Sample viewer

vx.netlux.org/Virus.DOS.Sinister.1200

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:09:53.066155211Z 171 PC: 13e4e | UNKNOWN!
2018-12-17T22:09:53.068408491Z 53 PC: 13e73 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:09:53.070069528Z 37 PC: 13e93 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:09:53.071815298Z 9 PC: 12a85 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ')
2018-12-17T22:09:53.084059804Z 0 PC: 12a89 | Program terminate

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2224,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:45:11.008081377Z 64 PC: 0 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T11:45:11.015146593Z 41 PC: 94fae | Parse filename
2018-12-25T11:45:11.019959776Z 41 PC: 9502f | Parse filename
2018-12-25T11:45:11.022383903Z 41 PC: 9504c | Parse filename
2018-12-25T11:45:11.024678668Z 26 PC: 984f7 | Set disk transfer address
2018-12-25T11:45:11.027555991Z 71 PC: 986f3 | Get current directory
2018-12-25T11:45:11.030800928Z 78 PC: 986fe | Find first file
2018-12-25T11:45:11.041846791Z 71 PC: 986f3 | Get current directory (See above)
2018-12-25T11:45:11.045678067Z 78 PC: 986fe | Find first file (See above)
2018-12-25T11:45:11.056940755Z 64 PC: 9a848 | Write file or device (Write 26 bytes on handle 2)
2018-12-25T11:45:11.063257361Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T11:45:11.066023707Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:45:11.067434613Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:45:11.069301308Z 62 PC: 122ab | Close file
2018-12-25T11:45:11.07116031Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:11.073511566Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:11.075519053Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:11.077534443Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:11.080444698Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:11.082144449Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:11.083740531Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:11.086348155Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:11.088060962Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:11.089822989Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:11.096044379Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:11.097746464Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:11.100004997Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:11.10379239Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:45:11.106232707Z 99 PC: 9a5d7 | Get DBCS lead byte table pointer
2018-12-25T11:45:11.10785834Z 56 PC: 94df9 | Get or set country info
2018-12-25T11:45:11.110546641Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T11:45:11.11623954Z 25 PC: 94e62 | Get default drive
2018-12-25T11:45:11.118131265Z 71 PC: 970dd | Get current directory
2018-12-25T11:45:11.123552155Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T11:45:11.127555239Z 2 PC: 970b2 | Character output (Char = '3e')
2018-12-25T11:45:11.130485527Z 93 PC: 94f20 | File sharing functions
2018-12-25T11:45:11.132605253Z 93 PC: 94f27 | File sharing functions
2018-12-25T11:45:11.136057625Z 10 PC: 94f39 | Buffered keyboard input
2018-12-25T11:45:26.054576689Z 0 PC: 0 | Program terminate (See above)
2018-12-25T11:45:27.409003786Z 0 PC: 0 | Program terminate (See above)
2018-12-25T11:45:27.511482902Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T11:45:27.517090316Z 41 PC: 94fae | Parse filename (See above)
2018-12-25T11:45:27.520020529Z 41 PC: 9502f | Parse filename (See above)
2018-12-25T11:45:27.521573769Z 41 PC: 9504c | Parse filename (See above)
2018-12-25T11:45:27.523909607Z 26 PC: 984f7 | Set disk transfer address (See above)
2018-12-25T11:45:27.527712434Z 71 PC: 986f3 | Get current directory (See above)
2018-12-25T11:45:27.538180197Z 78 PC: 986fe | Find first file (See above)
2018-12-25T11:45:27.544674747Z 71 PC: 9856c | Get current directory
2018-12-25T11:45:27.547582768Z 73 PC: 97c09 | Release memory
2018-12-25T11:45:27.549079764Z 75 PC: 11821 | Execute program
2018-12-25T11:45:27.575479956Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-25T11:45:27.581940668Z 76 PC: 12a4b | Terminate with return code (Return code = '36')

{"DateBased":true,"Day":4,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2224,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:45:11.354736367Z 171 PC: 13e4e | UNKNOWN!
2018-12-25T11:45:11.355692685Z 53 PC: 13e73 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:11.357623695Z 37 PC: 13e93 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:11.359227371Z 9 PC: 12a85 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ')
2018-12-25T11:45:11.365558346Z 0 PC: 12a89 | Program terminate