| File name: | 1 (39) |
| Full analysis: | https://app.any.run/tasks/7ad28336-9e24-458e-9828-8900ebf179bd |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2025, 19:43:43 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, 3 sections |
| MD5: | 0E130A3B78A715398D5FA40F18CA27B0 |
| SHA1: | 068C34DC4E0EF1544038902362576272A2947684 |
| SHA256: | E79DDC15A8300C62E374840C8FBA0C80109D5D1DB8F7CD5383F751DD09983F66 |
| SSDEEP: | 6144:LHKOE7I+hDyHA5l35U1mRLfx5tBqcvJGB9/Wyei/Tk/8SwjwpyAvEhEAf1ybvYua:Lq3M5HA5t586Bdha9Oyei/yx4DxmDsR |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:01:19 13:34:56+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit, No debug, Removable run from swap, Net run from swap, Uniprocessor only, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 299008 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13d4 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | UEFI |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 208 | C:\Users\admin\AppData\Local\Temp\Unicorn-26843.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-26843.exe | Unicorn-17311.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 664 | C:\Users\admin\AppData\Local\Temp\Unicorn-44342.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-44342.exe | Unicorn-17725.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 668 | C:\Users\admin\AppData\Local\Temp\Unicorn-47871.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-47871.exe | Unicorn-40689.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 728 | C:\Users\admin\AppData\Local\Temp\Unicorn-26875.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-26875.exe | Unicorn-36007.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 968 | C:\Users\admin\AppData\Local\Temp\Unicorn-18427.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-18427.exe | Unicorn-39271.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1116 | C:\Users\admin\AppData\Local\Temp\Unicorn-33035.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-33035.exe | — | Unicorn-19335.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1180 | C:\Users\admin\AppData\Local\Temp\Unicorn-5005.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-5005.exe | — | Unicorn-36007.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1228 | C:\Users\admin\AppData\Local\Temp\Unicorn-12219.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-12219.exe | Unicorn-47889.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1280 | C:\Users\admin\AppData\Local\Temp\Unicorn-37343.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-37343.exe | 1 (39).exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1388 | C:\Users\admin\AppData\Local\Temp\Unicorn-20269.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-20269.exe | Unicorn-17725.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6004 | 1 (39).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-37343.exe | executable | |
MD5:016D6284317E1517E2857BE052C8F399 | SHA256:89624AD54732542E653D086CC352DA7E27C80BD6DBBDC1458D60143FFAEEBC87 | |||
| 6108 | Unicorn-47889.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-237.exe | executable | |
MD5:14CFB99B6AFBDBFE7BF9C0E80C104491 | SHA256:E289E19DFEE1BCB6BBBE24CE3F37CB05FE8886FE50BD044C0121D204ED1A060C | |||
| 6108 | Unicorn-47889.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-3924.exe | executable | |
MD5:A75BE29E63D2D852262A51365365A1B9 | SHA256:EE9054A70A962EBDCB1FAE6A631299D8735191C8F623CEDD3E5DD3CE83F07CEF | |||
| 1280 | Unicorn-37343.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-20103.exe | executable | |
MD5:27A0369474DDB4F5A22BB6EA7F820170 | SHA256:CFB175759293977C1FB7AEA73093845F45F96A7DFC17913D0AC5F6E5A3A95442 | |||
| 6004 | 1 (39).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-47889.exe | executable | |
MD5:5DEBA57273D027C3049DD7C5255DF66A | SHA256:3BF67B7DA6E9DF1B4B35CFA94AE6E945AAB2CC9BCAB19BC74F84C230520FB2AA | |||
| 2140 | Unicorn-3924.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-17725.exe | executable | |
MD5:7D0A06812BFA8C4054C7EEA6B8F78E36 | SHA256:EAF0FE41681A4F70A37A7244A3093D0D483BFD1FF888D2CBFCDD5788721B2AB2 | |||
| 5776 | Unicorn-20103.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-35453.exe | executable | |
MD5:A152FECC434D087E921CDA4942292B60 | SHA256:355B4C6CF77F2A4D33C9A935943D6E609DAC0C4503C9387186F2FC0605D2CB66 | |||
| 5452 | Unicorn-237.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-8810.exe | executable | |
MD5:76B0F3480E3B2EE7C4F63C77D5645DBE | SHA256:56505F51FE8641D3181024475E61B265319900D307B44417821739FA3144F857 | |||
| 6108 | Unicorn-47889.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-49743.exe | executable | |
MD5:53192A9E27548E4352EB5E9460DAC4D0 | SHA256:44198E0325A08F44D42A69E10513E51C5A69BDE11B2D96A50BE1FC8615632879 | |||
| 1280 | Unicorn-37343.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-36007.exe | executable | |
MD5:F30559BF38A97362610199647998B749 | SHA256:9E16598F8324F48728E86CDDF1E4CB27C0587F3342F6594836CDA67F7C991CB4 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.48.23.10:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5956 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
7736 | SIHClient.exe | GET | 200 | 23.52.120.96:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7736 | SIHClient.exe | GET | 200 | 23.52.120.96:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 23.48.23.10:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
2104 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3216 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 20.190.160.2:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
2112 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 20.190.160.2:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |