Malicious
Classifications
Virus
Threat Names
KawaiiUnicorn
Dynamic Analysis Report
Created on 2024-08-01T15:30:17+00:00
Kawaii-Unicorn.exe
Windows Exe (x86-32)
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "16 minutes, 12 seconds" to "1 second" to reveal dormant functionality.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\OqXZRaykm\Desktop\Kawaii-Unicorn.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Verdict |
Malicious
|
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
kawaii-unicorn.exe | 1 | 0x00400000 | 0x00474FFF | Relevant Image |
![]() |
32-bit | 0x004013D4 |
![]() |
...
|
buffer | 1 | 0x020B0000 | 0x0215FFFF | Marked Executable |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x020B0000 | 0x020B9FFF | First Execution |
![]() |
32-bit | 0x020B5318 |
![]() |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-183.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-36048.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-50206.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-50206.exe | 51 | 0x00400000 | 0x00474FFF | Relevant Image |
![]() |
32-bit | 0x004013D4 |
![]() |
...
|
buffer | 51 | 0x004D0000 | 0x004DFFFF | Marked Executable |
![]() |
32-bit | - |
![]() |
...
|
buffer | 51 | 0x004D0000 | 0x004DFFFF | First Execution |
![]() |
32-bit | 0x004D5318 |
![]() |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-34283.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-34283.exe | 82 | 0x00400000 | 0x00474FFF | Relevant Image |
![]() |
32-bit | 0x004013D4 |
![]() |
...
|
buffer | 82 | 0x004C0000 | 0x004CFFFF | Marked Executable |
![]() |
32-bit | - |
![]() |
...
|
buffer | 82 | 0x004C0000 | 0x004CFFFF | First Execution |
![]() |
32-bit | 0x004C5318 |
![]() |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-23257.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-23257.exe | 66 | 0x00400000 | 0x00474FFF | Relevant Image |
![]() |
32-bit | 0x004013D4 |
![]() |
...
|
buffer | 66 | 0x004D0000 | 0x004DFFFF | Marked Executable |
![]() |
32-bit | - |
![]() |
...
|
buffer | 66 | 0x004D0000 | 0x004DFFFF | First Execution |
![]() |
32-bit | 0x004D5318 |
![]() |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-61101.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-61101.exe | 20 | 0x00400000 | 0x00474FFF | Relevant Image |
![]() |
32-bit | 0x004013D4 |
![]() |
...
|
buffer | 20 | 0x004C0000 | 0x004CFFFF | Marked Executable |
![]() |
32-bit | - |
![]() |
...
|
buffer | 20 | 0x004C0000 | 0x004CFFFF | First Execution |
![]() |
32-bit | 0x004C5318 |
![]() |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-30812.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-33308.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-30351.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-30351.exe | 36 | 0x00400000 | 0x00474FFF | Relevant Image |
![]() |
32-bit | 0x004013D4 |
![]() |
...
|
buffer | 36 | 0x004C0000 | 0x004CFFFF | Marked Executable |
![]() |
32-bit | - |
![]() |
...
|
buffer | 36 | 0x004C0000 | 0x004CFFFF | First Execution |
![]() |
32-bit | 0x004C5318 |
![]() |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-32837.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-36864.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-36864.exe | 49 | 0x00400000 | 0x00474FFF | Relevant Image |
![]() |
32-bit | 0x004013D4 |
![]() |
...
|
buffer | 49 | 0x005C0000 | 0x005CFFFF | Marked Executable |
![]() |
32-bit | - |
![]() |
...
|
buffer | 49 | 0x005C0000 | 0x005CFFFF | First Execution |
![]() |
32-bit | 0x005C5318 |
![]() |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-62317.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-62317.exe | 92 | 0x00400000 | 0x00474FFF | Relevant Image |
![]() |
32-bit | 0x004013D4 |
![]() |
...
|
buffer | 92 | 0x00590000 | 0x005BFFFF | Marked Executable |
![]() |
32-bit | - |
![]() |
...
|
buffer | 92 | 0x00590000 | 0x005BFFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-50222.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-50222.exe | 34 | 0x00400000 | 0x00474FFF | Relevant Image |
![]() |
32-bit | 0x004013D4 |
![]() |
...
|
buffer | 34 | 0x006B0000 | 0x006BFFFF | Marked Executable |
![]() |
32-bit | - |
![]() |
...
|
buffer | 34 | 0x006B0000 | 0x006BFFFF | First Execution |
![]() |
32-bit | 0x006B5318 |
![]() |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-11779.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-11779.exe | 70 | 0x00400000 | 0x00474FFF | Relevant Image |
![]() |
32-bit | 0x004013D4 |
![]() |
...
|
buffer | 70 | 0x006A0000 | 0x006AFFFF | Marked Executable |
![]() |
32-bit | - |
![]() |
...
|
buffer | 70 | 0x006A0000 | 0x006AFFFF | First Execution |
![]() |
32-bit | 0x006A5318 |
![]() |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-48636.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
unicorn-48636.exe | 21 | 0x00400000 | 0x00474FFF | Relevant Image |
![]() |
32-bit | 0x004013D4 |
![]() |
...
|
buffer | 21 | 0x004C0000 | 0x004CFFFF | Marked Executable |
![]() |
32-bit | - |
![]() |
...
|
buffer | 21 | 0x004C0000 | 0x004CFFFF | First Execution |
![]() |
32-bit | 0x004C5318 |
![]() |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-59261.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-33432.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.01 |
.rsrc | 0x0042D000 | 0x000479F8 | 0x00048000 | 0x0002D000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
Imports (1)
»
MSVBVM60.DLL (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CIcos | - | 0x00401000 | 0x0002B0CC | 0x0002B0CC | 0x00000000 |
_adj_fptan | - | 0x00401004 | 0x0002B0D0 | 0x0002B0D0 | 0x00000000 |
__vbaVarMove | - | 0x00401008 | 0x0002B0D4 | 0x0002B0D4 | 0x00000000 |
__vbaFreeVar | - | 0x0040100C | 0x0002B0D8 | 0x0002B0D8 | 0x00000000 |
None | 0x0000024C | 0x00401010 | 0x0002B0DC | 0x0002B0DC | - |
__vbaFreeVarList | - | 0x00401014 | 0x0002B0E0 | 0x0002B0E0 | 0x00000000 |
__vbaEnd | - | 0x00401018 | 0x0002B0E4 | 0x0002B0E4 | 0x00000000 |
_adj_fdiv_m64 | - | 0x0040101C | 0x0002B0E8 | 0x0002B0E8 | 0x00000000 |
__vbaFreeObjList | - | 0x00401020 | 0x0002B0EC | 0x0002B0EC | 0x00000000 |
_adj_fprem1 | - | 0x00401024 | 0x0002B0F0 | 0x0002B0F0 | 0x00000000 |
__vbaStrCat | - | 0x00401028 | 0x0002B0F4 | 0x0002B0F4 | 0x00000000 |
__vbaSetSystemError | - | 0x0040102C | 0x0002B0F8 | 0x0002B0F8 | 0x00000000 |
__vbaHresultCheckObj | - | 0x00401030 | 0x0002B0FC | 0x0002B0FC | 0x00000000 |
_adj_fdiv_m32 | - | 0x00401034 | 0x0002B100 | 0x0002B100 | 0x00000000 |
__vbaAryDestruct | - | 0x00401038 | 0x0002B104 | 0x0002B104 | 0x00000000 |
None | 0x00000251 | 0x0040103C | 0x0002B108 | 0x0002B108 | - |
None | 0x00000252 | 0x00401040 | 0x0002B10C | 0x0002B10C | - |
__vbaOnError | - | 0x00401044 | 0x0002B110 | 0x0002B110 | 0x00000000 |
__vbaObjSet | - | 0x00401048 | 0x0002B114 | 0x0002B114 | 0x00000000 |
_adj_fdiv_m16i | - | 0x0040104C | 0x0002B118 | 0x0002B118 | 0x00000000 |
_adj_fdivr_m16i | - | 0x00401050 | 0x0002B11C | 0x0002B11C | 0x00000000 |
_CIsin | - | 0x00401054 | 0x0002B120 | 0x0002B120 | 0x00000000 |
__vbaChkstk | - | 0x00401058 | 0x0002B124 | 0x0002B124 | 0x00000000 |
__vbaFileClose | - | 0x0040105C | 0x0002B128 | 0x0002B128 | 0x00000000 |
EVENT_SINK_AddRef | - | 0x00401060 | 0x0002B12C | 0x0002B12C | 0x00000000 |
__vbaGenerateBoundsError | - | 0x00401064 | 0x0002B130 | 0x0002B130 | 0x00000000 |
__vbaPutOwner3 | - | 0x00401068 | 0x0002B134 | 0x0002B134 | 0x00000000 |
DllFunctionCall | - | 0x0040106C | 0x0002B138 | 0x0002B138 | 0x00000000 |
_adj_fpatan | - | 0x00401070 | 0x0002B13C | 0x0002B13C | 0x00000000 |
__vbaRedim | - | 0x00401074 | 0x0002B140 | 0x0002B140 | 0x00000000 |
__vbaStrR8 | - | 0x00401078 | 0x0002B144 | 0x0002B144 | 0x00000000 |
EVENT_SINK_Release | - | 0x0040107C | 0x0002B148 | 0x0002B148 | 0x00000000 |
None | 0x00000258 | 0x00401080 | 0x0002B14C | 0x0002B14C | - |
__vbaUI1I2 | - | 0x00401084 | 0x0002B150 | 0x0002B150 | 0x00000000 |
_CIsqrt | - | 0x00401088 | 0x0002B154 | 0x0002B154 | 0x00000000 |
EVENT_SINK_QueryInterface | - | 0x0040108C | 0x0002B158 | 0x0002B158 | 0x00000000 |
__vbaExceptHandler | - | 0x00401090 | 0x0002B15C | 0x0002B15C | 0x00000000 |
_adj_fprem | - | 0x00401094 | 0x0002B160 | 0x0002B160 | 0x00000000 |
_adj_fdivr_m64 | - | 0x00401098 | 0x0002B164 | 0x0002B164 | 0x00000000 |
__vbaFPException | - | 0x0040109C | 0x0002B168 | 0x0002B168 | 0x00000000 |
__vbaGetOwner3 | - | 0x004010A0 | 0x0002B16C | 0x0002B16C | 0x00000000 |
__vbaUbound | - | 0x004010A4 | 0x0002B170 | 0x0002B170 | 0x00000000 |
__vbaStrVarVal | - | 0x004010A8 | 0x0002B174 | 0x0002B174 | 0x00000000 |
__vbaVarCat | - | 0x004010AC | 0x0002B178 | 0x0002B178 | 0x00000000 |
_CIlog | - | 0x004010B0 | 0x0002B17C | 0x0002B17C | 0x00000000 |
__vbaErrorOverflow | - | 0x004010B4 | 0x0002B180 | 0x0002B180 | 0x00000000 |
__vbaFileOpen | - | 0x004010B8 | 0x0002B184 | 0x0002B184 | 0x00000000 |
__vbaNew2 | - | 0x004010BC | 0x0002B188 | 0x0002B188 | 0x00000000 |
None | 0x0000023A | 0x004010C0 | 0x0002B18C | 0x0002B18C | - |
__vbaR8Str | - | 0x004010C4 | 0x0002B190 | 0x0002B190 | 0x00000000 |
_adj_fdiv_m32i | - | 0x004010C8 | 0x0002B194 | 0x0002B194 | 0x00000000 |
_adj_fdivr_m32i | - | 0x004010CC | 0x0002B198 | 0x0002B198 | 0x00000000 |
__vbaFreeStrList | - | 0x004010D0 | 0x0002B19C | 0x0002B19C | 0x00000000 |
_adj_fdivr_m32 | - | 0x004010D4 | 0x0002B1A0 | 0x0002B1A0 | 0x00000000 |
_adj_fdiv_r | - | 0x004010D8 | 0x0002B1A4 | 0x0002B1A4 | 0x00000000 |
None | 0x00000064 | 0x004010DC | 0x0002B1A8 | 0x0002B1A8 | - |
__vbaI4Var | - | 0x004010E0 | 0x0002B1AC | 0x0002B1AC | 0x00000000 |
__vbaVarMod | - | 0x004010E4 | 0x0002B1B0 | 0x0002B1B0 | 0x00000000 |
_CIatan | - | 0x004010E8 | 0x0002B1B4 | 0x0002B1B4 | 0x00000000 |
__vbaStrMove | - | 0x004010EC | 0x0002B1B8 | 0x0002B1B8 | 0x00000000 |
_allmul | - | 0x004010F0 | 0x0002B1BC | 0x0002B1BC | 0x00000000 |
_CItan | - | 0x004010F4 | 0x0002B1C0 | 0x0002B1C0 | 0x00000000 |
__vbaFPInt | - | 0x004010F8 | 0x0002B1C4 | 0x0002B1C4 | 0x00000000 |
__vbaUI1Var | - | 0x004010FC | 0x0002B1C8 | 0x0002B1C8 | 0x00000000 |
_CIexp | - | 0x00401100 | 0x0002B1CC | 0x0002B1CC | 0x00000000 |
__vbaFreeStr | - | 0x00401104 | 0x0002B1D0 | 0x0002B1D0 | 0x00000000 |
__vbaFreeObj | - | 0x00401108 | 0x0002B1D4 | 0x0002B1D4 | 0x00000000 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
KawaiiUnicorn | KawaiiUnicorn | Virus |
5/5
|
...
|
C:\Users\OqXZRaykm\Desktop\Unicorn-20961.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004013D4 |
Size Of Code | 0x0002B000 |
Size Of Initialized Data | 0x00049000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-01-19 14:34 (UTC+1) |
Version Information (6)
»
CompanyName | UEFI |
ProductName | Kawaii-Unicorn |
FileVersion | 1.00 |
ProductVersion | 1.00 |
InternalName | Kawaii-Unicorn |
OriginalFilename | Kawaii-Unicorn.exe |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0002A5C4 | 0x00C3B000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.85 |
.data | 0x0042C000 | 0x00000A20 | 0x00001000 | 0x0002C000 |