PUBLICATION & RESEARCH LIBRARY

Authors: Ahmed Garhy, Jayendra Pathak and Mohamed Saher

Publish Date: November 19, 2014

NSS Labs is providing an IDA DB to researchers interested in performing further analysis of the malware discussed in our blog post, Unicorn Just Got Real. Note that this is not a completely reversed version. We focused on the most important aspects of the malware and provided comments for better understanding. Decompilation should be available inside the IDB as well with the recovered data structure. Some parts of the IDB have not been commented on and were left purely for the reader’s and researcher’s interest.