Sample viewer

vx.netlux.org/Virus.DOS.Sidewinder.2048

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:29:42.026012643Z 255 PC: 15158 | UNKNOWN!
2018-12-17T22:29:42.027878969Z 53 PC: 15166 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:29:42.029927003Z 37 PC: 151b7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:29:42.031613742Z 76 PC: 14121 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5307,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:11.331339219Z 255 PC: 15158 | UNKNOWN!
2018-12-25T11:54:11.333183634Z 53 PC: 15166 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:11.334887061Z 37 PC: 151b7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:11.336557002Z 76 PC: 14121 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":15,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5307,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:11.337660766Z 255 PC: 15158 | UNKNOWN!
2018-12-25T11:54:11.339101113Z 53 PC: 15166 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:11.340385023Z 37 PC: 151b7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:11.341508156Z 76 PC: 14121 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":21,"Month":4,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5307,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:11.371619025Z 255 PC: 15158 | UNKNOWN!
2018-12-25T11:54:11.37288865Z 53 PC: 15166 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:11.374035958Z 37 PC: 151b7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:11.375231847Z 76 PC: 14121 | Terminate with return code (Return code = '0')