Publish Date: November 19, 2014
NSS Labs is providing an IDA DB to researchers interested in performing further analysis of the malware discussed in our blog post, Unicorn Just Got Real. Note that this is not a completely reversed version. We focused on the most important aspects of the malware and provided comments for better understanding. Decompilation should be available inside the IDB as well with the recovered data structure. Some parts of the IDB have not been commented on and were left purely for the reader’s and researcher’s interest.