Sample viewer

vx.netlux.org/Virus.DOS.T_Power.Cowa.2408

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:18.992347138Z 48 PC: 12c2c | Get DOS version
2018-12-17T23:02:18.995503098Z 53 PC: 133e4 | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T23:02:18.997337244Z 53 PC: 133e4 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:02:18.999145171Z 74 PC: 12d96 | Reallocate memory
2018-12-17T23:02:19.001419525Z 88 PC: 12d9e | case 0xGet or set allocation strateg:
2018-12-17T23:02:19.003370821Z 72 PC: 12dab | Allocate memory
2018-12-17T23:02:19.005410032Z 53 PC: 133e4 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:02:19.007267673Z 53 PC: 133e4 | Get interrupt vector (Interrupt = '209' AKA 'UNKNOWN!')
2018-12-17T23:02:19.009913414Z 37 PC: 133e9 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:02:19.011245988Z 37 PC: 133e9 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:02:19.01264149Z 37 PC: 133e9 | Set interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T23:02:19.01493525Z 74 PC: 12e2b | Reallocate memory
2018-12-17T23:02:19.016624183Z 88 PC: 12e35 | case 0xGet or set allocation strateg:
2018-12-17T23:02:19.018046696Z 250 PC: 12e4d | UNKNOWN!
2018-12-17T23:02:19.019724759Z 47 PC: 12e51 | Get disk transfer address
2018-12-17T23:02:19.021019131Z 26 PC: 12e61 | Set disk transfer address
2018-12-17T23:02:19.022310457Z 71 PC: 12e6b | Get current directory
2018-12-17T23:02:19.026245951Z 53 PC: 133e4 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:19.028176078Z 37 PC: 133e9 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:19.03048673Z 88 PC: 9eb0d | case 0xGet or set allocation strateg:
2018-12-17T23:02:19.032838419Z 250 PC: 9eb25 | UNKNOWN!
2018-12-17T23:02:19.034459885Z 47 PC: 9eb29 | Get disk transfer address
2018-12-17T23:02:19.035935437Z 26 PC: 9eb39 | Set disk transfer address
2018-12-17T23:02:19.037371425Z 71 PC: 9eb43 | Get current directory
2018-12-17T23:02:19.041170744Z 53 PC: 9f0bc | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:19.043301007Z 37 PC: 9f0c1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:19.044997966Z 67 PC: 9f0cf | Get or set file attributes
2018-12-17T23:02:19.518939188Z 61 PC: 9ebaa | Open file (Filename = '')
2018-12-17T23:02:19.527167207Z 87 PC: 9ec33 | Get or set file date and time
2018-12-17T23:02:19.529253447Z 63 PC: 9f0ad | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:02:19.533896872Z 66 PC: 9f09b | Move file pointer
2018-12-17T23:02:19.535670514Z 66 PC: 9f09b | Move file pointer
2018-12-17T23:02:19.538864936Z 64 PC: 9f03f | Write file or device (Write 2408 bytes on handle 5)
2018-12-17T23:02:19.551713077Z 66 PC: 9ec84 | Move file pointer
2018-12-17T23:02:19.554086697Z 64 PC: 9f0a4 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:02:19.558277612Z 78 PC: 9edc9 | Find first file
2018-12-17T23:02:19.566055345Z 78 PC: 9edc9 | Find first file
2018-12-17T23:02:19.572952765Z 78 PC: 9edc9 | Find first file
2018-12-17T23:02:19.579389579Z 78 PC: 9edc9 | Find first file
2018-12-17T23:02:19.586710134Z 78 PC: 9edc9 | Find first file
2018-12-17T23:02:19.594948844Z 78 PC: 9edc9 | Find first file
2018-12-17T23:02:19.601389656Z 78 PC: 9edc9 | Find first file
2018-12-17T23:02:19.607815139Z 78 PC: 9edc9 | Find first file
2018-12-17T23:02:19.616345296Z 78 PC: 9edc9 | Find first file
2018-12-17T23:02:19.622918177Z 87 PC: 9edea | Get or set file date and time
2018-12-17T23:02:19.624753685Z 87 PC: 9edf8 | Get or set file date and time
2018-12-17T23:02:19.627606185Z 62 PC: 9ee00 | Close file
2018-12-17T23:02:19.635536125Z 59 PC: 9f0c6 | Change current directory
2018-12-17T23:02:19.639968974Z 59 PC: 9f0c6 | Change current directory
2018-12-17T23:02:19.643677432Z 37 PC: 9f0c1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:19.645134139Z 26 PC: 9ee30 | Set disk transfer address
2018-12-17T23:02:19.646624028Z 61 PC: 12ebb | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T23:02:19.655084916Z 62 PC: 12ec0 | Close file
2018-12-17T23:02:19.657918209Z 59 PC: 133ee | Change current directory
2018-12-17T23:02:19.662445856Z 59 PC: 133ee | Change current directory
2018-12-17T23:02:19.666476129Z 37 PC: 133e9 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:19.668643922Z 26 PC: 13158 | Set disk transfer address
2018-12-17T23:02:19.670472388Z 9 PC: 12a82 | Display string (String= 'Goat file (EXE). Size=000003E8h/0000001000d bytes. ')
2018-12-17T23:02:19.675171847Z 76 PC: 12a86 | Terminate with return code (Return code = '36')