| File name: | 1 (705) |
| Full analysis: | https://app.any.run/tasks/cbdaf9e7-caea-4faf-8ae9-f518a84398b2 |
| Verdict: | Malicious activity |
| Analysis date: | March 25, 2025, 03:24:57 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections |
| MD5: | 82AF62909B14FCC9379B734DE01E2980 |
| SHA1: | B8327866126147AFDD6C7B881C6BB01474A96BE6 |
| SHA256: | F506A5329EAAC9E35D3A140F743F91369761DD366BD1326EF40E71FC91BFDF83 |
| SSDEEP: | 6144:2NEybXIJADmLA5BgojSEiCSx5trql38GBV/2yeXdSk/8SwjwpyAvEhNXSz7ns6wS:2ycYRLA5yoejrMMaVuyeXdWx4nxmDsR |
| .exe | | | DOS Executable Generic (100) |
|---|
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:01:19 13:34:56+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 299008 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13d4 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | UEFI |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 664 | C:\Users\admin\AppData\Local\Temp\Unicorn-7384.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-7384.exe | Unicorn-61148.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 668 | C:\Users\admin\AppData\Local\Temp\Unicorn-34261.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-34261.exe | Unicorn-54053.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 856 | C:\Users\admin\AppData\Local\Temp\Unicorn-10450.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-10450.exe | Unicorn-44636.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 904 | C:\Users\admin\AppData\Local\Temp\Unicorn-63209.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-63209.exe | — | Unicorn-48575.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1020 | C:\Users\admin\AppData\Local\Temp\Unicorn-1519.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-1519.exe | Unicorn-61029.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1052 | C:\Users\admin\AppData\Local\Temp\Unicorn-60803.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-60803.exe | Unicorn-15108.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1056 | C:\Users\admin\AppData\Local\Temp\Unicorn-36341.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-36341.exe | Unicorn-30629.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1188 | C:\Users\admin\AppData\Local\Temp\Unicorn-31765.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-31765.exe | Unicorn-62776.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1388 | C:\Users\admin\AppData\Local\Temp\Unicorn-33493.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-33493.exe | Unicorn-63845.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1660 | C:\Users\admin\AppData\Local\Temp\Unicorn-33720.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-33720.exe | Unicorn-14690.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5256 | 1 (705).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-64277.exe | executable | |
MD5:633D753D93845F3ADA11DE8614121CDA | SHA256:C25AE21BC7B7DAE846A3266BAD94225287E616CBC87131789C40B5859CDC0480 | |||
| 3132 | Unicorn-54899.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-29992.exe | executable | |
MD5:BC28A00524595C4D06BF426E8AEB1ED3 | SHA256:72674A571D046151AEED916C3CEAADEC8A3133C1EDC70279A631E1DE458C538F | |||
| 5256 | 1 (705).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-29727.exe | executable | |
MD5:36BC4AC2F89656F131203D35329E1ED4 | SHA256:AA6A512AC25461A865EDB06956161A65EA7514600ADD67715F7965BBE9D7DA95 | |||
| 6872 | Unicorn-40971.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-47973.exe | executable | |
MD5:B9215F6207F89E9769F2016D78EF5C71 | SHA256:8B2427393744D1B3200C890290042201451A875D8B6788D724AA65E91AABB857 | |||
| 2384 | Unicorn-64277.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-40971.exe | executable | |
MD5:C6AD612B43D4733366D0A413AB79A3EA | SHA256:FBB3D291585E8F7CC8606E554FF771166BAAFDFE4E2B2737A248D2B821310620 | |||
| 6808 | Unicorn-11828.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-15108.exe | executable | |
MD5:219B7321E2979E0DA513290F4236BB1C | SHA256:05B626FDAB75FE449377401A49814C1CB045C29FB170259DF926FFAAE0A20298 | |||
| 4736 | Unicorn-63416.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-44636.exe | executable | |
MD5:D2861AE58CF606924431675A842B2AC3 | SHA256:57812AA474FD7FE391AEF93D914C2FB03DAEDCD64A7E1F05E8E9F98A40D795D1 | |||
| 2384 | Unicorn-64277.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-57795.exe | executable | |
MD5:9F2F94010F816A9FB0DC5F3F85F36962 | SHA256:014E19B4BCE3A30A70BE49EF1B5F358311B963405F1BDD008C86259805D89663 | |||
| 4776 | Unicorn-61148.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-43182.exe | executable | |
MD5:255C0A76CBA05033E8FF7D1A291C5C90 | SHA256:CE26BA617E9395E356E4D53BAB98DD23BD7380937F9C4F3E1E6108A11F48E794 | |||
| 7224 | Unicorn-15108.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-48373.exe | executable | |
MD5:9AAC383682CD53ED1D359433B32F7874 | SHA256:DB8878668CFBB6FE74D12521E625E1C50D799EC6B8826B2DEC6A708B5EECB8DC | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4896 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
9028 | SIHClient.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
9028 | SIHClient.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2104 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 23.216.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2112 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3216 | svchost.exe | 40.113.103.199:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 20.190.159.2:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6544 | svchost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
4896 | backgroundTaskHost.exe | 20.199.58.43:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |