Sample viewer

vx.netlux.org/Virus.DOS.Anti-AV.907

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:20:48.562498882Z 53 PC: 1515e | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T22:20:48.568250818Z 67 PC: 15226 | Get or set file attributes
2018-12-17T22:20:48.585969675Z 65 PC: 1522d | Delete file (Filename = 'chklist.tav')
2018-12-17T22:20:48.59233898Z 67 PC: 15226 | Get or set file attributes
2018-12-17T22:20:48.599005188Z 65 PC: 1522d | Delete file (Filename = 'chklist.cps')
2018-12-17T22:20:48.618461371Z 67 PC: 15226 | Get or set file attributes
2018-12-17T22:20:48.62520289Z 65 PC: 1522d | Delete file (Filename = 'anti-vir.dat')
2018-12-17T22:20:48.632374612Z 67 PC: 15226 | Get or set file attributes
2018-12-17T22:20:48.639038481Z 65 PC: 1522d | Delete file (Filename = 'chklist.ms')
2018-12-17T22:20:48.64734867Z 53 PC: 152b5 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:48.649732706Z 37 PC: 152c4 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:48.655297758Z 47 PC: 154a7 | Get disk transfer address
2018-12-17T22:20:48.657266864Z 26 PC: 154b6 | Set disk transfer address
2018-12-17T22:20:48.659115605Z 78 PC: 1536c | Find first file
2018-12-17T22:20:48.667528572Z 79 PC: 15372 | Find next file
2018-12-17T22:20:48.671784597Z 79 PC: 15372 | Find next file
2018-12-17T22:20:48.674806555Z 79 PC: 15372 | Find next file
2018-12-17T22:20:48.679001377Z 79 PC: 15372 | Find next file
2018-12-17T22:20:48.68240616Z 79 PC: 15372 | Find next file
2018-12-17T22:20:48.685410024Z 79 PC: 15372 | Find next file
2018-12-17T22:20:48.689715728Z 79 PC: 15372 | Find next file
2018-12-17T22:20:48.692666027Z 67 PC: 153a5 | Get or set file attributes
2018-12-17T22:20:48.698605758Z 67 PC: 153b5 | Get or set file attributes
2018-12-17T22:20:48.715773729Z 61 PC: 153c4 | Open file (Filename = 'TEST.COM')
2018-12-17T22:20:48.724592293Z 87 PC: 153d2 | Get or set file date and time
2018-12-17T22:20:48.727155775Z 63 PC: 153e4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:20:48.730889706Z 87 PC: 1546b | Get or set file date and time
2018-12-17T22:20:48.733304664Z 62 PC: 1546f | Close file
2018-12-17T22:20:48.753608353Z 67 PC: 1547c | Get or set file attributes
2018-12-17T22:20:48.764246129Z 78 PC: 1536c | Find first file
2018-12-17T22:20:48.783331661Z 79 PC: 15372 | Find next file
2018-12-17T22:20:48.785923406Z 79 PC: 15372 | Find next file
2018-12-17T22:20:48.790322436Z 79 PC: 15372 | Find next file
2018-12-17T22:20:48.793230211Z 79 PC: 15372 | Find next file
2018-12-17T22:20:48.795743875Z 79 PC: 15372 | Find next file
2018-12-17T22:20:48.810345464Z 79 PC: 15372 | Find next file
2018-12-17T22:20:48.812927291Z 79 PC: 15372 | Find next file
2018-12-17T22:20:48.816225262Z 79 PC: 15372 | Find next file
2018-12-17T22:20:48.819677346Z 78 PC: 1536c | Find first file
2018-12-17T22:20:48.829929986Z 79 PC: 15372 | Find next file
2018-12-17T22:20:48.833450303Z 67 PC: 153a5 | Get or set file attributes
2018-12-17T22:20:48.840170276Z 67 PC: 153b5 | Get or set file attributes
2018-12-17T22:20:49.171332069Z 61 PC: 153c4 | Open file (Filename = 'C:\DOS\FORMAT.COM')
2018-12-17T22:20:49.179969414Z 87 PC: 153d2 | Get or set file date and time
2018-12-17T22:20:49.183104857Z 63 PC: 153e4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:20:49.192258709Z 66 PC: 1541e | Move file pointer
2018-12-17T22:20:49.194838836Z 64 PC: 15441 | Write file or device (Write 907 bytes on handle 5)
2018-12-17T22:20:49.210741486Z 66 PC: 1544e | Move file pointer
2018-12-17T22:20:49.212507133Z 64 PC: 1545a | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:20:49.215454636Z 87 PC: 1546b | Get or set file date and time
2018-12-17T22:20:49.218087493Z 62 PC: 1546f | Close file
2018-12-17T22:20:49.22682038Z 67 PC: 1547c | Get or set file attributes
2018-12-17T22:20:49.240247271Z 26 PC: 15203 | Set disk transfer address
2018-12-17T22:20:49.24224514Z 37 PC: 152e1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:20:49.245647072Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=00002710h/0000010000d bytes. ')
2018-12-17T22:20:49.249971183Z 76 PC: 12a86 | Terminate with return code (Return code = '36')