Sample viewer

vx.netlux.org/Virus.DOS.Vinchuca.925

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:40.387844684Z 53 PC: 12a62 | Get interrupt vector (Interrupt = '227' AKA 'UNKNOWN!')
2018-12-17T22:51:40.390218563Z 250 PC: 12a70 | UNKNOWN!
2018-12-17T22:51:40.391232993Z 53 PC: 12a77 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:40.392902005Z 37 PC: 12a87 | Set interrupt vector (Interrupt = '227' AKA 'UNKNOWN!')
2018-12-17T22:51:40.395010142Z 74 PC: 12ab8 | Reallocate memory
2018-12-17T22:51:40.396670099Z 75 PC: 12ac0 | Execute program
2018-12-17T22:51:40.411510977Z 53 PC: 12fc2 | Get interrupt vector (Interrupt = '227' AKA 'UNKNOWN!')
2018-12-17T22:51:40.414478725Z 76 PC: 12fa4 | Terminate with return code (Return code = '0')
2018-12-17T22:51:40.417438832Z 37 PC: 12acc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:40.418541978Z 49 PC: 12ad1 | Terminate and stay resident (Return code = '0' | Memory size = '73')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":10640,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:28:41.328316517Z 53 PC: 12a62 | Get interrupt vector (Interrupt = '227' AKA 'UNKNOWN!')
2018-12-25T12:28:41.330984533Z 250 PC: 12a70 | UNKNOWN!
2018-12-25T12:28:41.331777596Z 53 PC: 12a77 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:28:41.333050275Z 37 PC: 12a87 | Set interrupt vector (Interrupt = '227' AKA 'UNKNOWN!')
2018-12-25T12:28:41.334491417Z 74 PC: 12ab8 | Reallocate memory
2018-12-25T12:28:41.336562831Z 75 PC: 12ac0 | Execute program
2018-12-25T12:28:41.360393583Z 53 PC: 12fc2 | Get interrupt vector (Interrupt = '227' AKA 'UNKNOWN!')
2018-12-25T12:28:41.362989261Z 76 PC: 12fa4 | Terminate with return code (Return code = '0')
2018-12-25T12:28:41.370785989Z 37 PC: 12acc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:28:41.371759267Z 49 PC: 12ad1 | Terminate and stay resident (Return code = '0' | Memory size = '73')

{"DateBased":true,"Day":3,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":10640,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:28:41.471584907Z 53 PC: 12a62 | Get interrupt vector (Interrupt = '227' AKA 'UNKNOWN!')
2018-12-25T12:28:41.473097599Z 250 PC: 12a70 | UNKNOWN!
2018-12-25T12:28:41.473833272Z 53 PC: 12a77 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:28:41.474866829Z 37 PC: 12a87 | Set interrupt vector (Interrupt = '227' AKA 'UNKNOWN!')
2018-12-25T12:28:41.476362291Z 74 PC: 12ab8 | Reallocate memory
2018-12-25T12:28:41.477624862Z 75 PC: 12ac0 | Execute program
2018-12-25T12:28:41.491264099Z 53 PC: 12fc2 | Get interrupt vector (Interrupt = '227' AKA 'UNKNOWN!')
2018-12-25T12:28:41.49392609Z 76 PC: 12fa4 | Terminate with return code (Return code = '0')
2018-12-25T12:28:41.496672726Z 37 PC: 12acc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:28:41.497597818Z 49 PC: 12ad1 | Terminate and stay resident (Return code = '0' | Memory size = '73')

{"DateBased":true,"Day":3,"Month":7,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":10640,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:28:41.57320034Z 53 PC: 12a62 | Get interrupt vector (Interrupt = '227' AKA 'UNKNOWN!')
2018-12-25T12:28:41.575046971Z 250 PC: 12a70 | UNKNOWN!
2018-12-25T12:28:41.575955159Z 53 PC: 12a77 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:28:41.577756461Z 37 PC: 12a87 | Set interrupt vector (Interrupt = '227' AKA 'UNKNOWN!')
2018-12-25T12:28:41.580203169Z 74 PC: 12ab8 | Reallocate memory
2018-12-25T12:28:41.581662312Z 75 PC: 12ac0 | Execute program
2018-12-25T12:28:41.597231828Z 53 PC: 12fc2 | Get interrupt vector (Interrupt = '227' AKA 'UNKNOWN!')
2018-12-25T12:28:41.600687361Z 76 PC: 12fa4 | Terminate with return code (Return code = '0')
2018-12-25T12:28:41.604043174Z 37 PC: 12acc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:28:41.605260932Z 49 PC: 12ad1 | Terminate and stay resident (Return code = '0' | Memory size = '73')