Sample viewer

vx.netlux.org/Virus.DOS.Jorgito.543

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:58:40.783025817Z 249 PC: 12c36 | UNKNOWN!
2018-12-17T22:58:40.784883919Z 53 PC: 12c40 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:58:40.786651892Z 74 PC: 12c5d | Reallocate memory
2018-12-17T22:58:40.788498733Z 72 PC: 12c64 | Allocate memory
2018-12-17T22:58:40.790673951Z 37 PC: 12c8d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:58:40.793479455Z 9 PC: 12a82 | Display string (String= 'Goat file (EXE). Size=000003E8h/0000001000d bytes. ')
2018-12-17T22:58:40.798099919Z 76 PC: 12a86 | Terminate with return code (Return code = '36')

{"DateBased":true,"Day":1,"Month":1,"Year":1998,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12951,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:37:04.477640329Z 249 PC: 12c36 | UNKNOWN!
2018-12-25T12:37:04.479164494Z 53 PC: 12c40 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:37:04.480708526Z 74 PC: 12c5d | Reallocate memory
2018-12-25T12:37:04.483156898Z 72 PC: 12c64 | Allocate memory
2018-12-25T12:37:04.484734352Z 37 PC: 12c8d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:37:04.486228294Z 9 PC: 12a82 | Display string (String= 'Goat file (EXE). Size=000003E8h/0000001000d bytes. ')
2018-12-25T12:37:04.492607692Z 76 PC: 12a86 | Terminate with return code (Return code = '36')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12951,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:37:04.490803456Z 249 PC: 12c36 | UNKNOWN!
2018-12-25T12:37:04.493227268Z 53 PC: 12c40 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:37:04.494334217Z 74 PC: 12c5d | Reallocate memory
2018-12-25T12:37:04.495518479Z 72 PC: 12c64 | Allocate memory
2018-12-25T12:37:04.499733813Z 37 PC: 12c8d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:37:04.500977996Z 9 PC: 12a82 | Display string (String= 'Goat file (EXE). Size=000003E8h/0000001000d bytes. ')
2018-12-25T12:37:04.504722996Z 76 PC: 12a86 | Terminate with return code (Return code = '36')