| File name: | 1 (705) |
| Full analysis: | https://app.any.run/tasks/cbdaf9e7-caea-4faf-8ae9-f518a84398b2 |
| Verdict: | Malicious activity |
| Analysis date: | March 25, 2025, 03:24:57 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections |
| MD5: | 82AF62909B14FCC9379B734DE01E2980 |
| SHA1: | B8327866126147AFDD6C7B881C6BB01474A96BE6 |
| SHA256: | F506A5329EAAC9E35D3A140F743F91369761DD366BD1326EF40E71FC91BFDF83 |
| SSDEEP: | 6144:2NEybXIJADmLA5BgojSEiCSx5trql38GBV/2yeXdSk/8SwjwpyAvEhNXSz7ns6wS:2ycYRLA5yoejrMMaVuyeXdWx4nxmDsR |
| .exe | | | DOS Executable Generic (100) |
|---|
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:01:19 13:34:56+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 299008 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13d4 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | UEFI |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 664 | C:\Users\admin\AppData\Local\Temp\Unicorn-7384.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-7384.exe | Unicorn-61148.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 668 | C:\Users\admin\AppData\Local\Temp\Unicorn-34261.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-34261.exe | Unicorn-54053.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 856 | C:\Users\admin\AppData\Local\Temp\Unicorn-10450.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-10450.exe | Unicorn-44636.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 904 | C:\Users\admin\AppData\Local\Temp\Unicorn-63209.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-63209.exe | — | Unicorn-48575.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1020 | C:\Users\admin\AppData\Local\Temp\Unicorn-1519.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-1519.exe | Unicorn-61029.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1052 | C:\Users\admin\AppData\Local\Temp\Unicorn-60803.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-60803.exe | Unicorn-15108.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1056 | C:\Users\admin\AppData\Local\Temp\Unicorn-36341.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-36341.exe | Unicorn-30629.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1188 | C:\Users\admin\AppData\Local\Temp\Unicorn-31765.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-31765.exe | Unicorn-62776.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1388 | C:\Users\admin\AppData\Local\Temp\Unicorn-33493.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-33493.exe | Unicorn-63845.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1660 | C:\Users\admin\AppData\Local\Temp\Unicorn-33720.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-33720.exe | Unicorn-14690.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4776 | Unicorn-61148.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-61029.exe | executable | |
MD5:FCC264CCEBC868B9AB513420BD2E3151 | SHA256:5790E1B6A77EEF590C273CC44D61209C504F577418143D674466CF5A89BA34D2 | |||
| 6808 | Unicorn-11828.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-15108.exe | executable | |
MD5:219B7321E2979E0DA513290F4236BB1C | SHA256:05B626FDAB75FE449377401A49814C1CB045C29FB170259DF926FFAAE0A20298 | |||
| 4736 | Unicorn-63416.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-11828.exe | executable | |
MD5:C4821CA97BE4C6390324EF574F03F0CE | SHA256:86E8251D3B123CACBD2793BB1F7189197362CBB83659BE4D6E65364C839F9F70 | |||
| 6808 | Unicorn-11828.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-47340.exe | executable | |
MD5:5B6289104E1778C6553CB9E2A2A2BC66 | SHA256:685119E40AA2710EA778B70786E605B8DB1905AAD615B99FCE6A342718532E37 | |||
| 4736 | Unicorn-63416.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-44636.exe | executable | |
MD5:D2861AE58CF606924431675A842B2AC3 | SHA256:57812AA474FD7FE391AEF93D914C2FB03DAEDCD64A7E1F05E8E9F98A40D795D1 | |||
| 2384 | Unicorn-64277.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-40971.exe | executable | |
MD5:C6AD612B43D4733366D0A413AB79A3EA | SHA256:FBB3D291585E8F7CC8606E554FF771166BAAFDFE4E2B2737A248D2B821310620 | |||
| 5256 | 1 (705).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-64277.exe | executable | |
MD5:633D753D93845F3ADA11DE8614121CDA | SHA256:C25AE21BC7B7DAE846A3266BAD94225287E616CBC87131789C40B5859CDC0480 | |||
| 5256 | 1 (705).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-61148.exe | executable | |
MD5:37D002F16295975068E18654B42A19AB | SHA256:5D6DED019AF07B51F4A84EAC8B75D93A37109FDAFE965A5346672D563D6228D1 | |||
| 2384 | Unicorn-64277.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-63416.exe | executable | |
MD5:C37CBE1BB08875F779FF25043EC46018 | SHA256:98C1120D3356F296746D2BB1AF119D5B312856AA18E94F5AEAD6CDB1E4E9ECB9 | |||
| 5256 | 1 (705).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-29727.exe | executable | |
MD5:36BC4AC2F89656F131203D35329E1ED4 | SHA256:AA6A512AC25461A865EDB06956161A65EA7514600ADD67715F7965BBE9D7DA95 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4896 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
9028 | SIHClient.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
9028 | SIHClient.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2104 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 23.216.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2112 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3216 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 20.190.159.2:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6544 | svchost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
4896 | backgroundTaskHost.exe | 20.199.58.43:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |