| File name: | 1 (597) |
| Full analysis: | https://app.any.run/tasks/e5b25682-e61d-4c65-b92d-987b742786e2 |
| Verdict: | Malicious activity |
| Analysis date: | March 25, 2025, 03:06:26 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, 3 sections |
| MD5: | 51A8599D92099AAC0BE28015E92B38A0 |
| SHA1: | 0489E33C413FA85FEE235650A45BAAC49AF2D821 |
| SHA256: | F92CB1335E7423CFCEA900C3A07E49369DE83D106D334774576CF460B417932F |
| SSDEEP: | 6144:a7K8f7IJeDzHA5D0Use+3AfxatXQlvJGBH/0yeOUnk/8SwjwpyAvEhrss20+sHda:a+aMCHA54UPGXmhaHMyeOUxx4DxmDsR |
| .exe | | | Win32 Executable Microsoft Visual Basic 6 (90.6) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (4.9) |
| .exe | | | Generic Win/DOS Executable (2.2) |
| .exe | | | DOS Executable Generic (2.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:01:19 13:34:56+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit, No debug, Removable run from swap, Net run from swap, Uniprocessor only, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 299008 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13d4 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | UEFI |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 300 | "C:\Users\admin\AppData\Local\Temp\1 (597).exe" | C:\Users\admin\AppData\Local\Temp\1 (597).exe | explorer.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 516 | C:\Users\admin\AppData\Local\Temp\Unicorn-35318.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-35318.exe | — | Unicorn-48430.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 660 | C:\Users\admin\AppData\Local\Temp\Unicorn-26497.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-26497.exe | 1 (597).exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 672 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 736 | C:\Users\admin\AppData\Local\Temp\Unicorn-21726.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-21726.exe | Unicorn-7418.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 920 | C:\Users\admin\AppData\Local\Temp\Unicorn-49593.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-49593.exe | — | Unicorn-32142.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1012 | C:\Users\admin\AppData\Local\Temp\Unicorn-60018.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-60018.exe | 1 (597).exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1052 | C:\Users\admin\AppData\Local\Temp\Unicorn-40831.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-40831.exe | — | Unicorn-11674.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1056 | C:\Users\admin\AppData\Local\Temp\Unicorn-59230.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-59230.exe | Unicorn-56718.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1088 | C:\Users\admin\AppData\Local\Temp\Unicorn-40574.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-40574.exe | Unicorn-32424.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5772 | Unicorn-6074.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-7901.exe | executable | |
MD5:253AF0381F7DA0820AAED1B396DE92F8 | SHA256:6A7B23F9421A96412E09DD0F5BBC64E200B120EA11264C0C8586C6625022FF4E | |||
| 300 | 1 (597).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-2628.exe | executable | |
MD5:42465E0AA7E9395D2753BD3C62D02A15 | SHA256:7EF7C41444F6E75BF015319974F4C4019D9DE062F27107965F35F74B78F893D6 | |||
| 736 | Unicorn-21726.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-22318.exe | executable | |
MD5:A2E073989721ACD9830DB581D74BB873 | SHA256:1E67E3A1E4EA33CE978CB0035FC5B60E6B2829D1CEFD06293A8FDA73338A48CA | |||
| 1128 | Unicorn-7418.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-21726.exe | executable | |
MD5:82177AC32A459B53BF265B4A52350DE9 | SHA256:B4632A9DC093087522F14C22410846123EA70EF4824BCABCF4F1E315232F85D3 | |||
| 2268 | Unicorn-2628.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-6074.exe | executable | |
MD5:26EBF7464E6A594C5841443ADFFFA383 | SHA256:0E1E566C812937676FA1857C521403FAABF6C101784FF3D3E57734C4B0AC779D | |||
| 660 | Unicorn-26497.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-19073.exe | executable | |
MD5:EC3A3213922440E26FAC057812E084F6 | SHA256:17839D00B73420C7F8A006CF4CDF6885842419242DAAE74DB71480EAAE50B626 | |||
| 660 | Unicorn-26497.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-7418.exe | executable | |
MD5:102EEE941BF87847068C2BC56F81F50B | SHA256:2FC5090078CB00037D3CE0BB10D9B468E4E8AF1A77C6EB32D615196C60106DD6 | |||
| 1128 | Unicorn-7418.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-19665.exe | executable | |
MD5:B2002DC4AD3EF3F4F235131E88D5A657 | SHA256:A722D1A17F495CBA824FAC66A284DFCA6042E667BE1DD823878223DA158BAF6C | |||
| 300 | 1 (597).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-26497.exe | executable | |
MD5:B52A2FF083BF316F172011EA706CFDCA | SHA256:F2342650476F7F9E34AC7DF35A31D93358B31B16FC06ABFD9108DA6D0125C2D7 | |||
| 300 | 1 (597).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-32424.exe | executable | |
MD5:5B73852E4469362163253A21D0AED6C6 | SHA256:221390B8A04A799FFB1226FDC500F34D04AD549285D67E16B4FA6A2AFA22C8C2 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.216.77.28:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6944 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7932 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7932 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.216.77.28:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
3216 | svchost.exe | 40.113.110.67:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 20.190.160.65:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
6944 | backgroundTaskHost.exe | 20.31.169.57:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6944 | backgroundTaskHost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2104 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |