Sample viewer

vx.netlux.org/Virus.DOS.SofiaTerminator.1487

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:58:50.049426862Z 84 PC: 13ad9 | Get verify flag
2018-12-17T22:58:50.051406613Z 9 PC: 12a82 | Display string (String= 'Goat file (EXE). Size=000011A0h/0000004512d bytes. ')
2018-12-17T22:58:50.065056588Z 76 PC: 12a86 | Terminate with return code (Return code = '36')
2018-12-17T22:58:50.069185619Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:58:50.071249337Z 72 PC: 12174 | Allocate memory
2018-12-17T22:58:50.078236651Z 72 PC: 1218d | Allocate memory
2018-12-17T22:58:50.080831648Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:58:50.082442856Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:58:50.084811077Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:50.086361241Z 62 PC: 122ab | Close file
2018-12-17T22:58:50.088479242Z 69 PC: 9f5b5 | Duplicate handle
2018-12-17T22:58:50.091641726Z 62 PC: 122ab | Close file
2018-12-17T22:58:50.093646884Z 62 PC: 122ab | Close file
2018-12-17T22:58:50.095527479Z 62 PC: 122ab | Close file
2018-12-17T22:58:50.098048627Z 62 PC: 122ab | Close file
2018-12-17T22:58:50.100422689Z 62 PC: 122ab | Close file
2018-12-17T22:58:50.102831957Z 62 PC: 122ab | Close file
2018-12-17T22:58:50.105254571Z 62 PC: 122ab | Close file
2018-12-17T22:58:50.108101371Z 62 PC: 122ab | Close file
2018-12-17T22:58:50.10990457Z 62 PC: 122ab | Close file
2018-12-17T22:58:50.112248927Z 62 PC: 122ab | Close file
2018-12-17T22:58:50.115801403Z 62 PC: 122ab | Close file
2018-12-17T22:58:50.119422489Z 62 PC: 122ab | Close file
2018-12-17T22:58:50.124311769Z 62 PC: 122ab | Close file
2018-12-17T22:58:50.127652318Z 62 PC: 122ab | Close file
2018-12-17T22:58:50.131405031Z 99 PC: 999d7 | Get DBCS lead byte table pointer
2018-12-17T22:58:50.133349145Z 56 PC: 941f9 | Get or set country info
2018-12-17T22:58:50.136939022Z 64 PC: 99c48 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:58:50.144659964Z 25 PC: 94262 | Get default drive
2018-12-17T22:58:50.147763367Z 71 PC: 964dd | Get current directory
2018-12-17T22:58:50.154227676Z 64 PC: 99c48 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:58:50.161998882Z 2 PC: 964b2 | Character output (Char = '3e')
2018-12-17T22:58:50.164666055Z 93 PC: 94320 | File sharing functions
2018-12-17T22:58:50.16709462Z 93 PC: 94327 | File sharing functions
2018-12-17T22:58:50.170623663Z 10 PC: 94339 | Buffered keyboard input
2018-12-17T22:59:05.014874721Z 0 PC: 0 | Program terminate
2018-12-17T22:59:06.370227901Z 0 PC: 0 | Program terminate
2018-12-17T22:59:06.473099472Z 64 PC: 99c48 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:59:06.47982902Z 41 PC: 943ae | Parse filename
2018-12-17T22:59:06.483508095Z 41 PC: 9442f | Parse filename
2018-12-17T22:59:06.487153165Z 41 PC: 9444c | Parse filename
2018-12-17T22:59:06.490101346Z 26 PC: 978f7 | Set disk transfer address
2018-12-17T22:59:06.493823482Z 71 PC: 97af3 | Get current directory
2018-12-17T22:59:06.510307643Z 78 PC: 9f5b5 | Find first file
2018-12-17T22:59:06.526189252Z 47 PC: 9f5b5 | Get disk transfer address
2018-12-17T22:59:06.529950631Z 71 PC: 9796c | Get current directory
2018-12-17T22:59:06.535677835Z 73 PC: 97009 | Release memory
2018-12-17T22:59:06.537907075Z 67 PC: 9f5b5 | Get or set file attributes
2018-12-17T22:59:06.545256007Z 61 PC: 9f5b5 | Open file (Filename = '')
2018-12-17T22:59:06.55294091Z 87 PC: 9f5b5 | Get or set file date and time
2018-12-17T22:59:06.55499483Z 66 PC: 9f5b5 | Move file pointer
2018-12-17T22:59:06.557580199Z 63 PC: 9f5b5 | Read file or device (Read 24 bytes on handle 5)
2018-12-17T22:59:06.564997189Z 66 PC: 9f5b5 | Move file pointer
2018-12-17T22:59:06.567057452Z 87 PC: 9f5b5 | Get or set file date and time
2018-12-17T22:59:06.569120178Z 62 PC: 9f5b5 | Close file
2018-12-17T22:59:06.583255775Z 67 PC: 9f5b5 | Get or set file attributes
2018-12-17T22:59:06.596267289Z 13 PC: 9f5b5 | Disk reset
2018-12-17T22:59:06.598437669Z 75 PC: 11821 | Execute program
2018-12-17T22:59:06.614882897Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T22:59:06.620105492Z 76 PC: 12a4b | Terminate with return code (Return code = '36')