Hostile 93% Download

caef58b60f4c9b8f562de706e97da9ee656e3c0cf8091d397cc5f6a326248ab3

Kawaii-Unicorn ransomware marker

Kawaii-Unicorn writes randomized executable replicasKawaii-Unicorn family identity
SHA-256caef58b60f4c9b8f562de706e97da9ee656e3c0cf8091d397cc5f6a326248ab3

Evidence

Overlapping PE section file or virtual ranges 0x0–0xd0
0x04d5a90000300000004000000ffff0000MZ..............
0x10b8000000000000004000000000000000........@.......
0x2000000000000000000000000000000000................
0x30000000000000000000000000b8000000................
⋯10 more rows
MSVBVM60.DLL runtime reference 0x1b8–0x338
⋯7 more rows
0x2286cda5b4a100000000000000000003800l.[J..........8.
0x2384d535642564d36302e444c4c00000000MSVBVM60.DLL....
0x24800000000000000000000000000000000................
⋯15 more rows
VB6 runtime binary file write 0xfbc–0x11bc
⋯7 more rows
0x102c3ac3a07274a2a1726e02a372fec1a172:..rt..rn..r...r
0x103c05cda1723acda1729d49a272f19fa172...r:..r.I.r...r
0x104c0603a3720604a372ee94a372ea62a372...r...r...r.b.r
0x105c7d41a172749ba07210c4a1726c57a272}A.rt..r...rlW.r
0x106cfda09472f609a3720ac3a1729b05a272...r...r...r...r
0x107c879ba07269cea072dc19a2729395a372...ri..r...r...r
0x108c859aa072df47a2728906a372ba03a372...r.G.r...r...r
0x109c1375a4725057a2725ac6a1724819a272.u.rPW.rZ..rH..r
0x10ac7d69a2722b94a37267e8a072103da172}i.r+..rg..r.=.r
0x10bc37a2a1721856a272ea10a2723a03a3727..r.V.r...r:..r
0x10cc3a04a372016ca2726e03a372a9fda272:..r.l.rn..r...r
⋯15 more rows
Kawaii-Unicorn embedded product marker 0x291c0–0x293a0
⋯8 more rows
0x2924087000000960000009700000000000000................
0x292500000000000000000000000004b617761............Kawa
0x2926069692d556e69636f726e004b61776169ii-Unicorn.Kawai
0x29270692d556e69636f726e00005662310000i-Unicorn..Vb1..
⋯19 more rows
Embedded cmd rename with quoted source 0x298d0–0x29bc0
⋯3 more rows
0x299002e3dfbfcfaa06810a73808002b3371b5.=....h..8..+3q.
0x29910433a5c50726f6772616d2046696c6573C:\Program Files
0x299202028783836295c4d6963726f736f6674 (x86)\Microsoft
0x299302056697375616c2053747564696f5c56 Visual Studio\V
0x299404239385c5642362e4f4c420056420000B98\VB6.OLB.VB..
0x2995000994200000000000600000009000000..B.............
⋯6 more rows
0x299c054696d65723100000700000075736572Timer1......user
0x299d0333200001b0000005365744c6179657232......SetLayer
0x299e0656457696e646f774174747269627574edWindowAttribut
0x299f065730000cc994200d899420000000400es....B...B.....
0x29a00d4c242000000000000000000a1dcc242..B............B
0x29a10000bc07402ffe068f4994200b8d01240...t...h..B....@
0x29a2000ffd0ffe00000000f00000047657457............GetW
0x29a30696e646f774c6f6e67410000cc994200indowLongA....B.
0x29a402c9a420000000400e0c2420000000000,.B.......B.....
0x29a5000000000a1e8c242000bc07402ffe068.......B...t...h
0x29a603c9a4200b8d0124000ffd0ffe0000000<.B....@........
0x29a700f00000053657457696e646f774c6f6e....SetWindowLon
0x29a8067410000cc994200749a420000000400gA....B.t.B.....
0x29a90ecc242000000000000000000a1f4c242..B............B
⋯9 more rows
0x29b30ffffffff01000000d94ead339966cf11.........N.3.f..
0x29b40b70c00aa0060d393120000005c005500.....`......\.U.
0x29b506e00690063006f0072006e002d000000n.i.c.o.r.n.-...
0x29b60e14ead339966cf11b70c00aa0060d393.N.3.f.......`..
0x29b705f5f766261467265655374724c697374__vbaFreeStrList
0x29b80000000001e00000063006d0064002000........c.m.d. .
0x29b902f0063002000720065006e0061006d00/.c. .r.e.n.a.m.
0x29ba065002000220000000c0000002e006500e. .".........e.
0x29bb078006500220020000000000008000000x.e.". .........
0x29bc02e006400690065000000000056424136..d.i.e.....VBA6

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.