Sample viewer

vx.netlux.org/Virus.DOS.Lobo.1388

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:53:32.006448354Z 255 PC: 21e77 | UNKNOWN!
2018-12-17T21:53:32.007182506Z 53 PC: 21e8d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:53:32.008219457Z 74 PC: 21eb1 | Reallocate memory
2018-12-17T21:53:32.009903536Z 72 PC: 21eb8 | Allocate memory
2018-12-17T21:53:32.011448903Z 37 PC: 21eda | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:53:32.013328463Z 9 PC: 12a85 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat F400H bytes long ')
2018-12-17T21:53:32.019073939Z 0 PC: 12a89 | Program terminate

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":369,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:40:51.275705319Z 255 PC: 21e77 | UNKNOWN!
2018-12-25T11:40:51.279434749Z 53 PC: 21e8d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:40:51.280465278Z 74 PC: 21eb1 | Reallocate memory
2018-12-25T11:40:51.281603604Z 72 PC: 21eb8 | Allocate memory
2018-12-25T11:40:51.283282396Z 37 PC: 21eda | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:40:51.284360096Z 9 PC: 12a85 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat F400H bytes long ')
2018-12-25T11:40:51.288157238Z 0 PC: 12a89 | Program terminate

{"DateBased":true,"Day":2,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":369,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:40:51.403667563Z 255 PC: 21e77 | UNKNOWN!
2018-12-25T11:40:51.404474464Z 53 PC: 21e8d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:40:51.405501832Z 74 PC: 21eb1 | Reallocate memory
2018-12-25T11:40:51.407276303Z 72 PC: 21eb8 | Allocate memory
2018-12-25T11:40:51.408663854Z 37 PC: 21eda | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:40:51.409833151Z 9 PC: 12a85 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat F400H bytes long ')
2018-12-25T11:40:51.416081028Z 0 PC: 12a89 | Program terminate