Sample viewer

vx.netlux.org/Virus.DOS.Anti-AV.1049

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:01:12.873803617Z 53 PC: 1515e | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T23:01:12.878559918Z 67 PC: 15228 | Get or set file attributes
2018-12-17T23:01:12.884090916Z 65 PC: 1522f | Delete file (Filename = 'chklist.tav')
2018-12-17T23:01:12.889710531Z 67 PC: 15228 | Get or set file attributes
2018-12-17T23:01:12.901056971Z 65 PC: 1522f | Delete file (Filename = 'chklist.cps')
2018-12-17T23:01:12.906492553Z 67 PC: 15228 | Get or set file attributes
2018-12-17T23:01:12.911845634Z 65 PC: 1522f | Delete file (Filename = 'anti-vir.dat')
2018-12-17T23:01:12.918046059Z 67 PC: 15228 | Get or set file attributes
2018-12-17T23:01:12.923398115Z 65 PC: 1522f | Delete file (Filename = 'chklist.ms')
2018-12-17T23:01:12.933538969Z 53 PC: 15316 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:12.935046588Z 37 PC: 15325 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:12.936250914Z 47 PC: 15528 | Get disk transfer address
2018-12-17T23:01:12.937322588Z 26 PC: 15537 | Set disk transfer address
2018-12-17T23:01:12.938712127Z 78 PC: 153cd | Find first file
2018-12-17T23:01:12.94955823Z 79 PC: 153d3 | Find next file
2018-12-17T23:01:12.951923198Z 79 PC: 153d3 | Find next file
2018-12-17T23:01:12.95431448Z 79 PC: 153d3 | Find next file
2018-12-17T23:01:12.957220013Z 79 PC: 153d3 | Find next file
2018-12-17T23:01:12.959534264Z 79 PC: 153d3 | Find next file
2018-12-17T23:01:12.961829643Z 79 PC: 153d3 | Find next file
2018-12-17T23:01:12.965421252Z 79 PC: 153d3 | Find next file
2018-12-17T23:01:12.967916799Z 67 PC: 15406 | Get or set file attributes
2018-12-17T23:01:12.973276048Z 67 PC: 15416 | Get or set file attributes
2018-12-17T23:01:12.990470808Z 61 PC: 15425 | Open file (Filename = 'TEST.COM')
2018-12-17T23:01:12.996871877Z 87 PC: 15433 | Get or set file date and time
2018-12-17T23:01:13.001534722Z 63 PC: 15445 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:01:13.008362372Z 87 PC: 154d6 | Get or set file date and time
2018-12-17T23:01:13.009734856Z 62 PC: 154da | Close file
2018-12-17T23:01:13.016380492Z 67 PC: 154e7 | Get or set file attributes
2018-12-17T23:01:13.02692859Z 78 PC: 153cd | Find first file
2018-12-17T23:01:13.032618337Z 79 PC: 153d3 | Find next file
2018-12-17T23:01:13.034929309Z 79 PC: 153d3 | Find next file
2018-12-17T23:01:13.038819551Z 79 PC: 153d3 | Find next file
2018-12-17T23:01:13.041910046Z 79 PC: 153d3 | Find next file
2018-12-17T23:01:13.045477263Z 79 PC: 153d3 | Find next file
2018-12-17T23:01:13.048924179Z 79 PC: 153d3 | Find next file
2018-12-17T23:01:13.051473797Z 79 PC: 153d3 | Find next file
2018-12-17T23:01:13.05383033Z 79 PC: 153d3 | Find next file
2018-12-17T23:01:13.057853137Z 78 PC: 153cd | Find first file
2018-12-17T23:01:13.066127219Z 79 PC: 153d3 | Find next file
2018-12-17T23:01:13.068122487Z 67 PC: 15406 | Get or set file attributes
2018-12-17T23:01:13.072512602Z 67 PC: 15416 | Get or set file attributes
2018-12-17T23:01:13.415995144Z 61 PC: 15425 | Open file (Filename = 'C:\DOS\FORMAT.COM')
2018-12-17T23:01:13.423136338Z 87 PC: 15433 | Get or set file date and time
2018-12-17T23:01:13.425807005Z 63 PC: 15445 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:01:13.434445225Z 66 PC: 1547f | Move file pointer
2018-12-17T23:01:13.436601652Z 64 PC: 154a2 | Write file or device (Write 1049 bytes on handle 5)
2018-12-17T23:01:13.445292894Z 66 PC: 154af | Move file pointer
2018-12-17T23:01:13.446815646Z 64 PC: 154c5 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:01:13.449554672Z 87 PC: 154d6 | Get or set file date and time
2018-12-17T23:01:13.451374694Z 62 PC: 154da | Close file
2018-12-17T23:01:13.457903502Z 67 PC: 154e7 | Get or set file attributes
2018-12-17T23:01:13.46749508Z 26 PC: 15202 | Set disk transfer address
2018-12-17T23:01:13.468658692Z 37 PC: 15342 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:13.470013791Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=00002710h/0000010000d bytes. ')
2018-12-17T23:01:13.473864946Z 76 PC: 12a86 | Terminate with return code (Return code = '36')