Sample viewer

vx.netlux.org/Virus.DOS.Born2Loose.895

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:10:06.563213868Z 53 PC: 1515e | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T23:10:06.568900065Z 67 PC: 1521a | Get or set file attributes
2018-12-17T23:10:06.575226644Z 65 PC: 15221 | Delete file (Filename = 'chklist.tav')
2018-12-17T23:10:06.589864543Z 67 PC: 1521a | Get or set file attributes
2018-12-17T23:10:06.596916998Z 65 PC: 15221 | Delete file (Filename = 'chklist.cps')
2018-12-17T23:10:06.605066073Z 67 PC: 1521a | Get or set file attributes
2018-12-17T23:10:06.618872019Z 65 PC: 15221 | Delete file (Filename = 'anti-vir.dat')
2018-12-17T23:10:06.625134227Z 67 PC: 1521a | Get or set file attributes
2018-12-17T23:10:06.632652687Z 65 PC: 15221 | Delete file (Filename = 'chklist.ms')
2018-12-17T23:10:06.639310609Z 53 PC: 152a9 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:06.641160566Z 37 PC: 152b8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:06.643708344Z 47 PC: 1549b | Get disk transfer address
2018-12-17T23:10:06.64626581Z 26 PC: 154aa | Set disk transfer address
2018-12-17T23:10:06.648820551Z 78 PC: 15360 | Find first file
2018-12-17T23:10:06.655975198Z 79 PC: 15366 | Find next file
2018-12-17T23:10:06.659093999Z 79 PC: 15366 | Find next file
2018-12-17T23:10:06.661992897Z 79 PC: 15366 | Find next file
2018-12-17T23:10:06.665823696Z 79 PC: 15366 | Find next file
2018-12-17T23:10:06.668944561Z 79 PC: 15366 | Find next file
2018-12-17T23:10:06.671638243Z 79 PC: 15366 | Find next file
2018-12-17T23:10:06.674421003Z 79 PC: 15366 | Find next file
2018-12-17T23:10:06.678233157Z 67 PC: 15399 | Get or set file attributes
2018-12-17T23:10:06.690718822Z 67 PC: 153a9 | Get or set file attributes
2018-12-17T23:10:06.708414168Z 61 PC: 153b8 | Open file (Filename = 'TEST.COM')
2018-12-17T23:10:06.719044586Z 87 PC: 153c6 | Get or set file date and time
2018-12-17T23:10:06.722410421Z 63 PC: 153d8 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:10:06.731695531Z 87 PC: 1545f | Get or set file date and time
2018-12-17T23:10:06.734384715Z 62 PC: 15463 | Close file
2018-12-17T23:10:06.743415888Z 67 PC: 15470 | Get or set file attributes
2018-12-17T23:10:06.754300413Z 78 PC: 15360 | Find first file
2018-12-17T23:10:06.768254908Z 79 PC: 15366 | Find next file
2018-12-17T23:10:06.775257809Z 79 PC: 15366 | Find next file
2018-12-17T23:10:06.779676924Z 79 PC: 15366 | Find next file
2018-12-17T23:10:06.783749678Z 79 PC: 15366 | Find next file
2018-12-17T23:10:06.787108681Z 79 PC: 15366 | Find next file
2018-12-17T23:10:06.790259011Z 79 PC: 15366 | Find next file
2018-12-17T23:10:06.793686853Z 79 PC: 15366 | Find next file
2018-12-17T23:10:06.797208251Z 79 PC: 15366 | Find next file
2018-12-17T23:10:06.800307075Z 78 PC: 15360 | Find first file
2018-12-17T23:10:06.810493839Z 79 PC: 15366 | Find next file
2018-12-17T23:10:06.815035935Z 67 PC: 15399 | Get or set file attributes
2018-12-17T23:10:06.822015862Z 67 PC: 153a9 | Get or set file attributes
2018-12-17T23:10:07.167438997Z 61 PC: 153b8 | Open file (Filename = 'C:\DOS\FORMAT.COM')
2018-12-17T23:10:07.176492641Z 87 PC: 153c6 | Get or set file date and time
2018-12-17T23:10:07.178392272Z 63 PC: 153d8 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:10:07.184872109Z 66 PC: 15412 | Move file pointer
2018-12-17T23:10:07.187882226Z 64 PC: 15435 | Write file or device (Write 895 bytes on handle 5)
2018-12-17T23:10:07.196535839Z 66 PC: 15442 | Move file pointer
2018-12-17T23:10:07.198389623Z 64 PC: 1544e | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:10:07.202617037Z 87 PC: 1545f | Get or set file date and time
2018-12-17T23:10:07.205022709Z 62 PC: 15463 | Close file
2018-12-17T23:10:07.21244108Z 67 PC: 15470 | Get or set file attributes
2018-12-17T23:10:07.224120449Z 26 PC: 151f7 | Set disk transfer address
2018-12-17T23:10:07.226087436Z 37 PC: 152d5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:07.227749369Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=00002710h/0000010000d bytes. ')
2018-12-17T23:10:07.232442469Z 76 PC: 12a86 | Terminate with return code (Return code = '36')