File de8c69e6b0eda4a7_unicorn-6744.exe

Size 468.0KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 348bb11ce3d396a8b041565f657e77cc
SHA1 5a98ba95c241922fb00422ce74c981156c2a4b68
SHA256 de8c69e6b0eda4a75c8c2baaca967cdd91c6cb787ed55f1836cc631c21f5b405
SHA512
103afeb7c8ace8023473a2c7ac177a2021348bb7a576989a3b81396729607512f688e82108dc673a2e3237629271a1b831ab839bb7530b6c654c788e44b30532
CRC32 B7E6C8D5
ssdeep None
Yara
  • SEH__vba - (no description)

Score

This file is very suspicious, with a score of 10 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Autosubmit

Parent_Task_ID:6585859

Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE July 2, 2025, 12:12 p.m. July 2, 2025, 12:21 p.m. 533 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log

2025-06-24 21:29:14,030 [analyzer] DEBUG: Starting analyzer from: C:\tmptisd8w
2025-06-24 21:29:14,046 [analyzer] DEBUG: Pipe server name: \??\PIPE\rjEndPtdjtQrLfokLQesZwFWfD
2025-06-24 21:29:14,046 [analyzer] DEBUG: Log pipe server name: \??\PIPE\QGJaLdfFBxufwNNIpOiKQnroSR
2025-06-24 21:29:14,046 [analyzer] DEBUG: No analysis package specified, trying to detect it automagically.
2025-06-24 21:29:14,062 [analyzer] INFO: Automatically selected analysis package "exe"
2025-06-24 21:29:14,421 [analyzer] DEBUG: Started auxiliary module Curtain
2025-06-24 21:29:14,421 [analyzer] DEBUG: Started auxiliary module DbgView
2025-06-24 21:29:14,890 [analyzer] DEBUG: Started auxiliary module Disguise
2025-06-24 21:29:15,171 [analyzer] DEBUG: Loaded monitor into process with pid 508
2025-06-24 21:29:15,171 [analyzer] DEBUG: Started auxiliary module DumpTLSMasterSecrets
2025-06-24 21:29:15,187 [analyzer] DEBUG: Started auxiliary module Human
2025-06-24 21:29:15,187 [analyzer] DEBUG: Started auxiliary module InstallCertificate
2025-06-24 21:29:15,187 [analyzer] DEBUG: Started auxiliary module Reboot
2025-06-24 21:29:15,250 [analyzer] DEBUG: Started auxiliary module RecentFiles
2025-06-24 21:29:15,250 [analyzer] DEBUG: Started auxiliary module Screenshots
2025-06-24 21:29:15,250 [analyzer] DEBUG: Started auxiliary module Sysmon
2025-06-24 21:29:15,250 [analyzer] DEBUG: Started auxiliary module LoadZer0m0n
2025-06-24 21:29:15,500 [lib.api.process] INFO: Successfully executed process from path u'C:\\Users\\ADMINI~1\\AppData\\Local\\Temp\\de8c69e6b0eda4a7_unicorn-6744.exe' with arguments '' and pid 2796
2025-06-24 21:29:15,733 [analyzer] DEBUG: Loaded monitor into process with pid 2796
2025-06-24 21:29:18,812 [analyzer] INFO: Added new file to list with pid 2796 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-11841.exe
2025-06-24 21:29:18,937 [analyzer] INFO: Injected into process with pid 1484 and name u'Unicorn-11841.exe'
2025-06-24 21:29:19,140 [analyzer] DEBUG: Loaded monitor into process with pid 1484
2025-06-24 21:29:22,217 [analyzer] INFO: Added new file to list with pid 1484 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-55090.exe
2025-06-24 21:29:22,312 [analyzer] INFO: Injected into process with pid 3040 and name u'Unicorn-55090.exe'
2025-06-24 21:29:22,467 [analyzer] DEBUG: Loaded monitor into process with pid 3040
2025-06-24 21:29:25,546 [analyzer] INFO: Added new file to list with pid 3040 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-5801.exe
2025-06-24 21:29:25,655 [analyzer] INFO: Injected into process with pid 1488 and name u'Unicorn-5801.exe'
2025-06-24 21:29:25,828 [analyzer] DEBUG: Loaded monitor into process with pid 1488
2025-06-24 21:29:28,921 [analyzer] INFO: Added new file to list with pid 1488 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-6481.exe
2025-06-24 21:29:29,265 [analyzer] INFO: Injected into process with pid 2304 and name u'Unicorn-6481.exe'
2025-06-24 21:29:29,437 [analyzer] DEBUG: Loaded monitor into process with pid 2304
2025-06-24 21:29:32,530 [analyzer] INFO: Added new file to list with pid 2304 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-145.exe
2025-06-24 21:29:32,717 [analyzer] INFO: Injected into process with pid 2368 and name u'Unicorn-145.exe'
2025-06-24 21:29:32,905 [analyzer] DEBUG: Loaded monitor into process with pid 2368
2025-06-24 21:29:36,046 [analyzer] INFO: Added new file to list with pid 2368 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-20247.exe
2025-06-24 21:29:36,155 [analyzer] INFO: Injected into process with pid 2920 and name u'Unicorn-20247.exe'
2025-06-24 21:29:36,328 [analyzer] DEBUG: Loaded monitor into process with pid 2920
2025-06-24 21:29:39,390 [analyzer] INFO: Added new file to list with pid 2920 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-9094.exe
2025-06-24 21:29:39,578 [analyzer] INFO: Injected into process with pid 1564 and name u'Unicorn-9094.exe'
2025-06-24 21:29:39,750 [analyzer] DEBUG: Loaded monitor into process with pid 1564
2025-06-24 21:29:42,890 [analyzer] INFO: Added new file to list with pid 1564 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-646.exe
2025-06-24 21:29:43,030 [analyzer] INFO: Injected into process with pid 3060 and name u'Unicorn-646.exe'
2025-06-24 21:29:43,217 [analyzer] DEBUG: Loaded monitor into process with pid 3060
2025-06-24 21:29:46,328 [analyzer] INFO: Added new file to list with pid 3060 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27751.exe
2025-06-24 21:29:46,467 [analyzer] INFO: Injected into process with pid 2952 and name u'Unicorn-27751.exe'
2025-06-24 21:29:46,640 [analyzer] DEBUG: Loaded monitor into process with pid 2952
2025-06-24 21:29:49,717 [analyzer] INFO: Added new file to list with pid 2952 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27279.exe
2025-06-24 21:29:49,875 [analyzer] INFO: Injected into process with pid 2332 and name u'Unicorn-27279.exe'
2025-06-24 21:29:50,046 [analyzer] DEBUG: Loaded monitor into process with pid 2332
2025-06-24 21:29:53,125 [analyzer] INFO: Added new file to list with pid 2332 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-38431.exe
2025-06-24 21:29:53,265 [analyzer] INFO: Injected into process with pid 2476 and name u'Unicorn-38431.exe'
2025-06-24 21:29:53,437 [analyzer] DEBUG: Loaded monitor into process with pid 2476
2025-06-24 21:29:56,546 [analyzer] INFO: Added new file to list with pid 2476 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-46127.exe
2025-06-24 21:29:56,780 [analyzer] INFO: Injected into process with pid 2652 and name u'Unicorn-46127.exe'
2025-06-24 21:29:56,953 [analyzer] DEBUG: Loaded monitor into process with pid 2652
2025-06-24 21:30:00,078 [analyzer] INFO: Added new file to list with pid 2652 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-65255.exe
2025-06-24 21:30:00,203 [analyzer] INFO: Injected into process with pid 3120 and name u'Unicorn-65255.exe'
2025-06-24 21:30:00,358 [analyzer] DEBUG: Loaded monitor into process with pid 3120
2025-06-24 21:30:03,437 [analyzer] INFO: Added new file to list with pid 3120 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-62271.exe
2025-06-24 21:30:03,578 [analyzer] INFO: Injected into process with pid 3212 and name u'Unicorn-62271.exe'
2025-06-24 21:30:03,750 [analyzer] DEBUG: Loaded monitor into process with pid 3212
2025-06-24 21:30:06,842 [analyzer] INFO: Added new file to list with pid 3212 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-61799.exe
2025-06-24 21:30:06,953 [analyzer] INFO: Injected into process with pid 3300 and name u'Unicorn-61799.exe'
2025-06-24 21:30:07,125 [analyzer] DEBUG: Loaded monitor into process with pid 3300
2025-06-24 21:30:10,217 [analyzer] INFO: Added new file to list with pid 3300 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-31631.exe
2025-06-24 21:30:10,358 [analyzer] INFO: Injected into process with pid 3380 and name u'Unicorn-31631.exe'
2025-06-24 21:30:10,530 [analyzer] DEBUG: Loaded monitor into process with pid 3380
2025-06-24 21:30:13,625 [analyzer] INFO: Added new file to list with pid 3380 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-39711.exe
2025-06-24 21:30:13,765 [analyzer] INFO: Injected into process with pid 3476 and name u'Unicorn-39711.exe'
2025-06-24 21:30:13,937 [analyzer] DEBUG: Loaded monitor into process with pid 3476
2025-06-24 21:30:17,015 [analyzer] INFO: Added new file to list with pid 3476 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-42311.exe
2025-06-24 21:30:17,125 [analyzer] INFO: Injected into process with pid 3560 and name u'Unicorn-42311.exe'
2025-06-24 21:30:17,296 [analyzer] DEBUG: Loaded monitor into process with pid 3560
2025-06-24 21:30:20,375 [analyzer] INFO: Added new file to list with pid 3560 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27039.exe
2025-06-24 21:30:20,546 [analyzer] INFO: Injected into process with pid 3640 and name u'Unicorn-27039.exe'
2025-06-24 21:30:20,717 [analyzer] DEBUG: Loaded monitor into process with pid 3640
2025-06-24 21:30:23,812 [analyzer] INFO: Added new file to list with pid 3640 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-63359.exe
2025-06-24 21:30:23,937 [analyzer] INFO: Injected into process with pid 3744 and name u'Unicorn-63359.exe'
2025-06-24 21:30:24,171 [analyzer] DEBUG: Loaded monitor into process with pid 3744
2025-06-24 21:30:27,265 [analyzer] INFO: Added new file to list with pid 3744 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-33479.exe
2025-06-24 21:30:27,437 [analyzer] INFO: Injected into process with pid 3832 and name u'Unicorn-33479.exe'
2025-06-24 21:30:27,592 [analyzer] DEBUG: Loaded monitor into process with pid 3832
2025-06-24 21:30:30,671 [analyzer] INFO: Added new file to list with pid 3832 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-41175.exe
2025-06-24 21:30:30,953 [analyzer] INFO: Injected into process with pid 3916 and name u'Unicorn-41175.exe'
2025-06-24 21:30:31,155 [analyzer] DEBUG: Loaded monitor into process with pid 3916
2025-06-24 21:30:34,233 [analyzer] INFO: Added new file to list with pid 3916 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-2934.exe
2025-06-24 21:30:34,467 [analyzer] INFO: Injected into process with pid 4016 and name u'Unicorn-2934.exe'
2025-06-24 21:30:34,625 [analyzer] DEBUG: Loaded monitor into process with pid 4016
2025-06-24 21:30:37,703 [analyzer] INFO: Added new file to list with pid 4016 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-43687.exe
2025-06-24 21:30:37,828 [analyzer] INFO: Injected into process with pid 3076 and name u'Unicorn-43687.exe'
2025-06-24 21:30:38,000 [analyzer] DEBUG: Loaded monitor into process with pid 3076
2025-06-24 21:30:41,092 [analyzer] INFO: Added new file to list with pid 3076 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-13518.exe
2025-06-24 21:30:41,233 [analyzer] INFO: Injected into process with pid 3240 and name u'Unicorn-13518.exe'
2025-06-24 21:30:41,437 [analyzer] DEBUG: Loaded monitor into process with pid 3240
2025-06-24 21:30:44,546 [analyzer] INFO: Added new file to list with pid 3240 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-46103.exe
2025-06-24 21:30:44,655 [analyzer] INFO: Injected into process with pid 3456 and name u'Unicorn-46103.exe'
2025-06-24 21:30:44,828 [analyzer] DEBUG: Loaded monitor into process with pid 3456
2025-06-24 21:30:47,890 [analyzer] INFO: Added new file to list with pid 3456 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-34951.exe
2025-06-24 21:30:48,046 [analyzer] INFO: Injected into process with pid 3576 and name u'Unicorn-34951.exe'
2025-06-24 21:30:48,217 [analyzer] DEBUG: Loaded monitor into process with pid 3576
2025-06-24 21:30:51,328 [analyzer] INFO: Added new file to list with pid 3576 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-45719.exe
2025-06-24 21:30:51,500 [analyzer] INFO: Injected into process with pid 3656 and name u'Unicorn-45719.exe'
2025-06-24 21:30:51,671 [analyzer] DEBUG: Loaded monitor into process with pid 3656
2025-06-24 21:30:54,750 [analyzer] INFO: Added new file to list with pid 3656 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-12766.exe
2025-06-24 21:30:54,890 [analyzer] INFO: Injected into process with pid 840 and name u'Unicorn-12766.exe'
2025-06-24 21:30:55,062 [analyzer] DEBUG: Loaded monitor into process with pid 840
2025-06-24 21:30:58,155 [analyzer] INFO: Added new file to list with pid 840 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-23535.exe
2025-06-24 21:30:58,250 [analyzer] INFO: Injected into process with pid 3728 and name u'Unicorn-23535.exe'
2025-06-24 21:30:58,390 [analyzer] DEBUG: Loaded monitor into process with pid 3728
2025-06-24 21:31:01,467 [analyzer] INFO: Added new file to list with pid 3728 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-48911.exe
2025-06-24 21:31:01,578 [analyzer] INFO: Injected into process with pid 2192 and name u'Unicorn-48911.exe'
2025-06-24 21:31:01,733 [analyzer] DEBUG: Loaded monitor into process with pid 2192
2025-06-24 21:31:04,842 [analyzer] INFO: Added new file to list with pid 2192 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-32103.exe
2025-06-24 21:31:05,092 [analyzer] INFO: Injected into process with pid 1540 and name u'Unicorn-32103.exe'
2025-06-24 21:31:05,265 [analyzer] DEBUG: Loaded monitor into process with pid 1540
2025-06-24 21:31:08,358 [analyzer] INFO: Added new file to list with pid 1540 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-43063.exe
2025-06-24 21:31:08,453 [analyzer] INFO: Injected into process with pid 2316 and name u'Unicorn-43063.exe'
2025-06-24 21:31:08,608 [analyzer] DEBUG: Loaded monitor into process with pid 2316
2025-06-24 21:31:11,765 [analyzer] INFO: Added new file to list with pid 2316 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-63431.exe
2025-06-24 21:31:11,890 [analyzer] INFO: Injected into process with pid 2120 and name u'Unicorn-63431.exe'
2025-06-24 21:31:12,046 [analyzer] DEBUG: Loaded monitor into process with pid 2120
2025-06-24 21:31:15,140 [analyzer] INFO: Added new file to list with pid 2120 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-25095.exe
2025-06-24 21:31:15,233 [analyzer] INFO: Injected into process with pid 2588 and name u'Unicorn-25095.exe'
2025-06-24 21:31:15,405 [analyzer] DEBUG: Loaded monitor into process with pid 2588
2025-06-24 21:31:18,483 [analyzer] INFO: Added new file to list with pid 2588 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-1270.exe
2025-06-24 21:31:18,640 [analyzer] INFO: Injected into process with pid 3104 and name u'Unicorn-1270.exe'
2025-06-24 21:31:18,828 [analyzer] DEBUG: Loaded monitor into process with pid 3104
2025-06-24 21:31:21,921 [analyzer] INFO: Added new file to list with pid 3104 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-25687.exe
2025-06-24 21:31:22,000 [analyzer] INFO: Injected into process with pid 3280 and name u'Unicorn-25687.exe'
2025-06-24 21:31:22,155 [analyzer] DEBUG: Loaded monitor into process with pid 3280
2025-06-24 21:31:25,233 [analyzer] INFO: Added new file to list with pid 3280 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-52599.exe
2025-06-24 21:31:25,328 [analyzer] INFO: Injected into process with pid 3988 and name u'Unicorn-52599.exe'
2025-06-24 21:31:25,483 [analyzer] DEBUG: Loaded monitor into process with pid 3988
2025-06-24 21:31:28,578 [analyzer] INFO: Added new file to list with pid 3988 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27623.exe
2025-06-24 21:31:28,655 [analyzer] INFO: Injected into process with pid 1300 and name u'Unicorn-27623.exe'
2025-06-24 21:31:28,828 [analyzer] DEBUG: Loaded monitor into process with pid 1300
2025-06-24 21:31:31,937 [analyzer] INFO: Added new file to list with pid 1300 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-24639.exe
2025-06-24 21:31:32,030 [analyzer] INFO: Injected into process with pid 3632 and name u'Unicorn-24639.exe'
2025-06-24 21:31:32,203 [analyzer] DEBUG: Loaded monitor into process with pid 3632
2025-06-24 21:31:35,328 [analyzer] INFO: Added new file to list with pid 3632 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27239.exe
2025-06-24 21:31:35,421 [analyzer] INFO: Injected into process with pid 4120 and name u'Unicorn-27239.exe'
2025-06-24 21:31:35,562 [analyzer] DEBUG: Loaded monitor into process with pid 4120
2025-06-24 21:31:38,655 [analyzer] INFO: Added new file to list with pid 4120 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-59631.exe
2025-06-24 21:31:38,733 [analyzer] INFO: Injected into process with pid 4200 and name u'Unicorn-59631.exe'
2025-06-24 21:31:38,890 [analyzer] DEBUG: Loaded monitor into process with pid 4200
2025-06-24 21:31:41,983 [analyzer] INFO: Added new file to list with pid 4200 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27639.exe
2025-06-24 21:31:42,062 [analyzer] INFO: Injected into process with pid 4280 and name u'Unicorn-27639.exe'
2025-06-24 21:31:42,233 [analyzer] DEBUG: Loaded monitor into process with pid 4280
2025-06-24 21:31:45,328 [analyzer] INFO: Added new file to list with pid 4280 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-55908.exe
2025-06-24 21:31:45,390 [analyzer] INFO: Injected into process with pid 4360 and name u'Unicorn-55908.exe'
2025-06-24 21:31:45,562 [analyzer] DEBUG: Loaded monitor into process with pid 4360
2025-06-24 21:31:48,655 [analyzer] INFO: Added new file to list with pid 4360 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-22764.exe
2025-06-24 21:31:48,733 [analyzer] INFO: Injected into process with pid 4440 and name u'Unicorn-22764.exe'
2025-06-24 21:31:48,890 [analyzer] DEBUG: Loaded monitor into process with pid 4440
2025-06-24 21:31:52,000 [analyzer] INFO: Added new file to list with pid 4440 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-859.exe
2025-06-24 21:31:52,062 [analyzer] INFO: Injected into process with pid 4524 and name u'Unicorn-859.exe'
2025-06-24 21:31:52,233 [analyzer] DEBUG: Loaded monitor into process with pid 4524
2025-06-24 21:31:55,342 [analyzer] INFO: Added new file to list with pid 4524 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-46692.exe
2025-06-24 21:31:55,467 [analyzer] INFO: Injected into process with pid 4604 and name u'Unicorn-46692.exe'
2025-06-24 21:31:55,640 [analyzer] DEBUG: Loaded monitor into process with pid 4604
2025-06-24 21:31:58,750 [analyzer] INFO: Added new file to list with pid 4604 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-62940.exe
2025-06-24 21:31:58,842 [analyzer] INFO: Injected into process with pid 4684 and name u'Unicorn-62940.exe'
2025-06-24 21:31:59,000 [analyzer] DEBUG: Loaded monitor into process with pid 4684
2025-06-24 21:32:02,125 [analyzer] INFO: Added new file to list with pid 4684 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-57372.exe
2025-06-24 21:32:02,203 [analyzer] INFO: Injected into process with pid 4764 and name u'Unicorn-57372.exe'
2025-06-24 21:32:02,375 [analyzer] DEBUG: Loaded monitor into process with pid 4764
2025-06-24 21:32:05,515 [analyzer] INFO: Added new file to list with pid 4764 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-56900.exe
2025-06-24 21:32:05,592 [analyzer] INFO: Injected into process with pid 4848 and name u'Unicorn-56900.exe'
2025-06-24 21:32:05,780 [analyzer] DEBUG: Loaded monitor into process with pid 4848
2025-06-24 21:32:08,937 [analyzer] INFO: Added new file to list with pid 4848 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-8763.exe
2025-06-24 21:32:09,030 [analyzer] INFO: Injected into process with pid 4936 and name u'Unicorn-8763.exe'
2025-06-24 21:32:09,203 [analyzer] DEBUG: Loaded monitor into process with pid 4936
2025-06-24 21:32:12,358 [analyzer] INFO: Added new file to list with pid 4936 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-27700.exe
2025-06-24 21:32:12,467 [analyzer] INFO: Injected into process with pid 5020 and name u'Unicorn-27700.exe'
2025-06-24 21:32:12,625 [analyzer] DEBUG: Loaded monitor into process with pid 5020
2025-06-24 21:32:15,765 [analyzer] INFO: Added new file to list with pid 5020 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-48068.exe
2025-06-24 21:32:15,842 [analyzer] INFO: Injected into process with pid 5112 and name u'Unicorn-48068.exe'
2025-06-24 21:32:16,000 [analyzer] DEBUG: Loaded monitor into process with pid 5112
2025-06-24 21:32:19,140 [analyzer] INFO: Added new file to list with pid 5112 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-9731.exe
2025-06-24 21:32:19,217 [analyzer] INFO: Injected into process with pid 4012 and name u'Unicorn-9731.exe'
2025-06-24 21:32:19,390 [analyzer] DEBUG: Loaded monitor into process with pid 4012
2025-06-24 21:32:22,562 [analyzer] INFO: Added new file to list with pid 4012 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-25596.exe
2025-06-24 21:32:22,640 [analyzer] INFO: Injected into process with pid 4456 and name u'Unicorn-25596.exe'
2025-06-24 21:32:22,812 [analyzer] DEBUG: Loaded monitor into process with pid 4456
2025-06-24 21:32:25,953 [analyzer] INFO: Added new file to list with pid 4456 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-26660.exe
2025-06-24 21:32:26,030 [analyzer] INFO: Injected into process with pid 4624 and name u'Unicorn-26660.exe'
2025-06-24 21:32:26,171 [analyzer] DEBUG: Loaded monitor into process with pid 4624
2025-06-24 21:32:29,328 [analyzer] INFO: Added new file to list with pid 4624 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-21092.exe
2025-06-24 21:32:29,421 [analyzer] INFO: Injected into process with pid 4832 and name u'Unicorn-21092.exe'
2025-06-24 21:32:29,592 [analyzer] DEBUG: Loaded monitor into process with pid 4832
2025-06-24 21:32:32,796 [analyzer] INFO: Added new file to list with pid 4832 and path C:\Users\Administrator\AppData\Local\Temp\Unicorn-61844.exe
2025-06-24 21:32:32,858 [analyzer] INFO: Injected into process with pid 3984 and name u'Unicorn-61844.exe'
2025-06-24 21:32:33,015 [analyzer] DEBUG: Loaded monitor into process with pid 3984
2025-06-24 21:32:34,687 [analyzer] INFO: Analysis timeout hit, terminating analysis.
2025-06-24 21:32:35,671 [analyzer] INFO: Terminating remaining processes before shutdown.
2025-06-24 21:32:35,671 [lib.api.process] INFO: Successfully terminated process with pid 2796.
2025-06-24 21:32:35,671 [lib.api.process] INFO: Successfully terminated process with pid 1484.
2025-06-24 21:32:35,671 [lib.api.process] INFO: Successfully terminated process with pid 3040.
2025-06-24 21:32:35,671 [lib.api.process] INFO: Successfully terminated process with pid 1488.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 2304.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 2368.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 2920.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 1564.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3060.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 2952.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 2332.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 2476.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 2652.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3120.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3212.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3300.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3380.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3476.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3560.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3640.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3744.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3832.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3916.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 4016.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3076.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3240.
2025-06-24 21:32:35,687 [lib.api.process] INFO: Successfully terminated process with pid 3456.
2025-06-24 21:32:35,703 [lib.api.process] INFO: Successfully terminated process with pid 3576.
2025-06-24 21:32:35,703 [lib.api.process] INFO: Successfully terminated process with pid 3656.
2025-06-24 21:32:35,703 [lib.api.process] INFO: Successfully terminated process with pid 840.
2025-06-24 21:32:35,703 [lib.api.process] INFO: Successfully terminated process with pid 3728.
2025-06-24 21:32:35,703 [lib.api.process] INFO: Successfully terminated process with pid 2192.
2025-06-24 21:32:35,703 [lib.api.process] INFO: Successfully terminated process with pid 1540.
2025-06-24 21:32:35,703 [lib.api.process] INFO: Successfully terminated process with pid 2316.
2025-06-24 21:32:35,703 [lib.api.process] INFO: Successfully terminated process with pid 2120.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 2588.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 3104.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 3280.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 3988.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 1300.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 3632.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4120.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4200.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4280.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4360.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4440.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4524.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4604.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4684.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4764.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4848.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 4936.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 5020.
2025-06-24 21:32:35,717 [lib.api.process] INFO: Successfully terminated process with pid 5112.
2025-06-24 21:32:35,733 [lib.api.process] INFO: Successfully terminated process with pid 4012.
2025-06-24 21:32:35,733 [lib.api.process] INFO: Successfully terminated process with pid 4456.
2025-06-24 21:32:35,733 [lib.api.process] INFO: Successfully terminated process with pid 4624.
2025-06-24 21:32:35,733 [lib.api.process] INFO: Successfully terminated process with pid 4832.
2025-06-24 21:32:35,733 [lib.api.process] INFO: Successfully terminated process with pid 3984.
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-20247.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-34951.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-13518.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-65255.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-11841.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-59631.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-24639.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-27279.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-42311.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-62940.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-41175.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-9094.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-61799.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-46127.exe
2025-06-24 21:32:35,953 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-27039.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-56900.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-25095.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-63359.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-32103.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-26660.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-5801.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-27751.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-23535.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-43687.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-38431.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-46103.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-6481.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-25687.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-62271.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-57372.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-48068.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-43063.exe
2025-06-24 21:32:35,967 [analyzer] WARNING: Too many files: c:\users\administrator\appdata\local\temp\unicorn-22764.exe
2025-06-24 21:32:35,967 [analyzer] INFO: Analysis completed.

Cuckoo Log

2025-07-02 12:12:59,276 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:00,296 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:03,691 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:04,759 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:05,850 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:06,899 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:07,934 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:08,965 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:09,989 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:11,017 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:12,051 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:13,215 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:14,248 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:15,288 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:16,319 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:17,348 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:18,379 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:19,409 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:20,567 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:21,750 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:22,877 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:23,955 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:25,050 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:26,112 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:27,175 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:28,245 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:29,320 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:30,413 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:31,630 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:32,823 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:33,913 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:34,980 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:36,221 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:37,294 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:38,367 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:39,413 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:40,458 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:41,779 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:42,837 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:44,200 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:45,264 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:46,325 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:47,381 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:48,449 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:49,533 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:50,604 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:51,669 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:52,910 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:54,234 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:55,319 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:56,372 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:57,596 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:58,840 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:13:59,942 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:01,084 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:02,170 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:03,280 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:04,511 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:05,621 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:06,770 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:07,862 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:09,193 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:10,286 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:11,324 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:12,413 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:13,454 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:14,566 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:15,604 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:16,633 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:17,666 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:18,765 [cuckoo.core.scheduler] DEBUG: Task #6631140: no machine available yet
2025-07-02 12:14:19,810 [cuckoo.core.scheduler] INFO: Task #6631140: acquired machine win7x647 (label=win7x647)
2025-07-02 12:14:19,817 [cuckoo.core.resultserver] DEBUG: Now tracking machine 192.168.168.207 for task #6631140
2025-07-02 12:14:20,219 [cuckoo.auxiliary.sniffer] INFO: Started sniffer with PID 2753377 (interface=vboxnet0, host=192.168.168.207)
2025-07-02 12:14:20,941 [cuckoo.machinery.virtualbox] DEBUG: Starting vm win7x647
2025-07-02 12:14:21,635 [cuckoo.machinery.virtualbox] DEBUG: Restoring virtual machine win7x647 to vmcloak
2025-07-02 12:15:37,409 [cuckoo.core.guest] INFO: Starting analysis #6631140 on guest (id=win7x647, ip=192.168.168.207)
2025-07-02 12:15:38,415 [cuckoo.core.guest] DEBUG: win7x647: not ready yet
2025-07-02 12:15:43,453 [cuckoo.core.guest] INFO: Guest is running Cuckoo Agent 0.10 (id=win7x647, ip=192.168.168.207)
2025-07-02 12:15:43,528 [cuckoo.core.guest] DEBUG: Uploading analyzer to guest (id=win7x647, ip=192.168.168.207, monitor=latest, size=6660546)
2025-07-02 12:15:44,984 [cuckoo.core.resultserver] DEBUG: Task #6631140: live log analysis.log initialized.
2025-07-02 12:15:46,139 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:15:46,669 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:15:47,381 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0001.jpg'
2025-07-02 12:15:47,400 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 133483
2025-07-02 12:15:50,057 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:15:52,686 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0002.jpg'
2025-07-02 12:15:52,709 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 136753
2025-07-02 12:15:53,488 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:15:54,844 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0003.jpg'
2025-07-02 12:15:54,861 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 138055
2025-07-02 12:15:55,947 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0004.jpg'
2025-07-02 12:15:55,982 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 127189
2025-07-02 12:15:56,751 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:15:58,271 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0005.jpg'
2025-07-02 12:15:58,291 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 127254
2025-07-02 12:15:59,973 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:16:00,804 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:03,830 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:05,581 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0006.jpg'
2025-07-02 12:16:05,601 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 128810
2025-07-02 12:16:08,594 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:08,744 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0007.jpg'
2025-07-02 12:16:08,772 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 129882
2025-07-02 12:16:10,779 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:14,143 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:14,979 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0008.jpg'
2025-07-02 12:16:15,006 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 131149
2025-07-02 12:16:15,152 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:16:17,572 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:19,154 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0009.jpg'
2025-07-02 12:16:19,169 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 131644
2025-07-02 12:16:20,261 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0010.jpg'
2025-07-02 12:16:20,282 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 132821
2025-07-02 12:16:20,984 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:22,807 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0011.jpg'
2025-07-02 12:16:22,851 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 132447
2025-07-02 12:16:24,363 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:25,975 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0012.jpg'
2025-07-02 12:16:25,991 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 132954
2025-07-02 12:16:27,909 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:29,159 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0013.jpg'
2025-07-02 12:16:29,186 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 133111
2025-07-02 12:16:30,380 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:16:31,280 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:34,693 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:38,104 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:41,465 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:44,876 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:45,498 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:16:48,222 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:51,648 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:55,105 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:16:58,519 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:00,650 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:17:02,088 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:05,562 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:08,935 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:12,365 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:15,927 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:17:15,948 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:19,150 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:22,612 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:25,983 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:29,412 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:31,086 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:17:32,654 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:36,188 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:39,667 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:42,969 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:46,337 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:46,661 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:17:49,752 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:53,076 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:56,413 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:17:59,921 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:01,875 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:18:03,122 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:06,498 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:09,810 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:13,154 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:16,635 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:17,252 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:18:19,810 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:23,393 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:26,560 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:29,920 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:32,366 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:18:33,457 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:36,701 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:40,122 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:43,544 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:45,540 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0014.jpg'
2025-07-02 12:18:45,555 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 133554
2025-07-02 12:18:46,935 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:47,666 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0015.jpg'
2025-07-02 12:18:47,686 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:18:47,686 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 132852
2025-07-02 12:18:48,780 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0016.jpg'
2025-07-02 12:18:48,793 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 133806
2025-07-02 12:18:50,311 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:50,922 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0017.jpg'
2025-07-02 12:18:50,937 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 133662
2025-07-02 12:18:52,025 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0018.jpg'
2025-07-02 12:18:52,038 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 124644
2025-07-02 12:18:53,732 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:54,214 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0019.jpg'
2025-07-02 12:18:54,226 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 124847
2025-07-02 12:18:55,335 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0020.jpg'
2025-07-02 12:18:55,361 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 124040
2025-07-02 12:18:56,440 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0021.jpg'
2025-07-02 12:18:56,464 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 125351
2025-07-02 12:18:57,107 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:18:57,576 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0022.jpg'
2025-07-02 12:18:57,583 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 92327
2025-07-02 12:18:58,832 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0023.jpg'
2025-07-02 12:18:58,870 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 124469
2025-07-02 12:18:59,942 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0024.jpg'
2025-07-02 12:18:59,953 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 125992
2025-07-02 12:19:00,513 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:19:01,149 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0025.jpg'
2025-07-02 12:19:01,180 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 125762
2025-07-02 12:19:02,764 [cuckoo.core.guest] DEBUG: win7x647: analysis #6631140 still processing
2025-07-02 12:19:03,301 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0026.jpg'
2025-07-02 12:19:03,317 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 126640
2025-07-02 12:19:03,935 [cuckoo.core.resultserver] DEBUG: Task #6631140 is sending a BSON stream
2025-07-02 12:19:04,536 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0027.jpg'
2025-07-02 12:19:04,549 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 126800
2025-07-02 12:19:05,840 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'curtain/1750793554.83.curtain.log'
2025-07-02 12:19:05,843 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 36
2025-07-02 12:19:06,527 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'sysmon/1750793555.52.sysmon.xml'
2025-07-02 12:19:06,672 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'shots/0028.jpg'
2025-07-02 12:19:06,677 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 9354364
2025-07-02 12:19:06,719 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 127232
2025-07-02 12:19:06,739 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/3fb579a3150b0fb1_unicorn-646.exe'
2025-07-02 12:19:06,744 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479245
2025-07-02 12:19:06,749 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/41592e0c9b023724_unicorn-27623.exe'
2025-07-02 12:19:06,754 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479276
2025-07-02 12:19:06,759 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/8d388a3adb265e5a_unicorn-39711.exe'
2025-07-02 12:19:06,764 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479254
2025-07-02 12:19:06,768 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/fca5068e03e4a636_unicorn-9731.exe'
2025-07-02 12:19:06,772 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479291
2025-07-02 12:19:06,777 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/a244b4420809d82a_unicorn-12766.exe'
2025-07-02 12:19:06,782 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479266
2025-07-02 12:19:06,786 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/76d3386ec8564ce7_unicorn-145.exe'
2025-07-02 12:19:06,790 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479242
2025-07-02 12:19:06,795 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/a5a8ed9ae857c8b6_unicorn-8763.exe'
2025-07-02 12:19:06,800 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479288
2025-07-02 12:19:06,803 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/6e11cc09d250ff41_unicorn-859.exe'
2025-07-02 12:19:06,809 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479283
2025-07-02 12:19:06,814 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/a86168d486a97f14_unicorn-46692.exe'
2025-07-02 12:19:06,820 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479284
2025-07-02 12:19:06,823 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/ba07bca256966a1c_unicorn-27239.exe'
2025-07-02 12:19:06,828 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479278
2025-07-02 12:19:06,832 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/22d4191a6bb228ef_unicorn-31631.exe'
2025-07-02 12:19:06,838 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/2fd4fee88ee1b74e_unicorn-55908.exe'
2025-07-02 12:19:06,841 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479253
2025-07-02 12:19:06,849 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/3f76be1ba467f6c7_unicorn-33479.exe'
2025-07-02 12:19:06,852 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479281
2025-07-02 12:19:06,856 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479258
2025-07-02 12:19:06,862 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/df7cfb7f129b11c7_unicorn-27639.exe'
2025-07-02 12:19:07,036 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479280
2025-07-02 12:19:07,139 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/eaac0a84dfb9bd67_unicorn-27700.exe'
2025-07-02 12:19:07,146 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/6e78164cf2b6fdc3_unicorn-52599.exe'
2025-07-02 12:19:07,149 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/80e66f551336849a_unicorn-25596.exe'
2025-07-02 12:19:07,152 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/91d004345507f5a3_unicorn-1270.exe'
2025-07-02 12:19:07,155 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/d8c0d18bbfab302a_unicorn-55090.exe'
2025-07-02 12:19:08,790 [cuckoo.core.guest] INFO: win7x647: analysis completed successfully
2025-07-02 12:19:08,801 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Redsocks
2025-07-02 12:19:08,823 [cuckoo.core.plugins] DEBUG: Stopped auxiliary module: Sniffer
2025-07-02 12:19:09,073 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479239
2025-07-02 12:19:09,076 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/aede924038d73542_unicorn-45719.exe'
2025-07-02 12:19:09,117 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479265
2025-07-02 12:19:09,120 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/f4bdcf6f7a87879e_unicorn-63431.exe'
2025-07-02 12:19:09,122 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/df9dac50c3004bdc_unicorn-21092.exe'
2025-07-02 12:19:09,125 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/59110235b40a937c_unicorn-61844.exe'
2025-07-02 12:19:09,127 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/ad9957567e061ca5_unicorn-48911.exe'
2025-07-02 12:19:09,130 [cuckoo.core.resultserver] DEBUG: Task #6631140: File upload for 'files/68019cd3410e6de1_unicorn-2934.exe'
2025-07-02 12:19:09,179 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479260
2025-07-02 12:19:09,200 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479295
2025-07-02 12:19:09,203 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479271
2025-07-02 12:19:09,210 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479268
2025-07-02 12:19:09,213 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479294
2025-07-02 12:19:09,244 [cuckoo.core.resultserver] DEBUG: Task #6631140 had connection reset for <Context for LOG>
2025-07-02 12:19:09,362 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479273
2025-07-02 12:19:09,364 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479292
2025-07-02 12:19:09,366 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479275
2025-07-02 12:19:09,368 [cuckoo.core.resultserver] DEBUG: Task #6631140 uploaded file length: 479289
2025-07-02 12:19:10,003 [cuckoo.machinery.virtualbox] INFO: Successfully generated memory dump for virtual machine with label win7x647 to path /srv/cuckoo/cwd/storage/analyses/6631140/memory.dmp
2025-07-02 12:19:10,004 [cuckoo.machinery.virtualbox] DEBUG: Stopping vm win7x647
2025-07-02 12:21:45,231 [cuckoo.core.resultserver] DEBUG: Stopped tracking machine 192.168.168.207 for task #6631140
2025-07-02 12:21:46,281 [cuckoo.core.scheduler] DEBUG: Released database task #6631140
2025-07-02 12:21:46,300 [cuckoo.core.scheduler] INFO: Task #6631140: analysis procedure completed

Signatures

Yara rule detected for file (1 event)
description (no description) rule SEH__vba
One or more processes crashed (50 out of 58 events)
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
de8c69e6b0eda4a7_unicorn-6744+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 5443160
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-11841+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x680061
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 3218744
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-55090+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 9510200
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-5801+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-5801+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-5801.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 6561064
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-6481+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-6481+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-6481.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 5774632
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-145+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-145+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-145.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 6102312
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-20247+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 6626616
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-9094+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-9094+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-9094.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 5905704
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-646+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 5643560
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-27751+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-27751+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-27751.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 9510200
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-27279+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 6036792
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-38431+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-38431+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-38431.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 6298936
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-46127+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 6626616
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-65255+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-65255+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-65255.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 6167864
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-62271+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-62271+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-62271.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 5709112
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-61799+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-61799+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-61799.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 9510200
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-31631+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 5905720
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-39711+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-39711+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-39711.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 6233400
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-42311+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-42311+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-42311.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 5905720
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-27039+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-27039+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-27039.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 8985912
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-63359+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-63359+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-63359.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 6167864
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-33479+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 2694456
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-41175+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 6102328
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-2934+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-2934+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-2934.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 6495528
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-43687+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 9116984
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-13518+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 6298936
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-46103+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 6298936
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-34951+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x680061
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 3087672
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-45719+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x680fff
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 3087672
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-12766+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-12766+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-12766.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 6036792
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-23535+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 9379128
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-48911+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-48911+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-48911.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 5774648
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-32103+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-32103+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-32103.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 5643576
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-43063+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 5774648
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-63431+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 6036792
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-25095+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 5643576
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-1270+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-1270+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-1270.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 5315880
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-25687+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-25687+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-25687.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 9116984
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-52599+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-52599+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-52599.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 6298936
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-27623+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 9379128
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-24639+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: c4 00 f9 ff ff 00 63 5f c4 00 f9 ff ff 03 00 02
exception.instruction: les eax, ptr [eax]
exception.exception_code: 0xc0000005
exception.symbol:
exception.address: 0x6e006b
registers.esp: 1636932
registers.edi: 4369311
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 6298936
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-27239+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 2825528
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-59631+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-59631+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-59631.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 9379128
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-27639+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 6298936
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-55908+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x680061
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 3087672
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-22764+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-22764+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-22764.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 5381432
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-859+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.symbol:
exception.exception_code: 0xc0000005
exception.address: 0x0
registers.esp: 1636928
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 6102312
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-46692+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-46692+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-46692.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 6167864
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-62940+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff ff 00 00 00 00 04 01 04 40 00 00 00 00 00 00
exception.exception_code: 0xc000001d
exception.symbol:
exception.address: 0x6800f6
registers.esp: 1636924
registers.edi: 1637180
registers.eax: 1637100
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 3218744
1 0 0

__exception__

stacktrace:
IID_IVbaHost+0x236f3 UserDllMain-0x41bc4 msvbvm60+0x51d33 @ 0x72991d33
unicorn-57372+0x297de @ 0x4297de
IID_IVbaHost+0x239f4 UserDllMain-0x418c3 msvbvm60+0x52034 @ 0x72992034
IID_IVbaHost+0x23e5b UserDllMain-0x4145c msvbvm60+0x5249b @ 0x7299249b
IID_IVbaHost+0x24027 UserDllMain-0x41290 msvbvm60+0x52667 @ 0x72992667
DllCanUnloadNow+0x1c1d9 DllRegisterServer-0xa1b8 msvbvm60+0xbbe8b @ 0x729fbe8b
IID_IVbaHost+0x2e809 UserDllMain-0x36aae msvbvm60+0x5ce49 @ 0x7299ce49
IID_IVbaHost+0x3133d UserDllMain-0x33f7a msvbvm60+0x5f97d @ 0x7299f97d
gapfnScSendMessage+0x332 GetAppCompatFlags2-0x8ea user32+0x162fa @ 0x75af62fa
GetThreadDesktop+0xd7 GetWindowLongW-0x2c4 user32+0x16d3a @ 0x75af6d3a
CharPrevW+0x138 TranslateMessage-0x45 user32+0x177c4 @ 0x75af77c4
DispatchMessageA+0xf GetMessageA-0x9 user32+0x17bca @ 0x75af7bca
__vbaStrToAnsi+0x2f1 EbGetObjConnectionCounts-0x479 msvbvm60+0xa6c8 @ 0x7294a6c8
__vbaStrToAnsi+0x268 EbGetObjConnectionCounts-0x502 msvbvm60+0xa63f @ 0x7294a63f
__vbaStrToAnsi+0x146 EbGetObjConnectionCounts-0x624 msvbvm60+0xa51d @ 0x7294a51d

exception.instruction_r: ff 15 d0 10 4b 00 83 c4 0c 8d 4d c0 51 8d 55 c4
exception.symbol: unicorn-57372+0x2ab99
exception.instruction: call dword ptr [0x4b10d0]
exception.module: Unicorn-57372.exe
exception.exception_code: 0xc0000005
exception.offset: 175001
exception.address: 0x42ab99
registers.esp: 1636932
registers.edi: 1637180
registers.eax: 1637116
registers.ebp: 1637168
registers.edx: 1637112
registers.ebx: 1
registers.esi: 1637388
registers.ecx: 5381432
1 0 0
Foreign language identified in PE resource (1 event)
name RT_VERSION language LANG_CHINESE filetype data sublanguage SUBLANG_CHINESE_SIMPLIFIED offset 0x000747c4 size 0x00000234
Creates executable files on the filesystem (50 out of 58 events)
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-13518.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-27639.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-11841.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-12766.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-27039.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-24639.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-27279.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-42311.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-62940.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-41175.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-9094.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-61799.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-46127.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-46692.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-27623.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-56900.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-25095.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-63359.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-65255.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-26660.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-6481.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-27751.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-55908.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-23535.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-43687.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-38431.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-46103.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-45719.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-52599.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-62271.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-57372.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-48068.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-43063.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-22764.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-32103.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-646.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-859.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-39711.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-5801.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-59631.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-145.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-8763.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-2934.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-27239.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-31631.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-9731.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-33479.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-27700.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-1270.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-55090.exe
Drops an executable to the user AppData folder (2 events)
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-646.exe
file C:\Users\Administrator\AppData\Local\Temp\Unicorn-27623.exe
Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time) (1 event)
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2796
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
length: 24576
protection: 32 (PAGE_EXECUTE_READ)
base_address: 0x003f0000
process_handle: 0xffffffff
1 0 0
The binary likely contains encrypted or compressed data indicative of a packer (2 events)
section {u'size_of_data': u'0x0002b000', u'virtual_address': u'0x00001000', u'entropy': 7.571638596627531, u'name': u'.text', u'virtual_size': u'0x0002a5c4'} entropy 7.57163859663 description A section with a high entropy has been found
entropy 0.370689655172 description Overall entropy of this PE file is high
File has been identified by 12 AntiVirus engine on IRMA as malicious (12 events)
G Data Antivirus (Windows) Virus: Generic.Dacic.94CCEEA9.A.009F1AA1 (Engine A), Win32.Trojan.PSE.1FY1FUT (Engine B)
Avast Core Security (Linux) Win32:Evo-gen [Trj]
C4S ClamAV (Linux) Win.Packed.Generic-9967832-0
WithSecure (Linux) Trojan.TR/Crypt.XPACK.Gen
eScan Antivirus (Linux) Generic.Dacic.94CCEEA9.A.009F1AA1(DB)
ESET Security (Windows) a variant of Win32/VBClone.E trojan
Sophos Anti-Virus (Linux) Troj/VB-KCP
DrWeb Antivirus (Linux) Trojan.Siggen29.56020
ClamAV (Linux) Win.Packed.Generic-9967832-0
Bitdefender Antivirus (Linux) Generic.Dacic.94CCEEA9.A.009F1AA1
Kaspersky Standard (Windows) Trojan.Win32.VB.dosq
Emsisoft Commandline Scanner (Windows) Generic.Dacic.94CCEEA9.A.009F1AA1 (B)
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.