| File name: | 1 (1133) |
| Full analysis: | https://app.any.run/tasks/8a7274af-c734-48c1-ab6f-161705bede30 |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2025, 09:02:10 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, 3 sections |
| MD5: | 6221386F66067013D625613D73B48B20 |
| SHA1: | E4968C15B2E3D72858157D9A401BA605FFE1E7C7 |
| SHA256: | E5F79C40018404F83C0E71DF0FD19737FFD239DC9B3DB534FEE6373E09B8F442 |
| SSDEEP: | 12288:raX2EjHA5sUU7BchaVOye5Sex4DxmDsR:raGE056BchN5 |
| .exe | | | Win32 Executable Microsoft Visual Basic 6 (90.6) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (4.9) |
| .exe | | | Generic Win/DOS Executable (2.2) |
| .exe | | | DOS Executable Generic (2.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:01:19 13:34:56+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit, No debug, Removable run from swap, Net run from swap, Uniprocessor only, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 299008 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13d4 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | UEFI |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 668 | C:\Users\admin\AppData\Local\Temp\Unicorn-10935.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-10935.exe | Unicorn-37172.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 720 | C:\Users\admin\AppData\Local\Temp\Unicorn-40447.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-40447.exe | Unicorn-30639.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 732 | C:\Users\admin\AppData\Local\Temp\Unicorn-31142.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-31142.exe | — | Unicorn-22783.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 776 | C:\Users\admin\AppData\Local\Temp\Unicorn-24191.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-24191.exe | — | Unicorn-4909.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 | |||||||||||||||
| 856 | C:\Users\admin\AppData\Local\Temp\Unicorn-50505.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-50505.exe | Unicorn-23436.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 872 | C:\Users\admin\AppData\Local\Temp\Unicorn-62553.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-62553.exe | Unicorn-63333.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 900 | C:\Users\admin\AppData\Local\Temp\Unicorn-13908.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-13908.exe | — | Unicorn-50575.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1040 | C:\Users\admin\AppData\Local\Temp\Unicorn-25617.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-25617.exe | Unicorn-50136.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1128 | C:\Users\admin\AppData\Local\Temp\Unicorn-20609.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-20609.exe | Unicorn-21324.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1132 | C:\Users\admin\AppData\Local\Temp\Unicorn-36312.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-36312.exe | Unicorn-56537.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4528 | 1 (1133).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-56734.exe | executable | |
MD5:12476B9C49C7D36A170176D5C3B1B519 | SHA256:3B9D3EA3A49C60631D6D084B44AFCB874B387695A751EEF22D0A7F181449005B | |||
| 1168 | Unicorn-21324.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-20609.exe | executable | |
MD5:41EEAD5744D5E9726FC1EA4812A2B000 | SHA256:49084C7C9EA3B5B00EC9062A770602149E14046A046FA7B2986AF6FD9CB9FF88 | |||
| 2432 | Unicorn-14936.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-50401.exe | executable | |
MD5:9862C8659DB4E47B8F44296B55AE3365 | SHA256:62EDAC979FD81D478BA6CFAD7817C86D284F06292FD0DCC9A55E7DCF6E479462 | |||
| 4996 | Unicorn-8806.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-16001.exe | executable | |
MD5:8D67A80444F5F2DEB5CFE6463016E257 | SHA256:8B6F5C90598A094E95D60F8669DAF0E4D64AF102A97176934F9C00BFA78E8B4D | |||
| 1660 | Unicorn-37740.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-23436.exe | executable | |
MD5:23AA36CC99879CE4D066689399B61E85 | SHA256:3107FC1F9512E0708A028BDFA089A199A02211110864029CB5295BD50DAA3805 | |||
| 4528 | 1 (1133).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-50136.exe | executable | |
MD5:B30C1BBE219AF4296223F9A9EE884C2C | SHA256:96F381C30C6281A5E5BDED39BAD6318C759019C005146BF7B40C392DC48D1466 | |||
| 1760 | Unicorn-56734.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-28812.exe | executable | |
MD5:DA92068B35880BC87D8DDD757BC73FDF | SHA256:56860517BB8A36EE10612AF34E7CBC054F24C325672876D2DD38D47DE02D7C7D | |||
| 2092 | Unicorn-31953.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-36945.exe | executable | |
MD5:0758425A5CCFE64CE8CA00F867C68E61 | SHA256:39D579CD7A3A4114772B5F57EB2C4A5ADE617140A2490A02584BAA0FA0E9AAC1 | |||
| 5344 | Unicorn-55777.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-743.exe | executable | |
MD5:734A77FE2DBAAE86323F6774CDAFFD4E | SHA256:41513048DC389E85FCBEE30A7C68072586F32AC3E6C5BF1880CF05DB559E0804 | |||
| 7148 | Unicorn-16001.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-50204.exe | executable | |
MD5:B1C931D6A8A8FA979B4356A6A5BF83F0 | SHA256:DB6B224A31D5FA664D1086B5A8CCFC2E327B64E481929DECEC3D0D6906188BE6 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6544 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.16.164.9:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6660 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
8168 | SIHClient.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
8168 | SIHClient.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 2.16.164.9:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
2104 | svchost.exe | 51.124.78.146:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2112 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3216 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 40.126.31.0:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6544 | svchost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
6660 | backgroundTaskHost.exe | 20.103.156.88:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |