Sample viewer

vx.netlux.org/Virus.DOS.T_Power.Zarma.2389

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:25:54.095978467Z 48 PC: 12c2c | Get DOS version
2018-12-17T22:25:54.099549216Z 53 PC: 133d1 | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T22:25:54.101110623Z 53 PC: 133d1 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:25:54.102574594Z 74 PC: 12d95 | Reallocate memory
2018-12-17T22:25:54.116249369Z 88 PC: 12d9d | case 0xGet or set allocation strateg:
2018-12-17T22:25:54.117994256Z 72 PC: 12daa | Allocate memory
2018-12-17T22:25:54.119870399Z 53 PC: 133d1 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:25:54.121297205Z 53 PC: 133d1 | Get interrupt vector (Interrupt = '209' AKA 'UNKNOWN!')
2018-12-17T22:25:54.123349416Z 37 PC: 133d6 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:25:54.124681036Z 37 PC: 133d6 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:25:54.126006087Z 37 PC: 133d6 | Set interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T22:25:54.138687645Z 74 PC: 12e2a | Reallocate memory
2018-12-17T22:25:54.140563689Z 88 PC: 12e34 | case 0xGet or set allocation strateg:
2018-12-17T22:25:54.14246018Z 250 PC: 12e4c | UNKNOWN!
2018-12-17T22:25:54.144680091Z 47 PC: 12e50 | Get disk transfer address
2018-12-17T22:25:54.146170296Z 26 PC: 12e60 | Set disk transfer address
2018-12-17T22:25:54.147752532Z 71 PC: 12e6a | Get current directory
2018-12-17T22:25:54.151701696Z 53 PC: 133d1 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:25:54.153143297Z 37 PC: 133d6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:25:54.1548921Z 88 PC: 9eb2c | case 0xGet or set allocation strateg:
2018-12-17T22:25:54.156664825Z 250 PC: 9eb44 | UNKNOWN!
2018-12-17T22:25:54.165014547Z 47 PC: 9eb48 | Get disk transfer address
2018-12-17T22:25:54.166740369Z 26 PC: 9eb58 | Set disk transfer address
2018-12-17T22:25:54.168432234Z 71 PC: 9eb62 | Get current directory
2018-12-17T22:25:54.172987436Z 53 PC: 9f0c9 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:25:54.174702814Z 37 PC: 9f0ce | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:25:54.176530653Z 67 PC: 9f0dc | Get or set file attributes
2018-12-17T22:25:54.525235987Z 61 PC: 9ebc9 | Open file (Filename = '')
2018-12-17T22:25:54.532645349Z 87 PC: 9ec52 | Get or set file date and time
2018-12-17T22:25:54.534998991Z 63 PC: 9f0ba | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:25:54.539665653Z 66 PC: 9f0a8 | Move file pointer
2018-12-17T22:25:54.541539695Z 66 PC: 9f0a8 | Move file pointer
2018-12-17T22:25:54.545522632Z 64 PC: 9f04c | Write file or device (Write 2389 bytes on handle 5)
2018-12-17T22:25:54.557419564Z 66 PC: 9eca3 | Move file pointer
2018-12-17T22:25:54.559616785Z 64 PC: 9f0b1 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:25:54.563329774Z 78 PC: 9ede8 | Find first file
2018-12-17T22:25:54.57118092Z 78 PC: 9ede8 | Find first file
2018-12-17T22:25:54.592793756Z 78 PC: 9ede8 | Find first file
2018-12-17T22:25:54.599768607Z 78 PC: 9ede8 | Find first file
2018-12-17T22:25:54.607789869Z 78 PC: 9ede8 | Find first file
2018-12-17T22:25:54.614872911Z 78 PC: 9ede8 | Find first file
2018-12-17T22:25:54.621835286Z 78 PC: 9ede8 | Find first file
2018-12-17T22:25:54.628773787Z 87 PC: 9ee09 | Get or set file date and time
2018-12-17T22:25:54.631980598Z 87 PC: 9ee17 | Get or set file date and time
2018-12-17T22:25:54.634245245Z 62 PC: 9ee1f | Close file
2018-12-17T22:25:54.649001154Z 59 PC: 9f0d3 | Change current directory
2018-12-17T22:25:54.663710909Z 59 PC: 9f0d3 | Change current directory
2018-12-17T22:25:54.66678989Z 37 PC: 9f0ce | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:25:54.668669447Z 26 PC: 9ee4f | Set disk transfer address
2018-12-17T22:25:54.671639698Z 61 PC: 12eba | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:25:54.678751264Z 62 PC: 12ebf | Close file
2018-12-17T22:25:54.681282994Z 59 PC: 133db | Change current directory
2018-12-17T22:25:54.686830234Z 59 PC: 133db | Change current directory
2018-12-17T22:25:54.689243008Z 37 PC: 133d6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:25:54.690999773Z 26 PC: 13157 | Set disk transfer address
2018-12-17T22:25:54.693507735Z 9 PC: 12a82 | Display string (String= 'Goat file (EXE). Size=000003E8h/0000001000d bytes. ')
2018-12-17T22:25:54.698727196Z 76 PC: 12a86 | Terminate with return code (Return code = '36')