Sample viewer

vx.netlux.org/Virus.DOS.Cpw.1457.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:11.17831956Z 73 PC: 13fd0 | Release memory
2018-12-17T22:51:11.180741943Z 72 PC: 13fd7 | Allocate memory
2018-12-17T22:51:11.182632164Z 74 PC: 13fe5 | Reallocate memory
2018-12-17T22:51:11.184612828Z 74 PC: 13ff4 | Reallocate memory
2018-12-17T22:51:11.187028755Z 53 PC: 1401e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:11.188338785Z 53 PC: 1403d | Get interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-17T22:51:11.18974319Z 9 PC: 145 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ')
2018-12-17T22:51:11.195905739Z 0 PC: 149 | Program terminate

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":10476,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:28:08.550656207Z 73 PC: 13fd0 | Release memory
2018-12-25T12:28:08.553562543Z 72 PC: 13fd7 | Allocate memory
2018-12-25T12:28:08.566417905Z 74 PC: 13fe5 | Reallocate memory
2018-12-25T12:28:08.57073549Z 74 PC: 13ff4 | Reallocate memory
2018-12-25T12:28:08.572932912Z 53 PC: 1401e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:28:08.57663942Z 53 PC: 1403d | Get interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-25T12:28:08.578571471Z 9 PC: 145 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ')
2018-12-25T12:28:08.585809985Z 0 PC: 149 | Program terminate

{"DateBased":true,"Day":27,"Month":5,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":10476,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:28:08.77803607Z 73 PC: 13fd0 | Release memory
2018-12-25T12:28:08.780194748Z 72 PC: 13fd7 | Allocate memory
2018-12-25T12:28:08.78225193Z 74 PC: 13fe5 | Reallocate memory
2018-12-25T12:28:08.783894313Z 74 PC: 13ff4 | Reallocate memory
2018-12-25T12:28:08.785962284Z 53 PC: 1401e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:28:08.787908249Z 53 PC: 1403d | Get interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-25T12:28:08.790182613Z 9 PC: 145 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ')
2018-12-25T12:28:08.797064762Z 0 PC: 149 | Program terminate