Malicious
Classifications
Virus
Threat Names
KawaiiUnicorn
Dynamic Analysis Report
Created on 2024-08-01T15:30:17+00:00
Kawaii-Unicorn.exe
Windows Exe (x86-32)
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "16 minutes, 12 seconds" to "1 second" to reveal dormant functionality.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\OqXZRaykm\Desktop\Kawaii-Unicorn.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Verdict |
Malicious
|
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
kawaii-unicorn.exe | 1 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 1 | 0x020B0000 | 0x0215FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x020B0000 | 0x020B9FFF | First Execution | 32-bit | 0x020B5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-183.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-36048.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-50206.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-50206.exe | 51 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 51 | 0x004D0000 | 0x004DFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 51 | 0x004D0000 | 0x004DFFFF | First Execution | 32-bit | 0x004D5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-34283.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-34283.exe | 82 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 82 | 0x004C0000 | 0x004CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 82 | 0x004C0000 | 0x004CFFFF | First Execution | 32-bit | 0x004C5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-23257.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-23257.exe | 66 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 66 | 0x004D0000 | 0x004DFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 66 | 0x004D0000 | 0x004DFFFF | First Execution | 32-bit | 0x004D5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-61101.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-61101.exe | 20 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 20 | 0x004C0000 | 0x004CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 20 | 0x004C0000 | 0x004CFFFF | First Execution | 32-bit | 0x004C5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-30812.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-33308.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-30351.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-30351.exe | 36 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 36 | 0x004C0000 | 0x004CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 36 | 0x004C0000 | 0x004CFFFF | First Execution | 32-bit | 0x004C5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-32837.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-36864.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-36864.exe | 49 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 49 | 0x005C0000 | 0x005CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 49 | 0x005C0000 | 0x005CFFFF | First Execution | 32-bit | 0x005C5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-62317.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-62317.exe | 92 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 92 | 0x00590000 | 0x005BFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 92 | 0x00590000 | 0x005BFFFF | Content Changed | 32-bit | - |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-50222.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-50222.exe | 34 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 34 | 0x006B0000 | 0x006BFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 34 | 0x006B0000 | 0x006BFFFF | First Execution | 32-bit | 0x006B5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-11779.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-11779.exe | 70 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 70 | 0x006A0000 | 0x006AFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 70 | 0x006A0000 | 0x006AFFFF | First Execution | 32-bit | 0x006A5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-48636.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-48636.exe | 21 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 21 | 0x004C0000 | 0x004CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 21 | 0x004C0000 | 0x004CFFFF | First Execution | 32-bit | 0x004C5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-59261.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-33432.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-20961.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-20961.exe | 64 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 64 | 0x005C0000 | 0x005CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 64 | 0x005C0000 | 0x005CFFFF | First Execution | 32-bit | 0x005C5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-26311.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-26311.exe | 58 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 58 | 0x004C0000 | 0x004CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 58 | 0x004C0000 | 0x004CFFFF | First Execution | 32-bit | 0x004C5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-45432.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-45432.exe | 27 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 27 | 0x004D0000 | 0x004DFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 27 | 0x004D0000 | 0x004DFFFF | First Execution | 32-bit | 0x004D5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-48638.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-48638.exe | 67 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 67 | 0x004C0000 | 0x004CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 67 | 0x004C0000 | 0x004CFFFF | First Execution | 32-bit | 0x004C5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-3867.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-3867.exe | 88 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 88 | 0x005A0000 | 0x005AFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 88 | 0x005A0000 | 0x005AFFFF | Content Changed | 32-bit | - |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-15591.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-15591.exe | 83 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 83 | 0x004C0000 | 0x004CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 83 | 0x004C0000 | 0x004CFFFF | Content Changed | 32-bit | - |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-47645.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-47645.exe | 81 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 81 | 0x020B0000 | 0x020DFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 81 | 0x020B0000 | 0x020B9FFF | Marked Executable | 32-bit | - |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-49068.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-64568.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-34306.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-42638.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-50424.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-50424.exe | 32 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 32 | 0x00590000 | 0x0059FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 32 | 0x00590000 | 0x0059FFFF | First Execution | 32-bit | 0x00595318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-4490.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-4490.exe | 95 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-29451.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-29451.exe | 9 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 9 | 0x020A0000 | 0x020AFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 9 | 0x020A0000 | 0x020AFFFF | First Execution | 32-bit | 0x020A5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-35061.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-35061.exe | 17 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 17 | 0x004C0000 | 0x004DFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 17 | 0x004C0000 | 0x004C9FFF | First Execution | 32-bit | 0x004C5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-37186.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-37186.exe | 50 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 50 | 0x004C0000 | 0x004EFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 50 | 0x004C0000 | 0x004C9FFF | First Execution | 32-bit | 0x004C5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-34596.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-34596.exe | 72 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 72 | 0x00590000 | 0x005CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 72 | 0x00590000 | 0x00599FFF | First Execution | 32-bit | 0x00595318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-43392.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-43392.exe | 43 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 43 | 0x00590000 | 0x0059FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 43 | 0x00590000 | 0x0059FFFF | First Execution | 32-bit | 0x00595318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-50210.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-50210.exe | 53 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 53 | 0x005D0000 | 0x005DFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 53 | 0x005D0000 | 0x005DFFFF | First Execution | 32-bit | 0x005D5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-63547.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-63547.exe | 35 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 35 | 0x020A0000 | 0x020AFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 35 | 0x020A0000 | 0x020AFFFF | First Execution | 32-bit | 0x020A5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-57162.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-57162.exe | 15 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 15 | 0x004D0000 | 0x004FFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 15 | 0x004D0000 | 0x004FFFFF | First Execution | 32-bit | 0x004D5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-37106.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-37106.exe | 63 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 63 | 0x005A0000 | 0x005AFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 63 | 0x005A0000 | 0x005AFFFF | First Execution | 32-bit | 0x005A5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-41311.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-41311.exe | 38 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 38 | 0x00590000 | 0x0059FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 38 | 0x00590000 | 0x0059FFFF | First Execution | 32-bit | 0x00595318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-36039.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-36039.exe | 85 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 85 | 0x005A0000 | 0x005AFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 85 | 0x005A0000 | 0x005AFFFF | Content Changed | 32-bit | - |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-64220.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-64220.exe | 60 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 60 | 0x005A0000 | 0x005AFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 60 | 0x005A0000 | 0x005AFFFF | First Execution | 32-bit | 0x005A5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-2545.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-2545.exe | 54 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 54 | 0x004D0000 | 0x004DFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 54 | 0x004D0000 | 0x004DFFFF | First Execution | 32-bit | 0x004D5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-4031.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-4031.exe | 62 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 62 | 0x020B0000 | 0x020FFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 62 | 0x020B0000 | 0x020FFFFF | First Execution | 32-bit | 0x020B5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-24860.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-29034.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-29034.exe | 29 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 29 | 0x005A0000 | 0x005AFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 29 | 0x005A0000 | 0x005AFFFF | First Execution | 32-bit | 0x005A5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-1002.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-1002.exe | 77 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 77 | 0x005A0000 | 0x005BFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 77 | 0x005A0000 | 0x005BFFFF | First Execution | 32-bit | 0x005A5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-51023.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-51023.exe | 10 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 10 | 0x00590000 | 0x0059FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 10 | 0x00590000 | 0x0059FFFF | First Execution | 32-bit | 0x00595318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-21999.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-21999.exe | 6 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 6 | 0x004D0000 | 0x004DFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 6 | 0x004D0000 | 0x004DFFFF | First Execution | 32-bit | 0x004D5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-39045.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-39045.exe | 75 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 75 | 0x00590000 | 0x0059FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 75 | 0x00590000 | 0x0059FFFF | Content Changed | 32-bit | - |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-32676.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-32676.exe | 45 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 45 | 0x004D0000 | 0x004DFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 45 | 0x004D0000 | 0x004DFFFF | First Execution | 32-bit | 0x004D5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-60479.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-54568.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-54568.exe | 93 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-8421.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-8421.exe | 30 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 30 | 0x005D0000 | 0x005DFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 30 | 0x005D0000 | 0x005DFFFF | First Execution | 32-bit | 0x005D5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-20429.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-20429.exe | 59 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 59 | 0x004D0000 | 0x004DFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 59 | 0x004D0000 | 0x004DFFFF | First Execution | 32-bit | 0x004D5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-29494.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-29494.exe | 48 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 48 | 0x004C0000 | 0x004CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 48 | 0x004C0000 | 0x004CFFFF | First Execution | 32-bit | 0x004C5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-31495.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-31495.exe | 89 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 89 | 0x020B0000 | 0x020EFFFF | Marked Executable | 32-bit | - |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-17496.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-23193.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-22151.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-22151.exe | 94 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-9934.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-40756.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-40756.exe | 78 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 78 | 0x00560000 | 0x0056FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 78 | 0x00560000 | 0x0056FFFF | First Execution | 32-bit | 0x00565318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-11015.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-11015.exe | 76 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 76 | 0x005B0000 | 0x0062FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 76 | 0x005B0000 | 0x0062FFFF | Content Changed | 32-bit | - |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-1075.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-1075.exe | 14 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 14 | 0x00510000 | 0x0051FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 14 | 0x00510000 | 0x0051FFFF | First Execution | 32-bit | 0x00515318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-57664.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-57664.exe | 69 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 69 | 0x004D0000 | 0x0051FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 69 | 0x004D0000 | 0x0051FFFF | First Execution | 32-bit | 0x004D5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-14755.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-49205.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-49205.exe | 44 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 44 | 0x020A0000 | 0x020AFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 44 | 0x020A0000 | 0x020AFFFF | First Execution | 32-bit | 0x020A5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-61.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-61.exe | 28 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 28 | 0x004C0000 | 0x004CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 28 | 0x004C0000 | 0x004CFFFF | First Execution | 32-bit | 0x004C5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-14785.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-14785.exe | 19 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 19 | 0x00590000 | 0x0059FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 19 | 0x00590000 | 0x0059FFFF | First Execution | 32-bit | 0x00595318 |
...
|
||
unicorn-14785.exe | 19 | 0x00400000 | 0x00474FFF | Final Dump | 32-bit | - |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-22535.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-26074.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-26074.exe | 33 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 33 | 0x005C0000 | 0x0063FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 33 | 0x005C0000 | 0x005C9FFF | First Execution | 32-bit | 0x005C5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-12573.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-12573.exe | 42 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 42 | 0x004D0000 | 0x004DFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 42 | 0x004D0000 | 0x004DFFFF | First Execution | 32-bit | 0x004D5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-24797.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-24797.exe | 22 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 22 | 0x00590000 | 0x005DFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 22 | 0x00590000 | 0x00599FFF | First Execution | 32-bit | 0x00595318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-59443.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-59443.exe | 23 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 23 | 0x005A0000 | 0x005AFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 23 | 0x005A0000 | 0x005AFFFF | First Execution | 32-bit | 0x005A5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-23076.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-23076.exe | 47 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 47 | 0x004C0000 | 0x004CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 47 | 0x004C0000 | 0x004CFFFF | First Execution | 32-bit | 0x004C5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-15335.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-15335.exe | 11 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 11 | 0x004D0000 | 0x0051FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 11 | 0x004D0000 | 0x0051FFFF | First Execution | 32-bit | 0x004D5318 |
...
|
||
unicorn-15335.exe | 11 | 0x00400000 | 0x00474FFF | Final Dump | 32-bit | - |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-60201.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-60201.exe | 24 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 24 | 0x005A0000 | 0x005CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 24 | 0x005A0000 | 0x005CFFFF | First Execution | 32-bit | 0x005A5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-14432.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-14432.exe | 39 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 39 | 0x005A0000 | 0x005BFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 39 | 0x005A0000 | 0x005A9FFF | First Execution | 32-bit | 0x005A5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-7945.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-7945.exe | 8 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 8 | 0x005D0000 | 0x005DFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 8 | 0x005D0000 | 0x005DFFFF | First Execution | 32-bit | 0x005D5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-34718.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-34718.exe | 68 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 68 | 0x00590000 | 0x005DFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 68 | 0x00590000 | 0x00599FFF | First Execution | 32-bit | 0x00595318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-46820.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-46820.exe | 86 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 86 | 0x006A0000 | 0x006AFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 86 | 0x006A0000 | 0x006AFFFF | Content Changed | 32-bit | - |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-30329.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-45209.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-45209.exe | 90 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 90 | 0x004E0000 | 0x004EFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 90 | 0x004E0000 | 0x004EFFFF | Content Changed | 32-bit | - |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-21549.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-21549.exe | 71 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 71 | 0x00590000 | 0x0059FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 71 | 0x00590000 | 0x0059FFFF | First Execution | 32-bit | 0x00595318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-18783.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-18783.exe | 31 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 31 | 0x004D0000 | 0x004DFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 31 | 0x004D0000 | 0x004DFFFF | First Execution | 32-bit | 0x004D5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-44670.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-44670.exe | 41 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 41 | 0x005A0000 | 0x005AFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 41 | 0x005A0000 | 0x005AFFFF | First Execution | 32-bit | 0x005A5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-21580.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-56237.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-56237.exe | 52 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 52 | 0x005B0000 | 0x005BFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 52 | 0x005B0000 | 0x005BFFFF | First Execution | 32-bit | 0x005B5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-60706.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-60706.exe | 12 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 12 | 0x004D0000 | 0x004DFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 12 | 0x004D0000 | 0x004DFFFF | First Execution | 32-bit | 0x004D5318 |
...
|
||
unicorn-60706.exe | 12 | 0x00400000 | 0x00474FFF | Final Dump | 32-bit | - |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-38432.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-38432.exe | 65 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 65 | 0x004C0000 | 0x004CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 65 | 0x004C0000 | 0x004CFFFF | First Execution | 32-bit | 0x004C5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-15193.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-15193.exe | 57 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 57 | 0x004D0000 | 0x004DFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 57 | 0x004D0000 | 0x004DFFFF | First Execution | 32-bit | 0x004D5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-25264.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-53104.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-7332.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-7332.exe | 16 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 16 | 0x004C0000 | 0x004CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 16 | 0x004C0000 | 0x004CFFFF | First Execution | 32-bit | 0x004C5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-33386.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-33386.exe | 46 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 46 | 0x004F0000 | 0x004FFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 46 | 0x004F0000 | 0x004FFFFF | First Execution | 32-bit | 0x004F5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-50030.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-50030.exe | 37 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 37 | 0x004C0000 | 0x004CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 37 | 0x004C0000 | 0x004CFFFF | First Execution | 32-bit | 0x004C5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-35211.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-35211.exe | 7 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 7 | 0x005A0000 | 0x005AFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 7 | 0x005A0000 | 0x005AFFFF | First Execution | 32-bit | 0x005A5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-48133.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-48133.exe | 55 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 55 | 0x004D0000 | 0x004DFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 55 | 0x004D0000 | 0x004DFFFF | First Execution | 32-bit | 0x004D5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-36274.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-36274.exe | 18 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 18 | 0x00590000 | 0x0059FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 18 | 0x00590000 | 0x0059FFFF | First Execution | 32-bit | 0x00595318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-59546.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-59546.exe | 26 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 26 | 0x004C0000 | 0x004CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 26 | 0x004C0000 | 0x004CFFFF | First Execution | 32-bit | 0x004C5318 |
...
|
||
unicorn-59546.exe | 26 | 0x00400000 | 0x00474FFF | Final Dump | 32-bit | - |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-40441.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-40441.exe | 80 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 80 | 0x00560000 | 0x0056FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 80 | 0x00560000 | 0x0056FFFF | Content Changed | 32-bit | - |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-15242.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-15242.exe | 84 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 84 | 0x020A0000 | 0x020AFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 84 | 0x020A0000 | 0x020AFFFF | First Execution | 32-bit | 0x020A5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-44780.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-44780.exe | 3 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 3 | 0x00590000 | 0x0059FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 3 | 0x00590000 | 0x0059FFFF | First Execution | 32-bit | 0x00595318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-65522.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-65522.exe | 13 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 13 | 0x005C0000 | 0x005CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 13 | 0x005C0000 | 0x005CFFFF | First Execution | 32-bit | 0x005C5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-23559.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-23559.exe | 56 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 56 | 0x00590000 | 0x0059FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 56 | 0x00590000 | 0x0059FFFF | First Execution | 32-bit | 0x00595318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-7893.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-7893.exe | 25 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 25 | 0x020A0000 | 0x020CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 25 | 0x020A0000 | 0x020A9FFF | First Execution | 32-bit | 0x020A5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-25995.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-25995.exe | 91 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 91 | 0x004D0000 | 0x004DFFFF | Marked Executable | 32-bit | - |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-3989.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-3989.exe | 74 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 74 | 0x020A0000 | 0x020AFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 74 | 0x020A0000 | 0x020AFFFF | First Execution | 32-bit | 0x020A5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-38283.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-38283.exe | 40 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 40 | 0x005A0000 | 0x005BFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 40 | 0x005A0000 | 0x005BFFFF | First Execution | 32-bit | 0x005A5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-32917.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-32917.exe | 2 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 2 | 0x004C0000 | 0x004EFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 2 | 0x004C0000 | 0x004EFFFF | First Execution | 32-bit | 0x004C5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-6413.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-6413.exe | 5 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 5 | 0x00590000 | 0x0059FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 5 | 0x00590000 | 0x0059FFFF | First Execution | 32-bit | 0x00595318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-40757.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-40757.exe | 4 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 4 | 0x004C0000 | 0x004CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 4 | 0x004C0000 | 0x004CFFFF | First Execution | 32-bit | 0x004C5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-29747.exe | Dropped File | Binary |
Clean
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-48888.exe | Dropped File | Binary |
Clean
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-48888.exe | 87 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 87 | 0x020A0000 | 0x0215FFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 87 | 0x020A0000 | 0x0215FFFF | Content Changed | 32-bit | - |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-56784.exe | Dropped File | Binary |
Clean
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-40951.exe | Dropped File | Binary |
Clean
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-51014.exe | Dropped File | Binary |
Clean
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-57342.exe | Dropped File | Binary |
Clean
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-50692.exe | Dropped File | Binary |
Clean
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-57329.exe | Dropped File | Binary |
Clean
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-64431.exe | Dropped File | Binary |
Clean
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-51968.exe | Dropped File | Binary |
Clean
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-51968.exe | 61 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 61 | 0x005A0000 | 0x005AFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 61 | 0x005A0000 | 0x005AFFFF | First Execution | 32-bit | 0x005A5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-50325.exe | Dropped File | Binary |
Clean
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-50325.exe | 79 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 79 | 0x005A0000 | 0x005AFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 79 | 0x005A0000 | 0x005AFFFF | First Execution | 32-bit | 0x005A5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-25677.exe | Dropped File | Binary |
Clean
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-25677.exe | 73 | 0x00400000 | 0x00474FFF | Relevant Image | 32-bit | 0x004013D4 |
...
|
||
buffer | 73 | 0x006A0000 | 0x006CFFFF | Marked Executable | 32-bit | - |
...
|
||
buffer | 73 | 0x006A0000 | 0x006A9FFF | First Execution | 32-bit | 0x006A5318 |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-42288.exe | Dropped File | Binary |
Clean
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-11159.exe | Dropped File | Empty |
Clean
|
...
|
»