Sample viewer

vx.netlux.org/Virus.DOS.Flu.1160

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:53:04.518728989Z 63 PC: 1329b | Read file or device (Read 255 bytes on handle 12531)
2018-12-17T21:53:04.521660747Z 60 PC: 132c4 | Create or truncate file
2018-12-17T21:53:04.860073842Z 64 PC: 132d1 | Write file or device (Write 2100 bytes on handle 5)
2018-12-17T21:53:04.866301027Z 62 PC: 132d5 | Close file
2018-12-17T21:53:04.87353052Z 74 PC: 12ab7 | Reallocate memory
2018-12-17T21:53:04.875216898Z 240 PC: 12abd | UNKNOWN!
2018-12-17T21:53:04.875878389Z 53 PC: 12acd | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:53:04.877046281Z 37 PC: 12ae3 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:53:04.880100146Z 53 PC: 12ae8 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T21:53:04.881276124Z 37 PC: 12afe | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T21:53:04.882699597Z 67 PC: 12bb8 | Get or set file attributes
2018-12-17T21:53:04.889100229Z 67 PC: 12bc3 | Get or set file attributes
2018-12-17T21:53:04.898486847Z 61 PC: 12bcb | Open file (Filename = '')
2018-12-17T21:53:04.90449528Z 66 PC: 12c22 | Move file pointer
2018-12-17T21:53:04.906492564Z 63 PC: 12c33 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T21:53:04.909368138Z 66 PC: 12c4d | Move file pointer
2018-12-17T21:53:04.910810379Z 63 PC: 12c57 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T21:53:04.91480851Z 66 PC: 12cb5 | Move file pointer
2018-12-17T21:53:04.916170948Z 63 PC: 12cbf | Read file or device (Read 3 bytes on handle 5)
2018-12-17T21:53:04.918505538Z 66 PC: 12cc7 | Move file pointer
2018-12-17T21:53:04.920138271Z 64 PC: 12ce1 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:53:04.922732907Z 66 PC: 12cf5 | Move file pointer
2018-12-17T21:53:04.923975719Z 64 PC: 12d03 | Write file or device (Write 1160 bytes on handle 5)
2018-12-17T21:53:04.932883532Z 62 PC: 12d08 | Close file
2018-12-17T21:53:04.940716015Z 67 PC: 12d11 | Get or set file attributes
2018-12-17T21:53:04.949668533Z 61 PC: 12b06 | Open file (Filename = '')
2018-12-17T21:53:04.957152102Z 62 PC: 12b0c | Close file
2018-12-17T21:53:04.958994212Z 75 PC: 12b28 | Execute program
2018-12-17T21:53:04.972878428Z 9 PC: 13076 | Display string (String= 'Goat file (COM/....). Size=00000834h/0000002100d bytes. ')
2018-12-17T21:53:04.979162384Z 48 PC: 1307f | Get DOS version
2018-12-17T21:53:04.980936586Z 67 PC: 12bb8 | Get or set file attributes
2018-12-17T21:53:04.986940233Z 67 PC: 12bc3 | Get or set file attributes
2018-12-17T21:53:04.997784163Z 61 PC: 12bcb | Open file (Filename = '')
2018-12-17T21:53:05.005117425Z 62 PC: 12d08 | Close file
2018-12-17T21:53:05.006770351Z 67 PC: 12d11 | Get or set file attributes
2018-12-17T21:53:05.01632199Z 61 PC: 1314c | Open file (Filename = '')
2018-12-17T21:53:05.023853445Z 93 PC: 130ee | File sharing functions
2018-12-17T21:53:05.025617567Z 76 PC: 130d3 | Terminate with return code (Return code = '0')
2018-12-17T21:53:05.028539451Z 65 PC: 12b31 | Delete file (Filename = 'C:\DOS\')
2018-12-17T21:53:05.039142761Z 49 PC: 12b36 | Terminate and stay resident (Return code = '0' | Memory size = '89')