Sample viewer

vx.netlux.org/Virus.DOS.Mabuhay.4260

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:07:03.793560587Z 239 PC: 139f1 | UNKNOWN!
2018-12-17T23:07:03.795520461Z 73 PC: 13a1f | Release memory
2018-12-17T23:07:03.798016975Z 53 PC: 13a24 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:03.799410785Z 37 PC: 13a34 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:03.801442124Z 49 PC: 13a3f | Terminate and stay resident (Return code = '0' | Memory size = '267')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15734,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:44:17.445503217Z 239 PC: 139f1 | UNKNOWN!
2018-12-25T12:44:17.448283527Z 73 PC: 13a1f | Release memory
2018-12-25T12:44:17.44978125Z 53 PC: 13a24 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:17.451140986Z 37 PC: 13a34 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:17.45352966Z 49 PC: 13a3f | Terminate and stay resident (Return code = '0' | Memory size = '267')

{"DateBased":true,"Day":1,"Month":10,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15734,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:44:17.515572479Z 239 PC: 139f1 | UNKNOWN!
2018-12-25T12:44:17.517658315Z 73 PC: 13a1f | Release memory
2018-12-25T12:44:17.518924929Z 53 PC: 13a24 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:17.520478764Z 37 PC: 13a34 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:17.522554474Z 49 PC: 13a3f | Terminate and stay resident (Return code = '0' | Memory size = '267')

{"DateBased":true,"Day":10,"Month":10,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15734,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:44:17.576914977Z 239 PC: 139f1 | UNKNOWN!
2018-12-25T12:44:17.583799294Z 73 PC: 13a1f | Release memory
2018-12-25T12:44:17.584952455Z 53 PC: 13a24 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:17.585933922Z 37 PC: 13a34 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:17.588225496Z 49 PC: 13a3f | Terminate and stay resident (Return code = '0' | Memory size = '267')