Sample viewer

vx.netlux.org/Virus.DOS.Coda.1289

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:13:27.162800779Z 192 PC: 142eb | UNKNOWN!
2018-12-17T22:13:27.164080666Z 67 PC: 14323 | Get or set file attributes
2018-12-17T22:13:27.169175338Z 67 PC: 1432e | Get or set file attributes
2018-12-17T22:13:27.84188877Z 61 PC: 1433b | Open file (Filename = 'ÿÿÿÿÿÿÿÿÿÿÿÿ~öû')
2018-12-17T22:13:27.849353943Z 87 PC: 14344 | Get or set file date and time
2018-12-17T22:13:27.850937281Z 63 PC: 14352 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:13:27.853489866Z 66 PC: 1435d | Move file pointer
2018-12-17T22:13:27.855003013Z 63 PC: 1436a | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:13:27.858863033Z 64 PC: 14380 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:13:27.861435669Z 64 PC: 143b7 | Write file or device (Write 907 bytes on handle 5)
2018-12-17T22:13:27.867352071Z 64 PC: 143c3 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:13:27.869792735Z 64 PC: 143cf | Write file or device (Write 326 bytes on handle 5)
2018-12-17T22:13:27.874104242Z 64 PC: 143db | Write file or device (Write 20 bytes on handle 5)
2018-12-17T22:13:27.876087856Z 64 PC: 143e7 | Write file or device (Write 15 bytes on handle 5)
2018-12-17T22:13:27.878812678Z 42 PC: 143eb | Get date 0x143eb: mov word ptr [bp + 0x166], dx
0x143ef: mov ah, 0x40
0x143f1: mov dx, 0x15c
0x143f4: add dx, bp
0x143f6: mov cx, 0xe
0x143f9: int 0x21
0x143fb: mov al, 0xe9
0x143fd: mov byte ptr [0xfd], al
0x14400: pop word ptr [0xfe]
0x14404: mov ax, 0x4200
0x14407: xor dx, dx
0x14409: xor cx, cx
0x1440b: int 0x21
0x1440d: mov ah, 0x40
0x1440f: mov dx, 0xfd
0x14412: mov cx, 3
0x14415: int 0x21
0x14417: pop dx
0x14418: pop cx
0x14419: mov ax, 0x5701
2018-12-17T22:13:27.880963468Z 64 PC: 143fb | Write file or device (Write 14 bytes on handle 5)
2018-12-17T22:13:27.882893822Z 66 PC: 1440d | Move file pointer
2018-12-17T22:13:27.884734577Z 64 PC: 14417 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:13:27.8865621Z 87 PC: 1441e | Get or set file date and time
2018-12-17T22:13:27.887866001Z 62 PC: 14422 | Close file
2018-12-17T22:13:27.894070897Z 67 PC: 1442a | Get or set file attributes
2018-12-17T22:13:27.899959641Z 9 PC: 12a86 | Display string (String= 'Goat file (EXE/k...). Size=00001A90h/0000006800d bytes. ')
2018-12-17T22:13:27.903124403Z 48 PC: 12a8f | Get DOS version
2018-12-17T22:13:27.904468181Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-17T22:13:27.908489307Z 93 PC: 12afe | File sharing functions
2018-12-17T22:13:27.909835164Z 9 PC: 12a86 | Display string (String= 'Size change=050Dh/01293d. ')
2018-12-17T22:13:27.91361424Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')