorn-26787.exe (PID: 10272)
      • Unicorn-21525.exe (PID: 10500)
      • Unicorn-59103.exe (PID: 10532)
      • Unicorn-32958.exe (PID: 10524)
      • Unicorn-35645.exe (PID: 10660)
      • Unicorn-49585.exe (PID: 10068)
      • Unicorn-51505.exe (PID: 10560)
      • Unicorn-54219.exe (PID: 10588)
      • Unicorn-51915.exe (PID: 9720)
      • Unicorn-18017.exe (PID: 10604)
      • Unicorn-41509.exe (PID: 9936)
      • Unicorn-54603.exe (PID: 10740)
      • Unicorn-57183.exe (PID: 9960)
      • Unicorn-6279.exe (PID: 10792)
      • Unicorn-42713.exe (PID: 10856)
      • Unicorn-40021.exe (PID: 10880)
      • Unicorn-2667.exe (PID: 10384)
      • Unicorn-6772.exe (PID: 10452)
      • Unicorn-12802.exe (PID: 10464)
      • Unicorn-11816.exe (PID: 10936)
      • Unicorn-52657.exe (PID: 11048)
      • Unicorn-40405.exe (PID: 11088)
      • Unicorn-14338.exe (PID: 11136)
      • Unicorn-50611.exe (PID: 11068)
      • Unicorn-46845.exe (PID: 9364)
      • Unicorn-15085.exe (PID: 11120)
      • Unicorn-61401.exe (PID: 11252)
      • Unicorn-40981.exe (PID: 11224)
      • Unicorn-63539.exe (PID: 11180)
      • Unicorn-6170.exe (PID: 11204)
      • Unicorn-38843.exe (PID: 10308)
      • Unicorn-61235.exe (PID: 9684)
      • Unicorn-25297.exe (PID: 8304)
      • Unicorn-3840.exe (PID: 10900)
      • Unicorn-34929.exe (PID: 10952)
      • Unicorn-53404.exe (PID: 11012)
      • Unicorn-49149.exe (PID: 11144)
      • Unicorn-20923.exe (PID: 9092)
      • Unicorn-4032.exe (PID: 11260)
      • Unicorn-20753.exe (PID: 11392)
      • Unicorn-29204.exe (PID: 924)
      • Unicorn-9247.exe (PID: 11312)
      • Unicorn-42111.exe (PID: 11116)
      • Unicorn-38350.exe (PID: 6268)
      • Unicorn-44058.exe (PID: 11320)
      • Unicorn-47587.exe (PID: 4996)
      • Unicorn-40789.exe (PID: 6592)
      • Unicorn-35889.exe (PID: 872)
      • Unicorn-61785.exe (PID: 11420)
      • Unicorn-4151.exe (PID: 11496)
      • Unicorn-41535.exe (PID: 11244)
      • Unicorn-38350.exe (PID: 11108)
      • Unicorn-61301.exe (PID: 8808)
      • Unicorn-47971.exe (PID: 11616)
      • Unicorn-16669.exe (PID: 11376)
      • Unicorn-8976.exe (PID: 11672)
      • Unicorn-35719.exe (PID: 11652)
      • Unicorn-53736.exe (PID: 11692)
      • Unicorn-64307.exe (PID: 11732)
      • Unicorn-61100.exe (PID: 11792)
      • Unicorn-13715.exe (PID: 11752)
      • Unicorn-63823.exe (PID: 11472)
      • Unicorn-33124.exe (PID: 11876)
      • Unicorn-59070.exe (PID: 11836)
      • Unicorn-61023.exe (PID: 11480)
      • Unicorn-3025.exe (PID: 11304)
      • Unicorn-61023.exe (PID: 11488)
      • Unicorn-24928.exe (PID: 11428)
      • Unicorn-17223.exe (PID: 11596)
      • Unicorn-23829.exe (PID: 11800)
    • Executes application which crashes

      • Unicorn-40543.exe (PID: 1300)
      • Unicorn-28589.exe (PID: 9364)
  • INFO

    • Checks supported languages

      • 1 (345).exe (PID: 7000)
      • Unicorn-63313.exe (PID: 7396)
      • Unicorn-62088.exe (PID: 7888)
      • Unicorn-52213.exe (PID: 7828)
      • Unicorn-38377.exe (PID: 7848)
      • Unicorn-43059.exe (PID: 7868)
      • Unicorn-25605.exe (PID: 7980)
      • Unicorn-16045.exe (PID: 8000)
      • Unicorn-50109.exe (PID: 8016)
      • Unicorn-20501.exe (PID: 7904)
      • Unicorn-20400.exe (PID: 7920)
      • Unicorn-48063.exe (PID: 8032)
      • Unicorn-54193.exe (PID: 8040)
      • Unicorn-3601.exe (PID: 8048)
      • Unicorn-58277.exe (PID: 8056)
      • Unicorn-20535.exe (PID: 8144)
      • Unicorn-4753.exe (PID: 8164)
      • Unicorn-60150.exe (PID: 8096)
      • Unicorn-60005.exe (PID: 5728)
      • Unicorn-31417.exe (PID: 5376)
      • Unicorn-43093.exe (PID: 8184)
      • Unicorn-43761.exe (PID: 5680)
      • Unicorn-54530.exe (PID: 1052)
      • Unicorn-46362.exe (PID: 660)
      • Unicorn-4774.exe (PID: 5556)
      • Unicorn-4509.exe (PID: 5608)
      • Unicorn-690.exe (PID: 1660)
      • Unicorn-690.exe (PID: 2108)
      • Unicorn-2728.exe (PID: 5640)
      • Unicorn-65465.exe (PID: 3240)
      • Unicorn-31417.exe (PID: 1180)
      • Unicorn-19719.exe (PID: 5056)
      • Unicorn-28485.exe (PID: 7452)
      • Unicorn-32660.exe (PID: 6584)
      • Unicorn-21940.exe (PID: 732)
      • Unicorn-37207.exe (PID: 7332)
      • Unicorn-60892.exe (PID: 7524)
      • Unicorn-4857.exe (PID: 7336)
      • Unicorn-50851.exe (PID: 2516)
      • Unicorn-50166.exe (PID: 7760)
      • Unicorn-46658.exe (PID: 1388)
      • Unicorn-54504.exe (PID: 4068)
      • Unicorn-57841.exe (PID: 4188)
      • Unicorn-2610.exe (PID: 5228)
      • Unicorn-61925.exe (PID: 6080)
      • Unicorn-6694.exe (PID: 5800)
      • Unicorn-2610.exe (PID: 856)
      • Unicorn-62994.exe (PID: 7020)
      • Unicorn-38605.exe (PID: 7284)
      • Unicorn-57327.exe (PID: 668)
      • Unicorn-207.exe (PID: 7428)
      • Unicorn-61925.exe (PID: 2040)
      • Unicorn-59879.exe (PID: 7288)
      • Unicorn-61432.exe (PID: 976)
      • Unicorn-41204.exe (PID: 7640)
      • Unicorn-35728.exe (PID: 7816)
      • Unicorn-46144.exe (PID: 7424)
      • Unicorn-46144.exe (PID: 1132)
      • Unicorn-36051.exe (PID: 7216)
      • Unicorn-43954.exe (PID: 7552)
      • Unicorn-61110.exe (PID: 5324)
      • Unicorn-15438.exe (PID: 4336)
      • Unicorn-23607.exe (PID: 7384)
      • Unicorn-31967.exe (PID: 7212)
      • Unicorn-14461.exe (PID: 7600)
      • Unicorn-42081.exe (PID: 8208)
      • Unicorn-61494.exe (PID: 8312)
      • Unicorn-22215.exe (PID: 8200)
      • Unicorn-46833.exe (PID: 8240)
      • Unicorn-33097.exe (PID: 8252)
      • Unicorn-5992.exe (PID: 8440)
      • Unicorn-57815.exe (PID: 8452)
      • Unicorn-41479.exe (PID: 8480)
      • Unicorn-54286.exe (PID: 8532)
      • Unicorn-44987.exe (PID: 8420)
      • Unicorn-41598.exe (PID: 8692)
      • Unicorn-25335.exe (PID: 8748)
      • Unicorn-12982.exe (PID: 8788)
      • Unicorn-16975.exe (PID: 8864)
      • Unicorn-53072.exe (PID: 8912)
      • Unicorn-15568.exe (PID: 8940)
      • Unicorn-64769.exe (PID: 8960)
      • Unicorn-13430.exe (PID: 8984)
      • Unicorn-13430.exe (PID: 8976)
      • Unicorn-32459.exe (PID: 9012)
      • Unicorn-42019.exe (PID: 9048)
      • Unicorn-64577.exe (PID: 9084)
      • Unicorn-50742.exe (PID: 9104)
      • Unicorn-5817.exe (PID: 9064)
      • Unicorn-50498.exe (PID: 8296)
      • Unicorn-34427.exe (PID: 8736)
      • Unicorn-21909.exe (PID: 8476)
      • Unicorn-13906.exe (PID: 6156)
      • Unicorn-9154.exe (PID: 9120)
      • Unicorn-9154.exe (PID: 9128)
      • Unicorn-25297.exe (PID: 8304)
      • Unicorn-171.exe (PID: 8332)
      • Unicorn-24121.exe (PID: 8956)
      • Unicorn-14369.exe (PID: 7316)
      • Unicorn-62637.exe (PID: 9308)
      • Unicorn-34134.exe (PID: 9220)
      • Unicorn-17707.exe (PID: 9240)
      • Unicorn-28013.exe (PID: 9260)
      • Unicorn-28589.exe (PID: 9364)
      • Unicorn-20320.exe (PID: 9408)
      • Unicorn-24867.exe (PID: 9460)
      • Unicorn-40156.exe (PID: 9592)
      • Unicorn-40156.exe (PID: 9600)
      • Unicorn-49009.exe (PID: 9328)
      • Unicorn-49101.exe (PID: 9344)
      • Unicorn-58692.exe (PID: 9712)
      • Unicorn-4852.exe (PID: 9756)
      • Unicorn-12755.exe (PID: 9704)
      • Unicorn-19010.exe (PID: 9728)
      • Unicorn-51915.exe (PID: 9720)
      • Unicorn-4852.exe (PID: 9744)
      • Unicorn-9491.exe (PID: 9840)
      • Unicorn-49777.exe (PID: 9808)
      • Unicorn-768.exe (PID: 9800)
      • Unicorn-47639.exe (PID: 9928)
      • Unicorn-37525.exe (PID: 9868)
      • Unicorn-27773.exe (PID: 9920)
      • Unicorn-62029.exe (PID: 9952)
      • Unicorn-33441.exe (PID: 9856)
      • Unicorn-576.exe (PID: 9988)
      • Unicorn-576.exe (PID: 9968)
      • Unicorn-14774.exe (PID: 10016)
      • Unicorn-43455.exe (PID: 10032)
      • Unicorn-41509.exe (PID: 9936)
      • Unicorn-49320.exe (PID: 10024)
      • Unicorn-57183.exe (PID: 9960)
      • Unicorn-25081.exe (PID: 10076)
      • Unicorn-54992.exe (PID: 10148)
      • Unicorn-48215.exe (PID: 10176)
      • Unicorn-28349.exe (PID: 10184)
      • Unicorn-12013.exe (PID: 10220)
      • Unicorn-60559.exe (PID: 10228)
      • Unicorn-20611.exe (PID: 8592)
      • Unicorn-49585.exe (PID: 10068)
      • Unicorn-4560.exe (PID: 10004)
      • Unicorn-30103.exe (PID: 9524)
      • Unicorn-1436.exe (PID: 9640)
      • Unicorn-5428.exe (PID: 8904)
      • Unicorn-60659.exe (PID: 9680)
      • Unicorn-29476.exe (PID: 8900)
      • Unicorn-37909.exe (PID: 9296)
      • Unicorn-46845.exe (PID: 9364)
      • Unicorn-61235.exe (PID: 9684)
      • Unicorn-65319.exe (PID: 9668)
      • Unicorn-24287.exe (PID: 6876)
      • Unicorn-24022.exe (PID: 7764)
      • Unicorn-26787.exe (PID: 10272)
      • Unicorn-2667.exe (PID: 10384)
      • Unicorn-45838.exe (PID: 10336)
      • Unicorn-6751.exe (PID: 10408)
      • Unicorn-23109.exe (PID: 10428)
      • Unicorn-7758.exe (PID: 10256)
      • Unicorn-14456.exe (PID: 10316)
      • Unicorn-21525.exe (PID: 10500)
      • Unicorn-32958.exe (PID: 10524)
      • Unicorn-51505.exe (PID: 10560)
      • Unicorn-6772.exe (PID: 10452)
      • Unicorn-12802.exe (PID: 10464)
      • Unicorn-35645.exe (PID: 10660)
      • Unicorn-54603.exe (PID: 10740)
      • Unicorn-54219.exe (PID: 10588)
      • Unicorn-18017.exe (PID: 10604)
      • Unicorn-40021.exe (PID: 10880)
      • Unicorn-3840.exe (PID: 10900)
      • Unicorn-42713.exe (PID: 10856)
      • Unicorn-11816.exe (PID: 10936)
      • Unicorn-52657.exe (PID: 11048)
      • Unicorn-40405.exe (PID: 11088)
      • Unicorn-50611.exe (PID: 11068)
      • Unicorn-15085.exe (PID: 11120)
      • Unicorn-34929.exe (PID: 10952)
      • Unicorn-63539.exe (PID: 11180)
      • Unicorn-6170.exe (PID: 11204)
      • Unicorn-40.exe (PID: 11196)
      • Unicorn-40981.exe (PID: 11224)
      • Unicorn-14338.exe (PID: 11136)
      • Unicorn-38843.exe (PID: 10308)
      • Unicorn-41535.exe (PID: 11244)
      • Unicorn-61301.exe (PID: 8808)
      • Unicorn-40789.exe (PID: 6592)
      • Unicorn-20923.exe (PID: 9092)
      • Unicorn-44058.exe (PID: 11320)
      • Unicorn-38350.exe (PID: 11108)
      • Unicorn-42111.exe (PID: 11116)
      • Unicorn-47587.exe (PID: 4996)
      • Unicorn-35889.exe (PID: 872)
      • Unicorn-29204.exe (PID: 924)
      • Unicorn-9247.exe (PID: 11312)
      • Unicorn-3025.exe (PID: 11304)
      • Unicorn-38350.exe (PID: 6268)
      • Unicorn-16669.exe (PID: 11376)
      • Unicorn-24928.exe (PID: 11428)
      • Unicorn-61023.exe (PID: 11480)
      • Unicorn-61785.exe (PID: 11420)
      • Unicorn-61023.exe (PID: 11488)
      • Unicorn-4151.exe (PID: 11496)
      • Unicorn-63823.exe (PID: 11472)
      • Unicorn-17223.exe (PID: 11596)
      • Unicorn-47971.exe (PID: 11616)
      • Unicorn-35719.exe (PID: 11652)
      • Unicorn-8976.exe (PID: 11672)
      • Unicorn-53736.exe (PID: 11692)
      • Unicorn-61100.exe (PID: 11792)
      • Unicorn-13715.exe (PID: 11752)
      • Unicorn-64307.exe (PID: 11732)
      • Unicorn-23829.exe (PID: 11800)
      • Unicorn-33124.exe (PID: 11876)
      • Unicorn-2662.exe (PID: 11900)
      • Unicorn-50457.exe (PID: 11916)
      • Unicorn-10493.exe (PID: 11924)
      • Unicorn-5240.exe (PID: 11976)
      • Unicorn-59070.exe (PID: 11836)
      • Unicorn-38027.exe (PID: 11856)
      • Unicorn-50841.exe (PID: 12028)
      • Unicorn-18531.exe (PID: 12060)
      • Unicorn-52687.exe (PID: 12128)
      • Unicorn-43035.exe (PID: 12160)
      • Unicorn-49887.exe (PID: 12132)
      • Unicorn-52403.exe (PID: 11992)
      • Unicorn-49258.exe (PID: 12052)
      • Unicorn-53150.exe (PID: 12208)
      • Unicorn-43084.exe (PID: 12200)
      • Unicorn-22423.exe (PID: 12216)
      • Unicorn-32729.exe (PID: 12252)
      • Unicorn-36813.exe (PID: 12276)
      • Unicorn-51780.exe (PID: 2968)
      • Unicorn-30704.exe (PID: 11680)
      • Unicorn-21053.exe (PID: 12012)
      • Unicorn-32970.exe (PID: 12152)
      • Unicorn-28402.exe (PID: 12348)
      • Unicorn-22536.exe (PID: 12356)
      • Unicorn-8801.exe (PID: 12364)
      • Unicorn-40157.exe (PID: 12468)
      • Unicorn-41473.exe (PID: 12520)
      • Unicorn-18095.exe (PID: 12496)
      • Unicorn-59948.exe (PID: 12296)
      • Unicorn-8146.exe (PID: 11576)
      • Unicorn-633.exe (PID: 12328)
      • Unicorn-57810.exe (PID: 12448)
      • Unicorn-41473.exe (PID: 12528)
      • Unicorn-48987.exe (PID: 12656)
      • Unicorn-35251.exe (PID: 12640)
      • Unicorn-3870.exe (PID: 12608)
      • Unicorn-57155.exe (PID: 12688)
      • Unicorn-63020.exe (PID: 12680)
      • Unicorn-40495.exe (PID: 12720)
      • Unicorn-63099.exe (PID: 12752)
      • Unicorn-18095.exe (PID: 12504)
      • Unicorn-64032.exe (PID: 12512)
      • Unicorn-29051.exe (PID: 12784)
      • Unicorn-39165.exe (PID: 12808)
      • Unicorn-12614.exe (PID: 12828)
      • Unicorn-25329.exe (PID: 12860)
      • Unicorn-12065.exe (PID: 12904)
      • Unicorn-52164.exe (PID: 12744)
      • Unicorn-45771.exe (PID: 12960)
      • Unicorn-654.exe (PID: 13008)
      • Unicorn-19683.exe (PID: 13032)
      • Unicorn-30805.exe (PID: 12936)
      • Unicorn-12906.exe (PID: 13060)
      • Unicorn-31381.exe (PID: 13148)
      • Unicorn-28920.exe (PID: 13128)
      • Unicorn-31381.exe (PID: 13140)
      • Unicorn-45579.exe (PID: 13204)
      • Unicorn-8822.exe (PID: 13044)
      • Unicorn-39357.exe (PID: 13240)
      • Unicorn-13238.exe (PID: 9136)
      • Unicorn-29243.exe (PID: 13220)
      • Unicorn-42071.exe (PID: 13308)
      • Unicorn-23021.exe (PID: 13284)
      • Unicorn-41395.exe (PID: 13264)
      • Unicorn-7160.exe (PID: 7696)
      • Unicorn-40679.exe (PID: 11004)
      • Unicorn-1038.exe (PID: 1676)
      • Unicorn-25735.exe (PID: 13004)
      • Unicorn-31765.exe (PID: 5740)
      • Unicorn-54878.exe (PID: 2152)
      • Unicorn-33903.exe (PID: 13300)
      • Unicorn-14037.exe (PID: 13292)
      • Unicorn-13290.exe (PID: 2096)
      • Unicorn-42049.exe (PID: 13276)
      • Unicorn-13290.exe (PID: 13016)
    • Reads the computer name

      • Unicorn-63313.exe (PID: 7396)
      • 1 (345).exe (PID: 7000)
      • Unicorn-52213.exe (PID: 7828)
      • Unicorn-38377.exe (PID: 7848)
      • Unicorn-20501.exe (PID: 7904)
      • Unicorn-20400.exe (PID: 7920)
      • Unicorn-25605.exe (PID: 7980)
      • Unicorn-43059.exe (PID: 7868)
      • Unicorn-62088.exe (PID: 7888)
      • Unicorn-58277.exe (PID: 8056)
      • Unicorn-16045.exe (PID: 8000)
      • Unicorn-48063.exe (PID: 8032)
      • Unicorn-3601.exe (PID: 8048)
      • Unicorn-50109.exe (PID: 8016)
      • Unicorn-60150.exe (PID: 8096)
      • Unicorn-4753.exe (PID: 8164)
      • Unicorn-43093.exe (PID: 8184)
      • Unicorn-43761.exe (PID: 5680)
      • Unicorn-60005.exe (PID: 5728)
      • Unicorn-20535.exe (PID: 8144)
      • Unicorn-31417.exe (PID: 5376)
      • Unicorn-31417.exe (PID: 1180)
      • Unicorn-19719.exe (PID: 5056)
      • Unicorn-2728.exe (PID: 5640)
      • Unicorn-690.exe (PID: 2108)
      • Unicorn-4509.exe (PID: 5608)
      • Unicorn-690.exe (PID: 1660)
      • Unicorn-4774.exe (PID: 5556)
      • Unicorn-54530.exe (PID: 1052)
      • Unicorn-65465.exe (PID: 3240)
      • Unicorn-33638.exe (PID: 7232)
      • Unicorn-28485.exe (PID: 7452)
      • Unicorn-57073.exe (PID: 7208)
      • Unicorn-50851.exe (PID: 2516)
      • Unicorn-4857.exe (PID: 7336)
      • Unicorn-60892.exe (PID: 7524)
      • Unicorn-21748.exe (PID: 6656)
      • Unicorn-50166.exe (PID: 7760)
      • Unicorn-46658.exe (PID: 632)
      • Unicorn-14540.exe (PID: 7660)
      • Unicorn-2702.exe (PID: 5984)
      • Unicorn-54504.exe (PID: 4068)
      • Unicorn-61925.exe (PID: 6080)
      • Unicorn-57841.exe (PID: 4188)
      • Unicorn-62994.exe (PID: 6228)
      • Unicorn-61925.exe (PID: 2040)
      • Unicorn-2610.exe (PID: 5228)
      • Unicorn-59879.exe (PID: 7288)
      • Unicorn-38605.exe (PID: 7284)
      • Unicorn-42443.exe (PID: 5380)
      • Unicorn-61432.exe (PID: 976)
      • Unicorn-207.exe (PID: 7428)
      • Unicorn-42173.exe (PID: 7960)
      • Unicorn-41204.exe (PID: 7640)
      • Unicorn-55594.exe (PID: 7948)
      • Unicorn-43954.exe (PID: 7552)
      • Unicorn-33097.exe (PID: 8252)
      • Unicorn-14461.exe (PID: 7600)
      • Unicorn-36051.exe (PID: 7216)
      • Unicorn-23607.exe (PID: 7384)
      • Unicorn-31967.exe (PID: 7212)
      • Unicorn-35728.exe (PID: 7816)
      • Unicorn-22215.exe (PID: 8200)
      • Unicorn-46833.exe (PID: 8240)
      • Unicorn-42081.exe (PID: 8208)
      • Unicorn-23607.exe (PID: 2100)
      • Unicorn-37997.exe (PID: 7584)
      • Unicorn-61494.exe (PID: 8312)
      • Unicorn-44987.exe (PID: 8420)
      • Unicorn-5992.exe (PID: 8440)
      • Unicorn-57815.exe (PID: 8452)
      • Unicorn-62454.exe (PID: 8488)
      • Unicorn-41479.exe (PID: 8480)
      • Unicorn-20675.exe (PID: 8604)
      • Unicorn-12982.exe (PID: 8788)
      • Unicorn-16975.exe (PID: 8864)
      • Unicorn-25335.exe (PID: 8748)
      • Unicorn-53072.exe (PID: 8912)
      • Unicorn-15568.exe (PID: 8940)
      • Unicorn-13430.exe (PID: 8984)
      • Unicorn-13430.exe (PID: 8976)
      • Unicorn-5070.exe (PID: 9112)
      • Unicorn-9154.exe (PID: 9128)
      • Unicorn-34427.exe (PID: 8736)
      • Unicorn-13238.exe (PID: 9136)
      • Unicorn-14561.exe (PID: 8644)
      • Unicorn-171.exe (PID: 8332)
      • Unicorn-13906.exe (PID: 6156)
      • Unicorn-42019.exe (PID: 9048)
      • Unicorn-17707.exe (PID: 9240)
      • Unicorn-34134.exe (PID: 9220)
      • Unicorn-24121.exe (PID: 8956)
      • Unicorn-62637.exe (PID: 9308)
      • Unicorn-28013.exe (PID: 9260)
      • Unicorn-20320.exe (PID: 9408)
      • Unicorn-24867.exe (PID: 9460)
      • Unicorn-40156.exe (PID: 9592)
      • Unicorn-40156.exe (PID: 9600)
      • Unicorn-58692.exe (PID: 9712)
      • Unicorn-49777.exe (PID: 9808)
      • Unicorn-51915.exe (PID: 9720)
      • Unicorn-9491.exe (PID: 9840)
      • Unicorn-33441.exe (PID: 9856)
      • Unicorn-39471.exe (PID: 9884)
      • Unicorn-47639.exe (PID: 9928)
      • Unicorn-62029.exe (PID: 9952)
      • Unicorn-576.exe (PID: 9968)
      • Unicorn-57183.exe (PID: 9960)
      • Unicorn-27773.exe (PID: 9920)
      • Unicorn-23689.exe (PID: 9900)
      • Unicorn-25081.exe (PID: 10076)
      • Unicorn-43455.exe (PID: 10032)
      • Unicorn-14774.exe (PID: 10016)
      • Unicorn-49320.exe (PID: 10024)
      • Unicorn-41509.exe (PID: 9936)
      • Unicorn-5215.exe (PID: 10088)
      • Unicorn-28349.exe (PID: 10184)
      • Unicorn-37525.exe (PID: 9868)
      • Unicorn-60559.exe (PID: 10228)
      • Unicorn-4560.exe (PID: 10004)
      • Unicorn-54992.exe (PID: 10148)
      • Unicorn-12013.exe (PID: 10220)
      • Unicorn-37909.exe (PID: 9296)
      • Unicorn-30103.exe (PID: 9524)
      • Unicorn-1436.exe (PID: 9640)
    • Create files in a temporary directory

      • Unicorn-63313.exe (PID: 7396)
      • Unicorn-52213.exe (PID: 7828)
      • 1 (345).exe (PID: 7000)
      • Unicorn-43059.exe (PID: 7868)
      • Unicorn-20501.exe (PID: 7904)
      • Unicorn-20400.exe (PID: 7920)
      • Unicorn-50109.exe (PID: 8016)
      • Unicorn-60150.exe (PID: 8096)
      • Unicorn-60005.exe (PID: 5728)
      • Unicorn-25605.exe (PID: 7980)
      • Unicorn-4753.exe (PID: 8164)
      • Unicorn-43761.exe (PID: 5680)
      • Unicorn-43093.exe (PID: 8184)
      • Unicorn-48063.exe (PID: 8032)
      • Unicorn-31417.exe (PID: 5376)
      • Unicorn-62088.exe (PID: 7888)
      • Unicorn-54193.exe (PID: 8040)
      • Unicorn-19719.exe (PID: 5056)
      • Unicorn-690.exe (PID: 1660)
      • Unicorn-46362.exe (PID: 660)
      • Unicorn-54530.exe (PID: 1052)
      • Unicorn-58277.exe (PID: 8056)
      • Unicorn-3601.exe (PID: 8048)
      • Unicorn-38377.exe (PID: 7848)
      • Unicorn-33638.exe (PID: 7232)
      • Unicorn-20535.exe (PID: 8144)
      • Unicorn-28485.exe (PID: 7452)
      • Unicorn-37207.exe (PID: 7332)
      • Unicorn-57073.exe (PID: 7208)
      • Unicorn-16045.exe (PID: 8000)
      • Unicorn-32660.exe (PID: 6584)
      • Unicorn-46658.exe (PID: 632)
      • Unicorn-31417.exe (PID: 1180)
      • Unicorn-2702.exe (PID: 5984)
      • Unicorn-4774.exe (PID: 5556)
      • Unicorn-6694.exe (PID: 5800)
      • Unicorn-61925.exe (PID: 6080)
      • Unicorn-57841.exe (PID: 4188)
      • Unicorn-2610.exe (PID: 5228)
      • Unicorn-59879.exe (PID: 7288)
      • Unicorn-690.exe (PID: 2108)
      • Unicorn-564.exe (PID: 5552)
      • Unicorn-62994.exe (PID: 7020)
      • Unicorn-2728.exe (PID: 5640)
      • Unicorn-61925.exe (PID: 2040)
      • Unicorn-65465.exe (PID: 3240)
      • Unicorn-46144.exe (PID: 7424)
      • Unicorn-57327.exe (PID: 668)
      • Unicorn-23607.exe (PID: 7384)
      • Unicorn-35728.exe (PID: 7816)
      • Unicorn-43954.exe (PID: 7552)
      • Unicorn-14461.exe (PID: 7600)
      • Unicorn-21940.exe (PID: 732)
      • Unicorn-61110.exe (PID: 5324)
      • Unicorn-42081.exe (PID: 8208)
      • Unicorn-37997.exe (PID: 7584)
      • Unicorn-36051.exe (PID: 7216)
      • Unicorn-22215.exe (PID: 8200)
      • Unicorn-4857.exe (PID: 7336)
      • Unicorn-33150.exe (PID: 7480)
      • Unicorn-50851.exe (PID: 2516)
      • Unicorn-21748.exe (PID: 6656)
      • Unicorn-61494.exe (PID: 8312)
      • Unicorn-50166.exe (PID: 7760)
      • Unicorn-57815.exe (PID: 8452)
      • Unicorn-41479.exe (PID: 8480)
      • Unicorn-54286.exe (PID: 8532)
      • Unicorn-14540.exe (PID: 7660)
      • Unicorn-62454.exe (PID: 8488)
      • Unicorn-20675.exe (PID: 8604)
      • Unicorn-42443.exe (PID: 5380)
      • Unicorn-46658.exe (PID: 1388)
      • Unicorn-54504.exe (PID: 4068)
      • Unicorn-16975.exe (PID: 8864)
      • Unicorn-53072.exe (PID: 8912)
      • Unicorn-2610.exe (PID: 856)
      • Unicorn-32459.exe (PID: 9012)
      • Unicorn-5817.exe (PID: 9064)
      • Unicorn-64577.exe (PID: 9084)
      • Unicorn-4509.exe (PID: 5608)
      • Unicorn-171.exe (PID: 8332)
      • Unicorn-13906.exe (PID: 6156)
      • Unicorn-13238.exe (PID: 9136)
      • Unicorn-46144.exe (PID: 1132)
      • Unicorn-38605.exe (PID: 7284)
      • Unicorn-24121.exe (PID: 8956)
      • Unicorn-14369.exe (PID: 7316)
      • Unicorn-50498.exe (PID: 8296)
      • Unicorn-61432.exe (PID: 976)
      • Unicorn-17707.exe (PID: 9240)
      • Unicorn-207.exe (PID: 7428)
      • Unicorn-62637.exe (PID: 9308)
      • Unicorn-20320.exe (PID: 9408)
      • Unicorn-24867.exe (PID: 9460)
      • Unicorn-41204.exe (PID: 7640)
      • Unicorn-42173.exe (PID: 7960)
      • Unicorn-55594.exe (PID: 7948)
      • Unicorn-33097.exe (PID: 8252)
      • Unicorn-60892.exe (PID: 7524)
      • Unicorn-23607.exe (PID: 2100)
      • Unicorn-15438.exe (PID: 4336)
      • Unicorn-46833.exe (PID: 8240)
      • Unicorn-42657.exe (PID: 8280)
      • Unicorn-12755.exe (PID: 9704)
      • Unicorn-19010.exe (PID: 9728)
      • Unicorn-58692.exe (PID: 9712)
      • Unicorn-44987.exe (PID: 8420)
      • Unicorn-4852.exe (PID: 9756)
      • Unicorn-768.exe (PID: 9800)
      • Unicorn-9491.exe (PID: 9840)
      • Unicorn-5992.exe (PID: 8440)
      • Unicorn-27773.exe (PID: 9920)
      • Unicorn-39471.exe (PID: 9884)
      • Unicorn-576.exe (PID: 9968)
      • Unicorn-62029.exe (PID: 9952)
      • Unicorn-33441.exe (PID: 9856)
      • Unicorn-49320.exe (PID: 10024)
      • Unicorn-43455.exe (PID: 10032)
      • Unicorn-5215.exe (PID: 10088)
    • The sample compiled with chinese language support

      • 1 (345).exe (PID: 7000)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 4172)
      • BackgroundTransferHost.exe (PID: 7484)
      • BackgroundTransferHost.exe (PID: 3008)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 7484)
      • WerFault.exe (PID: 8836)
      • WerFault.exe (PID: 9436)
      • WerFault.exe (PID: 9668)
    • Checks proxy server information

      • BackgroundTransferHost.exe (PID: 7484)
    • Reads the software policy settings

      • BackgroundTransferHost.exe (PID: 7484)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | DOS Executable Generic (100)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:01:19 13:34:56+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 176128
InitializedDataSize: 299008
UninitializedDataSize: -
EntryPoint: 0x13d4
OSVersion: 4
ImageVersion: 1
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: UEFI
ProductName: Kawaii-Unicorn
FileVersion: 1
ProductVersion: 1
InternalName: Kawaii-Unicorn
OriginalFileName: Kawaii-Unicorn.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
486
Monitored processes
349
Malicious processes
57
Suspicious processes
63

Behavior graph

Click at the process to see the details
start 1 (345).exe sppextcomobj.exe no specs slui.exe no specs unicorn-63313.exe unicorn-52213.exe unicorn-38377.exe unicorn-43059.exe unicorn-62088.exe unicorn-20501.exe unicorn-20400.exe unicorn-25605.exe unicorn-16045.exe unicorn-50109.exe unicorn-48063.exe unicorn-54193.exe unicorn-3601.exe unicorn-58277.exe unicorn-60150.exe unicorn-20535.exe unicorn-4753.exe unicorn-43093.exe unicorn-43761.exe backgroundtransferhost.exe no specs unicorn-60005.exe unicorn-31417.exe unicorn-31417.exe unicorn-46362.exe unicorn-19719.exe unicorn-4774.exe unicorn-4509.exe unicorn-690.exe unicorn-690.exe unicorn-54530.exe unicorn-2728.exe unicorn-65465.exe unicorn-33638.exe unicorn-21940.exe unicorn-28485.exe unicorn-32660.exe backgroundtransferhost.exe unicorn-4857.exe unicorn-37207.exe unicorn-60892.exe unicorn-57073.exe unicorn-50851.exe unicorn-21748.exe unicorn-50166.exe unicorn-14540.exe unicorn-46658.exe unicorn-46658.exe unicorn-54504.exe unicorn-2702.exe unicorn-57841.exe backgroundtransferhost.exe no specs unicorn-61925.exe unicorn-61925.exe unicorn-2610.exe unicorn-2610.exe unicorn-564.exe unicorn-6694.exe unicorn-38605.exe unicorn-62994.exe unicorn-62994.exe unicorn-57327.exe unicorn-40543.exe unicorn-207.exe unicorn-46144.exe unicorn-46144.exe unicorn-59879.exe unicorn-61432.exe unicorn-42443.exe unicorn-41204.exe unicorn-35728.exe unicorn-55594.exe unicorn-42173.exe unicorn-31967.exe unicorn-36051.exe unicorn-43954.exe unicorn-61110.exe unicorn-15438.exe unicorn-23607.exe unicorn-23607.exe unicorn-14461.exe unicorn-37997.exe unicorn-33150.exe unicorn-22215.exe unicorn-42081.exe unicorn-46833.exe unicorn-33097.exe unicorn-42657.exe unicorn-61494.exe unicorn-44987.exe unicorn-5992.exe unicorn-57815.exe unicorn-41479.exe unicorn-62454.exe unicorn-54286.exe unicorn-20675.exe unicorn-41598.exe unicorn-25335.exe unicorn-12982.exe werfault.exe no specs unicorn-16975.exe unicorn-53072.exe unicorn-15568.exe unicorn-64769.exe unicorn-13430.exe unicorn-13430.exe unicorn-32459.exe unicorn-42019.exe unicorn-5817.exe unicorn-64577.exe unicorn-48796.exe unicorn-50742.exe unicorn-5070.exe unicorn-9154.exe unicorn-9154.exe unicorn-13238.exe unicorn-50498.exe unicorn-25297.exe unicorn-171.exe unicorn-13906.exe unicorn-21909.exe unicorn-14561.exe unicorn-34427.exe unicorn-24121.exe backgroundtransferhost.exe no specs unicorn-14369.exe unicorn-34134.exe unicorn-17707.exe unicorn-28013.exe unicorn-62637.exe unicorn-49009.exe unicorn-49101.exe unicorn-28589.exe unicorn-20320.exe werfault.exe no specs unicorn-24867.exe unicorn-40156.exe unicorn-40156.exe werfault.exe no specs unicorn-12755.exe unicorn-58692.exe unicorn-51915.exe unicorn-19010.exe unicorn-4852.exe unicorn-4852.exe unicorn-768.exe unicorn-49777.exe unicorn-9491.exe unicorn-33441.exe unicorn-37525.exe unicorn-39471.exe unicorn-23689.exe unicorn-27773.exe unicorn-47639.exe unicorn-41509.exe unicorn-62029.exe unicorn-57183.exe unicorn-576.exe unicorn-576.exe unicorn-4560.exe unicorn-14774.exe unicorn-49320.exe unicorn-43455.exe unicorn-49585.exe unicorn-25081.exe unicorn-5215.exe unicorn-54992.exe unicorn-28349.exe unicorn-48215.exe unicorn-28349.exe unicorn-12013.exe unicorn-60559.exe unicorn-20611.exe unicorn-29476.exe unicorn-37909.exe unicorn-30103.exe unicorn-9704.exe unicorn-1436.exe unicorn-5428.exe unicorn-60659.exe unicorn-26979.exe unicorn-46845.exe unicorn-61235.exe unicorn-65319.exe unicorn-24022.exe unicorn-24287.exe unicorn-7758.exe unicorn-26787.exe unicorn-14456.exe unicorn-55489.exe unicorn-45838.exe unicorn-2667.exe unicorn-6751.exe unicorn-23109.exe unicorn-6772.exe unicorn-12802.exe unicorn-21525.exe unicorn-32958.exe unicorn-59103.exe unicorn-51505.exe unicorn-54219.exe unicorn-18017.exe unicorn-35645.exe unicorn-54603.exe unicorn-6279.exe unicorn-42713.exe unicorn-40021.exe unicorn-3840.exe unicorn-11816.exe unicorn-34929.exe backgroundtransferhost.exe no specs unicorn-53404.exe unicorn-52657.exe unicorn-50611.exe unicorn-40405.exe unicorn-15085.exe unicorn-14338.exe unicorn-49149.exe unicorn-63539.exe unicorn-40.exe no specs unicorn-6170.exe unicorn-40981.exe unicorn-41535.exe unicorn-61401.exe unicorn-4032.exe unicorn-38843.exe unicorn-61301.exe unicorn-20923.exe unicorn-40789.exe unicorn-47587.exe unicorn-38350.exe unicorn-38350.exe unicorn-35889.exe unicorn-42111.exe unicorn-29204.exe unicorn-3025.exe unicorn-9247.exe unicorn-44058.exe unicorn-16669.exe unicorn-20753.exe unicorn-61785.exe unicorn-24928.exe unicorn-61553.exe no specs unicorn-63823.exe unicorn-61023.exe unicorn-61023.exe unicorn-4151.exe unicorn-17223.exe unicorn-47971.exe unicorn-35719.exe unicorn-8976.exe unicorn-53736.exe unicorn-64307.exe unicorn-13715.exe unicorn-61100.exe unicorn-23829.exe unicorn-59070.exe unicorn-38027.exe no specs unicorn-33124.exe unicorn-2662.exe no specs unicorn-50457.exe no specs unicorn-10493.exe no specs unicorn-27634.exe no specs unicorn-5240.exe no specs unicorn-52403.exe no specs unicorn-50841.exe no specs unicorn-49258.exe no specs unicorn-18531.exe no specs unicorn-52687.exe no specs unicorn-49887.exe no specs unicorn-32970.exe no specs unicorn-43035.exe no specs unicorn-43084.exe no specs unicorn-53150.exe no specs unicorn-22423.exe no specs unicorn-32729.exe no specs unicorn-36813.exe no specs unicorn-30704.exe no specs unicorn-51780.exe no specs unicorn-21053.exe no specs unicorn-8146.exe no specs unicorn-59948.exe no specs unicorn-633.exe no specs unicorn-28402.exe no specs unicorn-22536.exe no specs unicorn-8801.exe no specs unicorn-14831.exe no specs unicorn-9231.exe no specs unicorn-57810.exe no specs unicorn-40157.exe no specs unicorn-18095.exe no specs unicorn-18095.exe no specs unicorn-64032.exe no specs unicorn-41473.exe no specs unicorn-41473.exe no specs unicorn-55209.exe no specs unicorn-3870.exe no specs unicorn-14176.exe no specs unicorn-35251.exe no specs unicorn-48987.exe no specs unicorn-63020.exe no specs unicorn-57155.exe no specs unicorn-40495.exe no specs unicorn-52164.exe no specs unicorn-63099.exe no specs unicorn-29051.exe no specs unicorn-39165.exe no specs unicorn-12614.exe no specs unicorn-25329.exe no specs unicorn-12065.exe no specs unicorn-30805.exe no specs unicorn-45771.exe no specs unicorn-654.exe no specs unicorn-19683.exe no specs unicorn-8822.exe no specs unicorn-12906.exe no specs unicorn-28920.exe no specs unicorn-31381.exe no specs unicorn-31381.exe no specs unicorn-45579.exe no specs unicorn-29243.exe no specs unicorn-39357.exe no specs unicorn-27659.exe no specs unicorn-41395.exe no specs unicorn-42049.exe no specs unicorn-23021.exe no specs unicorn-14037.exe no specs unicorn-33903.exe no specs unicorn-18937.exe no specs unicorn-42071.exe no specs unicorn-15428.exe no specs unicorn-54878.exe no specs unicorn-21651.exe no specs unicorn-16804.exe no specs unicorn-7160.exe no specs unicorn-13290.exe no specs unicorn-1038.exe no specs unicorn-25735.exe no specs unicorn-40679.exe no specs unicorn-13290.exe no specs unicorn-33903.exe no specs unicorn-31765.exe no specs unicorn-25735.exe no specs unicorn-21459.exe no specs unicorn-56269.exe no specs unicorn-25543.exe no specs unicorn-29627.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
632C:\Users\admin\AppData\Local\Temp\Unicorn-46658.exeC:\Users\admin\AppData\Local\Temp\Unicorn-46658.exe
Unicorn-46362.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-46658.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
660C:\Users\admin\AppData\Local\Temp\Unicorn-46362.exeC:\Users\admin\AppData\Local\Temp\Unicorn-46362.exe
Unicorn-62088.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-46362.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
668C:\Users\admin\AppData\Local\Temp\Unicorn-57327.exeC:\Users\admin\AppData\Local\Temp\Unicorn-57327.exe
Unicorn-58277.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-57327.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
732C:\Users\admin\AppData\Local\Temp\Unicorn-21940.exeC:\Users\admin\AppData\Local\Temp\Unicorn-21940.exe
Unicorn-25605.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-21940.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
856C:\Users\admin\AppData\Local\Temp\Unicorn-2610.exeC:\Users\admin\AppData\Local\Temp\Unicorn-2610.exe
Unicorn-4774.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-2610.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
872C:\Users\admin\AppData\Local\Temp\Unicorn-35889.exeC:\Users\admin\AppData\Local\Temp\Unicorn-35889.exe
Unicorn-46144.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-35889.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
924C:\Users\admin\AppData\Local\Temp\Unicorn-29204.exeC:\Users\admin\AppData\Local\Temp\Unicorn-29204.exe
Unicorn-19719.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-29204.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
976C:\Users\admin\AppData\Local\Temp\Unicorn-61432.exeC:\Users\admin\AppData\Local\Temp\Unicorn-61432.exe
Unicorn-33638.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-61432.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1052C:\Users\admin\AppData\Local\Temp\Unicorn-54530.exeC:\Users\admin\AppData\Local\Temp\Unicorn-54530.exe
Unicorn-20400.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-54530.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
1132C:\Users\admin\AppData\Local\Temp\Unicorn-46144.exeC:\Users\admin\AppData\Local\Temp\Unicorn-46144.exe
Unicorn-3601.exe
User:
admin
Company:
UEFI
Integrity Level:
MEDIUM
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\unicorn-46144.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
Total events
13 722
Read events
13 707
Write events
15
Delete events
0

Modification events

(PID) Process:(4172) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4172) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4172) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7484) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7484) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7484) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3008) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3008) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3008) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(9092) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
Executable files
1 152
Suspicious files
14
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
70001 (345).exeC:\Users\admin\AppData\Local\Temp\Unicorn-38377.exeexecutable
MD5:FD1C6145B5879F4B49EF84137471157C
SHA256:FEB48D4255043BE9B285E4DF275AE59BF1B609F01E27540FC8DEDBF215D74DE5
7396Unicorn-63313.exeC:\Users\admin\AppData\Local\Temp\Unicorn-62088.exeexecutable
MD5:CF9FCADC1787DACB0CB036247D2D2BF2
SHA256:78249405C04441492E6082754A286EFAA0C42274411F87E275AAD627C394E4F4
7848Unicorn-38377.exeC:\Users\admin\AppData\Local\Temp\Unicorn-20501.exeexecutable
MD5:4AE6BCFA694237F2591FB18368B4BF50
SHA256:7CAA7199AD09B9CEFA662D35F919537F51F371917B807C06A6B111FAB0C5C262
7396Unicorn-63313.exeC:\Users\admin\AppData\Local\Temp\Unicorn-52213.exeexecutable
MD5:0F15DCB0915C63FAF11D00585631008A
SHA256:B2DFC188FE2A14AFCB2CAD7A6D9AA14CEC526C100C2EABCE6E3CEC33A560D5ED
7868Unicorn-43059.exeC:\Users\admin\AppData\Local\Temp\Unicorn-25605.exeexecutable
MD5:948872D94F44D1AB65B1DC34EEB3C77D
SHA256:AAD2D84A294D3F101840967396AAD08911ED7A2D4074421905ADAEA1F98FDFA6
7828Unicorn-52213.exeC:\Users\admin\AppData\Local\Temp\Unicorn-43059.exeexecutable
MD5:87C7C033B2E95CCC2C7F74588270C4C6
SHA256:8F8E2556328C8AC7B343CC85DEC4B819A7AFB5C4E7EABC6F4ECFC6EF90216BEF
70001 (345).exeC:\Users\admin\AppData\Local\Temp\Unicorn-20400.exeexecutable
MD5:8DF717E5AD17CAD6C5E92D51D0F37638
SHA256:2ED86437EEC901B03DA72BC1B904DBFE2FF79F6CD0CF00A61992A449A6174FD4
7904Unicorn-20501.exeC:\Users\admin\AppData\Local\Temp\Unicorn-54193.exeexecutable
MD5:756F799638F395E881DC17FF9BA90534
SHA256:55D51EEF979CC7A1D64972502093063B1C1FCF830CAEBF923D7B18E20C979F9E
7920Unicorn-20400.exeC:\Users\admin\AppData\Local\Temp\Unicorn-58277.exeexecutable
MD5:55C4B27E03E3A3E8A365B5B3F6467800
SHA256:E84E2F178EA894061DEEE6BB0395C826238D112567F3D97BF7D4B9DF2C94ACE4
7396Unicorn-63313.exeC:\Users\admin\AppData\Local\Temp\Unicorn-48063.exeexecutable
MD5:E3CFBCF1E150D5BCE9BE4EFE8647A361
SHA256:671FEB854E9B445FFE76481CB228A5ADB73C0A954905970876091C8FBEAEABF4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
24
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7484
BackgroundTransferHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
7576
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
2.19.11.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
8588
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
8588
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.19.11.120:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
20.190.159.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
7576
backgroundTaskHost.exe
20.199.58.43:443
arc.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
7576
backgroundTaskHost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 2.19.11.120
  • 2.19.11.105
whitelisted
google.com
  • 142.250.184.206
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 20.190.159.73
  • 40.126.31.128
  • 40.126.31.69
  • 40.126.31.71
  • 40.126.31.1
  • 20.190.159.4
  • 40.126.31.3
  • 40.126.31.130
whitelisted
ocsp.digicert.com
  • 184.30.131.245
  • 2.23.77.188
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
www.bing.com
  • 23.15.178.226
  • 23.15.178.200
  • 23.15.178.147
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted

Threats

No threats detected
No debug info