Sample viewer

vx.netlux.org/Virus.DOS.Kampi.4181

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:22:01.816990711Z 255 PC: 1329c | UNKNOWN!
2018-12-17T22:22:01.819169882Z 72 PC: 132bb | Allocate memory
2018-12-17T22:22:01.820884295Z 82 PC: 1330b | Get DOS internal pointers (SYSVARS)
2018-12-17T22:22:01.822228525Z 53 PC: 9ec2f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:22:01.82371171Z 37 PC: 9ec43 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:22:01.825662625Z 9 PC: 12a86 | Display string (String= 'Goat file (COM/....). Size=00000834h/0000002100d bytes. ')
2018-12-17T22:22:01.832080136Z 48 PC: 12a8f | Get DOS version
2018-12-17T22:22:01.834617643Z 53 PC: 9f04b | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:22:01.837241382Z 37 PC: 9f04b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:22:01.838327364Z 67 PC: 9f04b | Get or set file attributes
2018-12-17T22:22:01.845594025Z 67 PC: 9f04b | Get or set file attributes
2018-12-17T22:22:01.863145215Z 61 PC: 9f04b | Open file (Filename = '')
2018-12-17T22:22:01.876224403Z 87 PC: 9f04b | Get or set file date and time
2018-12-17T22:22:01.877733536Z 66 PC: 9f04b | Move file pointer
2018-12-17T22:22:01.879392879Z 66 PC: 9f04b | Move file pointer
2018-12-17T22:22:01.880748631Z 63 PC: 9f04b | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:22:01.887553537Z 87 PC: 9f04b | Get or set file date and time
2018-12-17T22:22:01.892771703Z 62 PC: 9f04b | Close file
2018-12-17T22:22:01.89985232Z 67 PC: 9f04b | Get or set file attributes
2018-12-17T22:22:01.909854004Z 37 PC: 9f04b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:22:01.912201881Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-17T22:22:01.919474831Z 93 PC: 12afe | File sharing functions
2018-12-17T22:22:01.921950927Z 9 PC: 12a86 | Display string (String= 'Size change=1055h/04181d. ')
2018-12-17T22:22:01.92799581Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')