Sample viewer

vx.netlux.org/Virus.DOS.Lawine.2259

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:21:18.294271721Z 48 PC: 132cf | Get DOS version
2018-12-17T22:21:18.297278976Z 14 PC: 132f3 | Set default drive (Drive = 'î')
2018-12-17T22:21:18.299359674Z 75 PC: 13301 | Execute program
2018-12-17T22:21:18.301581774Z 74 PC: 13357 | Reallocate memory
2018-12-17T22:21:18.303688693Z 88 PC: 13372 | case 0xGet or set allocation strateg:
2018-12-17T22:21:18.312470454Z 88 PC: 1337b | case 0xGet or set allocation strateg:
2018-12-17T22:21:18.319480366Z 88 PC: 1338c | case 0xGet or set allocation strateg:
2018-12-17T22:21:18.321382776Z 88 PC: 13394 | case 0xGet or set allocation strateg:
2018-12-17T22:21:18.324020659Z 72 PC: 1339b | Allocate memory
2018-12-17T22:21:18.325982566Z 53 PC: 133b5 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:21:18.327395405Z 82 PC: 134a0 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:21:18.346311296Z 11 PC: 134e9 | Get input status
2018-12-17T22:21:18.349556381Z 53 PC: 133da | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:21:18.35153721Z 37 PC: 133fa | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:21:18.354220865Z 37 PC: 13402 | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:21:18.356204816Z 74 PC: 13410 | Reallocate memory
2018-12-17T22:21:18.358617604Z 74 PC: 13414 | Reallocate memory
2018-12-17T22:21:18.361299769Z 88 PC: 1341f | case 0xGet or set allocation strateg:
2018-12-17T22:21:18.371684212Z 88 PC: 13428 | case 0xGet or set allocation strateg:
2018-12-17T22:21:18.373748573Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=000007D0h/0000002000d bytes. ')
2018-12-17T22:21:18.38062172Z 76 PC: 12a86 | Terminate with return code (Return code = '36')