Sample viewer

vx.netlux.org/Virus.DOS.T_Power.Cowa.2298

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:02:37.683465557Z 24 PC: 2071f | Reserved
2018-12-17T22:02:37.686175312Z 53 PC: 20a9d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:02:37.687086169Z 74 PC: 209a6 | Reallocate memory
2018-12-17T22:02:37.688058848Z 88 PC: 20ce4 | case 0xGet or set allocation strateg:
2018-12-17T22:02:37.692579766Z 72 PC: 20cf1 | Allocate memory
2018-12-17T22:02:37.69404958Z 53 PC: 20a9d | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:02:37.695059555Z 53 PC: 20a9d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:02:37.696477845Z 37 PC: 20aa2 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:02:37.697483013Z 37 PC: 20aa2 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:02:37.698485519Z 74 PC: 20d7b | Reallocate memory
2018-12-17T22:02:37.700099648Z 88 PC: 20d86 | case 0xGet or set allocation strateg:
2018-12-17T22:02:37.701265393Z 47 PC: 20e1f | Get disk transfer address
2018-12-17T22:02:37.702243178Z 26 PC: 20976 | Set disk transfer address
2018-12-17T22:02:37.703672019Z 71 PC: 20e3a | Get current directory
2018-12-17T22:02:37.706370201Z 53 PC: 20a9d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:37.707366779Z 37 PC: 20aa2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:37.709306895Z 67 PC: 20ae8 | Get or set file attributes
2018-12-17T22:02:38.047289706Z 61 PC: 20ae0 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:02:38.053770079Z 63 PC: 20a83 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:02:38.057621358Z 66 PC: 20a60 | Move file pointer
2018-12-17T22:02:38.059125786Z 63 PC: 20a83 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:02:38.061477724Z 66 PC: 20a6f | Move file pointer
2018-12-17T22:02:38.063048235Z 66 PC: 20a98 | Move file pointer
2018-12-17T22:02:38.064770145Z 63 PC: 20a83 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:02:38.070281601Z 66 PC: 20a6f | Move file pointer
2018-12-17T22:02:38.071594647Z 74 PC: 209a6 | Reallocate memory
2018-12-17T22:02:38.07295858Z 72 PC: 209bd | Allocate memory
2018-12-17T22:02:38.074482434Z 64 PC: 20a36 | Write file or device (Write 2298 bytes on handle 5)
2018-12-17T22:02:38.083684742Z 73 PC: 20a43 | Release memory
2018-12-17T22:02:38.090405572Z 74 PC: 20a51 | Reallocate memory
2018-12-17T22:02:38.091661511Z 66 PC: 20a60 | Move file pointer
2018-12-17T22:02:38.092766002Z 64 PC: 20a79 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:02:38.09569122Z 78 PC: 2095a | Find first file
2018-12-17T22:02:38.101214408Z 78 PC: 2095a | Find first file
2018-12-17T22:02:38.106646884Z 78 PC: 2095a | Find first file
2018-12-17T22:02:38.113077774Z 78 PC: 2095a | Find first file
2018-12-17T22:02:38.118725614Z 78 PC: 2095a | Find first file
2018-12-17T22:02:38.124183663Z 62 PC: 20a8d | Close file
2018-12-17T22:02:38.131555652Z 59 PC: 20aa7 | Change current directory
2018-12-17T22:02:38.13529551Z 59 PC: 20aa7 | Change current directory
2018-12-17T22:02:38.136864675Z 37 PC: 20aa2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:38.138350802Z 26 PC: 20976 | Set disk transfer address
2018-12-17T22:02:38.139289509Z 80 PC: 141b9 | Set current PSP
2018-12-17T22:02:38.139834501Z 48 PC: 141be | Get DOS version
2018-12-17T22:02:38.141402252Z 2 PC: 1406c | Character output (Char = '56')
2018-12-17T22:02:38.143339106Z 2 PC: 1406c | Character output (Char = '65')
2018-12-17T22:02:38.145264134Z 2 PC: 1406c | Character output (Char = '72')
2018-12-17T22:02:38.147642219Z 2 PC: 1406c | Character output (Char = '73')
2018-12-17T22:02:38.149529516Z 2 PC: 1406c | Character output (Char = '69')
2018-12-17T22:02:38.151402806Z 2 PC: 1406c | Character output (Char = 'a2')
2018-12-17T22:02:38.153352845Z 2 PC: 1406c | Character output (Char = '6e')
2018-12-17T22:02:38.155990361Z 2 PC: 1406c | Character output (Char = '20')
2018-12-17T22:02:38.15792733Z 2 PC: 1406c | Character output (Char = '69')
2018-12-17T22:02:38.159978899Z 2 PC: 1406c | Character output (Char = '6e')
2018-12-17T22:02:38.161863663Z 2 PC: 1406c | Character output (Char = '63')
2018-12-17T22:02:38.163748943Z 2 PC: 1406c | Character output (Char = '6f')
2018-12-17T22:02:38.165854896Z 2 PC: 1406c | Character output (Char = '72')
2018-12-17T22:02:38.167618057Z 2 PC: 1406c | Character output (Char = '72')
2018-12-17T22:02:38.169395445Z 2 PC: 1406c | Character output (Char = '65')
2018-12-17T22:02:38.171411818Z 2 PC: 1406c | Character output (Char = '63')
2018-12-17T22:02:38.173310564Z 2 PC: 1406c | Character output (Char = '74')
2018-12-17T22:02:38.175404487Z 2 PC: 1406c | Character output (Char = '61')
2018-12-17T22:02:38.177637542Z 2 PC: 1406c | Character output (Char = '20')
2018-12-17T22:02:38.179518086Z 2 PC: 1406c | Character output (Char = '64')
2018-12-17T22:02:38.181578543Z 2 PC: 1406c | Character output (Char = '65')
2018-12-17T22:02:38.183758583Z 2 PC: 1406c | Character output (Char = '20')
2018-12-17T22:02:38.185629523Z 2 PC: 1406c | Character output (Char = '44')
2018-12-17T22:02:38.18789653Z 2 PC: 1406c | Character output (Char = '4f')
2018-12-17T22:02:38.189815584Z 2 PC: 1406c | Character output (Char = '53')
2018-12-17T22:02:38.191684918Z 2 PC: 1406c | Character output (Char = '0d')
2018-12-17T22:02:38.193826941Z 2 PC: 1406c | Character output (Char = '0a')