| File name: | 1 (633) |
| Full analysis: | https://app.any.run/tasks/3b5bae3d-ed6a-45ec-8793-81793110f9de |
| Verdict: | Malicious activity |
| Analysis date: | March 25, 2025, 02:08:50 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, 3 sections |
| MD5: | 61FA97B648FBDBC12104792F8C314E90 |
| SHA1: | 0303569A69F7B33BB5361EC4A7A0C8BB6095B7EE |
| SHA256: | F9D80164EC356B232FB31C71663340E7661B2FD0F5C1AFC2669EDFDD67BF8F79 |
| SSDEEP: | 6144:p7K0fxIDvDoqA5Umh4hD/ifx/tBKlvJGBH/Wyej6rk/8SwjwpyAvEh/quu5x3Mxa:p+ii4qA5phkSBshaHOyej6bx4DxmDsR |
| .exe | | | Win32 Executable Microsoft Visual Basic 6 (90.6) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (4.9) |
| .exe | | | Generic Win/DOS Executable (2.2) |
| .exe | | | DOS Executable Generic (2.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:01:19 13:34:56+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit, No debug, Removable run from swap, Net run from swap, Uniprocessor only, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 176128 |
| InitializedDataSize: | 299008 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x13d4 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Unicode |
| CompanyName: | UEFI |
| ProductName: | Kawaii-Unicorn |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | Kawaii-Unicorn |
| OriginalFileName: | Kawaii-Unicorn.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 496 | C:\Users\admin\AppData\Local\Temp\Unicorn-46393.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-46393.exe | — | Unicorn-49951.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 | |||||||||||||||
| 660 | C:\Users\admin\AppData\Local\Temp\Unicorn-7253.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-7253.exe | Unicorn-55862.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 664 | C:\Users\admin\AppData\Local\Temp\Unicorn-7957.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-7957.exe | Unicorn-53117.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 720 | C:\Users\admin\AppData\Local\Temp\Unicorn-54870.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-54870.exe | Unicorn-30879.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 776 | C:\Users\admin\AppData\Local\Temp\Unicorn-25059.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-25059.exe | — | Unicorn-920.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 856 | C:\Users\admin\AppData\Local\Temp\Unicorn-4766.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-4766.exe | Unicorn-8725.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 864 | C:\Users\admin\AppData\Local\Temp\Unicorn-64548.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-64548.exe | Unicorn-51743.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1116 | C:\Users\admin\AppData\Local\Temp\Unicorn-28486.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-28486.exe | — | Unicorn-4220.exe | |||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
| 1164 | C:\Users\admin\AppData\Local\Temp\Unicorn-24179.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-24179.exe | 1 (633).exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 1164 | C:\Users\admin\AppData\Local\Temp\Unicorn-3861.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-3861.exe | Unicorn-39213.exe | ||||||||||||
User: admin Company: UEFI Integrity Level: MEDIUM Version: 1.00 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7300 | 1 (633).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-34431.exe | executable | |
MD5:379EAC46D0F7214E79FBDB39B2B5CCF4 | SHA256:9C20B1414B386FA51B5E313DAA7000117A478223B35829FE051615D700B9EA03 | |||
| 2320 | Unicorn-14335.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-36511.exe | executable | |
MD5:CA3D0734A3CFF4AC1E9F939EF3B419D3 | SHA256:D3DDAF2D28B114EB9C9DC5231773B19A3BCE10C6810E4C358D398DA55664A003 | |||
| 8024 | Unicorn-51743.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-51222.exe | executable | |
MD5:B773F833A82B000BFA72691E0267133E | SHA256:33A011A0AD3EE837730402F84A7080530A9E21DF3C32DA5D31D2153102F1AC1D | |||
| 8044 | Unicorn-64934.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-34201.exe | executable | |
MD5:D40634BB060975AA1F379BF67D42B690 | SHA256:A2571E423417CB0676091DD080C26DDF87F3558CDD78F29228C3FBD68729CFEA | |||
| 8024 | Unicorn-51743.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-37532.exe | executable | |
MD5:98A6A2DD7B485944483F8D200E997E1D | SHA256:EBE8DE43DAC065C287D3CBA47B84398969599442ABAF82F53FAB9C913CD15BD1 | |||
| 6620 | Unicorn-34201.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-37881.exe | executable | |
MD5:0147C1C8D26DBC037C6786BB7C3CA6D6 | SHA256:6C303ACE36D4CE60C9480F3FF207455F8FBE75D8434B366D1C4640C7854088B3 | |||
| 7492 | Unicorn-34431.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-14335.exe | executable | |
MD5:B17B1027C55A489C74A222E17DB350E9 | SHA256:5F029D13F6FE5333BD1DF51C879157D1A0E61C9A2A59B65DD86E42AA82826898 | |||
| 7300 | 1 (633).exe | C:\Users\admin\AppData\Local\Temp\Unicorn-36452.exe | executable | |
MD5:FD6E8FBFA23E9C1030A0DE9499427DDB | SHA256:C213E844F13ECA87A9874E92512A35D930E00292194B1E325F5FF41E01A58B8F | |||
| 8184 | Unicorn-51222.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-7128.exe | executable | |
MD5:B9FC5DF5DD60432033E84AC17AA51F91 | SHA256:5DD1BB4CCCFFD962C5F2E8330D44107C283BF72A259B463AA0727E69E8BCB27D | |||
| 4776 | Unicorn-36452.exe | C:\Users\admin\AppData\Local\Temp\Unicorn-55862.exe | executable | |
MD5:EB7AC377D0960BFD7FFAED14EEB7E484 | SHA256:618B55A48226A9B6DA7AD04FDEFC2E0CA3590006E96DDA8F70D79A73091AB82A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.16.164.120:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
7748 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
8332 | SIHClient.exe | GET | 200 | 23.52.120.96:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
8332 | SIHClient.exe | GET | 200 | 23.52.120.96:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.16.164.120:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
3216 | svchost.exe | 40.115.3.253:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 20.190.160.65:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
2104 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
7748 | backgroundTaskHost.exe | 20.31.169.57:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
7748 | backgroundTaskHost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |