Sample viewer

vx.netlux.org/Virus.DOS.Tosha.321

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:30.348980905Z 75 PC: 1335c | Execute program
2018-12-17T22:57:30.350867439Z 53 PC: 13366 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:30.3518804Z 37 PC: 13390 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:30.352885482Z 9 PC: 12a86 | Display string (String= 'Goat file (COM/....). Size=00000834h/0000002100d bytes. ')
2018-12-17T22:57:30.35861077Z 48 PC: 12a8f | Get DOS version
2018-12-17T22:57:30.359689542Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-17T22:57:30.365947113Z 93 PC: 12afe | File sharing functions
2018-12-17T22:57:30.368127846Z 9 PC: 12a86 | Display string (String= 'Size change=0141h/00321d. ')
2018-12-17T22:57:30.371952321Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12576,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:35:40.877300534Z 75 PC: 1335c | Execute program
2018-12-25T12:35:40.879275452Z 53 PC: 13366 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:35:40.881354661Z 37 PC: 13390 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:35:40.883133403Z 9 PC: 12a86 | Display string (String= 'Goat file (COM/....). Size=00000834h/0000002100d bytes. ')
2018-12-25T12:35:40.889748973Z 48 PC: 12a8f | Get DOS version
2018-12-25T12:35:40.90019714Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-25T12:35:40.908195154Z 93 PC: 12afe | File sharing functions
2018-12-25T12:35:40.91075392Z 9 PC: 12a86 | Display string (See above)
2018-12-25T12:35:40.916896431Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')

{"DateBased":true,"Day":5,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12576,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:35:42.289464065Z 75 PC: 1335c | Execute program
2018-12-25T12:35:42.291618389Z 53 PC: 13366 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:35:42.298198891Z 37 PC: 13390 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:35:42.30019396Z 9 PC: 12a86 | Display string (String= 'Goat file (COM/....). Size=00000834h/0000002100d bytes. ')
2018-12-25T12:35:42.306455976Z 48 PC: 12a8f | Get DOS version
2018-12-25T12:35:42.30974321Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-25T12:35:42.316310659Z 93 PC: 12afe | File sharing functions
2018-12-25T12:35:42.318118461Z 9 PC: 12a86 | Display string (See above)
2018-12-25T12:35:42.331887727Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')

{"DateBased":true,"Day":21,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12576,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:35:42.36060018Z 75 PC: 1335c | Execute program
2018-12-25T12:35:42.36308702Z 53 PC: 13366 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:35:42.365397903Z 37 PC: 13390 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:35:42.367738102Z 9 PC: 12a86 | Display string (String= 'Goat file (COM/....). Size=00000834h/0000002100d bytes. ')
2018-12-25T12:35:42.374424708Z 48 PC: 12a8f | Get DOS version
2018-12-25T12:35:42.376613887Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-25T12:35:42.383093618Z 93 PC: 12afe | File sharing functions
2018-12-25T12:35:42.388738061Z 9 PC: 12a86 | Display string (See above)
2018-12-25T12:35:42.398606058Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')