| File name: | 1 (252) |
| Full analysis: | https://app.any.run/tasks/b78e60b2-cf0e-4f07-b744-65377504e1b0 |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2025, 18:58:08 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections |
| MD5: | 5D8F4CD8BDB38EB6F6F173F1E4A66580 |
| SHA1: | D906664BCAADA03D04234B06D2DC24E0B43E5B94 |
| SHA256: | E0A9BA7E9BF7FB05D2A1DFB860D1C9BF7B407ABE00E23B3F2519C07440ED0338 |
| SSDEEP: | 6144:S7NgAAIBMDfHAkRXTZeMvvfC4KBql/JGBCIW2erdak/8SwjwpyivEhIowRmAs/2a:ShZPkHAkBTYDBMRaCz2erd3x4DxmDsR |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:01:20 00:32:00+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 299008 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13d4 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | UEFI |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 300 | C:\Users\admin\AppData\Local\Temp\Unicorn-12284.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-12284.exe | — | Unicorn-38653.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 664 | C:\Users\admin\AppData\Local\Temp\Unicorn-25743.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-25743.exe | — | Unicorn-47231.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 | |||||||||||||||
| 684 | C:\Users\admin\AppData\Local\Temp\Unicorn-17276.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-17276.exe | — | Unicorn-51927.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 776 | C:\Users\admin\AppData\Local\Temp\Unicorn-31343.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-31343.exe | — | Unicorn-12041.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 856 | C:\Users\admin\AppData\Local\Temp\Unicorn-25743.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-25743.exe | — | Unicorn-47231.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 896 | C:\Users\admin\AppData\Local\Temp\Unicorn-35995.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-35995.exe | Unicorn-38653.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 904 | C:\Users\admin\AppData\Local\Temp\Unicorn-27735.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-27735.exe | — | Unicorn-42431.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 960 | C:\Users\admin\AppData\Local\Temp\Unicorn-55404.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-55404.exe | Unicorn-15663.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 976 | C:\Users\admin\AppData\Local\Temp\Unicorn-47231.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-47231.exe | Unicorn-62607.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1096 | C:\Users\admin\AppData\Local\Temp\Unicorn-7468.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-7468.exe | — | Unicorn-38653.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 | |||||||||||||||
| (PID) Process: | (7724) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (7724) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (7724) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (9000) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (9000) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (9000) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (10084) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (10084) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (10084) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (12956) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4892 | Unicorn-62477.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-46826.exe | executable | |
MD5:04BECF60BA6AC976E91885B61C21C48B | SHA256:C34C48DF3A72CC55E3C39F94125CD64A97149A78FA951347365F5E9042EB6145 | |||
| 4892 | Unicorn-62477.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-41071.exe | executable | |
MD5:38C30FD431591BE815A308AFFC40D01B | SHA256:3E9B84900C2044C0AB30A8ACCEB1A7030DDCB37BD09C551E8F30E1E98F419B25 | |||
| 5324 | 1 (252).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-62477.exe | executable | |
MD5:D65955889F039A5B757BEEEB1655F23D | SHA256:C26103F79D6A3267F96226DA35E803C409B0F58DF8062C7626569EDE2265D4C5 | |||
| 5324 | 1 (252).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-59218.exe | executable | |
MD5:E22BE97BE6AE128709FAC4C60F1AD1A0 | SHA256:FC0FF6DE8A4CB2BA551D16AA8E3EB2C1DF3E01601F95C81DC7CF616765530C5A | |||
| 6192 | Unicorn-29373.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-62607.exe | executable | |
MD5:2589166A15B9A0D2E2A279A0A2426F25 | SHA256:5B3AFE7B8BBE5826103293BB2308B56065FF6BD1E9ADE806072AB4FFDE62E038 | |||
| 5324 | 1 (252).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-29373.exe | executable | |
MD5:AEFD4AB88389E31064CBDD03BA2A1659 | SHA256:244C4A4B01488509C1F100AFEA171C1921EDD053817D1A4975E545AC2FF9695C | |||
| 5720 | Unicorn-41071.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-27797.exe | executable | |
MD5:0813BCBDC5B5BB836E7EDC6C4AFB4BBA | SHA256:30E70A753F12F817B6AFE7EAE443D536A45D389BB24E8EB4B1A55ECF03F71061 | |||
| 2040 | Unicorn-46826.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-7604.exe | executable | |
MD5:12D41AB3AE72D7A81F68510CA261B48B | SHA256:65C572C238857AD10ABB0731CD80F4435694F7DFEB9AE14F69B9F18407AE9A1F | |||
| 5756 | Unicorn-14558.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-44299.exe | executable | |
MD5:B8B58FC8CAAE1F00DB1B7C9662441C61 | SHA256:0F798E741E1BC4AE63A06160766FE84F751C7E2602E1BFD441135BD34C2B8AE4 | |||
| 2960 | Unicorn-2861.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-21741.exe | executable | |
MD5:5BBA116DBF304E5D41B79760144D1FF1 | SHA256:59B8800081A0452E927FC33ED08C9B9B57AF93EF00FD3DCB7F9B94507308DAED | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
8592 | SIHClient.exe | GET | 200 | 92.123.22.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.16.164.72:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
4776 | backgroundTaskHost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
8592 | SIHClient.exe | GET | 200 | 92.123.22.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
9000 | BackgroundTransferHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
3284 | svchost.exe | GET | 200 | 23.53.40.192:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
3284 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 2.16.164.72:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
5164 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4784 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2112 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3216 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 20.190.160.20:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
4776 | backgroundTaskHost.exe | 20.223.35.26:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |