Sample viewer

vx.netlux.org/Virus.DOS.Born2Loose.1037

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:57:17.223730432Z 53 PC: 1515e | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T21:57:17.229640004Z 67 PC: 1521c | Get or set file attributes
2018-12-17T21:57:17.235648454Z 65 PC: 15223 | Delete file (Filename = 'chklist.tav')
2018-12-17T21:57:17.241632023Z 67 PC: 1521c | Get or set file attributes
2018-12-17T21:57:17.253089577Z 65 PC: 15223 | Delete file (Filename = 'chklist.cps')
2018-12-17T21:57:17.264218038Z 67 PC: 1521c | Get or set file attributes
2018-12-17T21:57:17.270069804Z 65 PC: 15223 | Delete file (Filename = 'anti-vir.dat')
2018-12-17T21:57:17.276944212Z 67 PC: 1521c | Get or set file attributes
2018-12-17T21:57:17.282951035Z 65 PC: 15223 | Delete file (Filename = 'chklist.ms')
2018-12-17T21:57:17.288938016Z 53 PC: 1530a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:57:17.291213431Z 37 PC: 15319 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:57:17.293937485Z 47 PC: 1551c | Get disk transfer address
2018-12-17T21:57:17.295407171Z 26 PC: 1552b | Set disk transfer address
2018-12-17T21:57:17.297629052Z 78 PC: 153c1 | Find first file
2018-12-17T21:57:17.308999566Z 79 PC: 153c7 | Find next file
2018-12-17T21:57:17.31182496Z 79 PC: 153c7 | Find next file
2018-12-17T21:57:17.315328502Z 79 PC: 153c7 | Find next file
2018-12-17T21:57:17.320809175Z 79 PC: 153c7 | Find next file
2018-12-17T21:57:17.323267432Z 79 PC: 153c7 | Find next file
2018-12-17T21:57:17.325547214Z 79 PC: 153c7 | Find next file
2018-12-17T21:57:17.328986778Z 79 PC: 153c7 | Find next file
2018-12-17T21:57:17.332740064Z 67 PC: 153fa | Get or set file attributes
2018-12-17T21:57:17.338548798Z 67 PC: 1540a | Get or set file attributes
2018-12-17T21:57:17.355154708Z 61 PC: 15419 | Open file (Filename = 'TEST.COM')
2018-12-17T21:57:17.372981508Z 87 PC: 15427 | Get or set file date and time
2018-12-17T21:57:17.374428532Z 63 PC: 15439 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T21:57:17.381636451Z 87 PC: 154ca | Get or set file date and time
2018-12-17T21:57:17.383620233Z 62 PC: 154ce | Close file
2018-12-17T21:57:17.391330667Z 67 PC: 154db | Get or set file attributes
2018-12-17T21:57:17.402605228Z 78 PC: 153c1 | Find first file
2018-12-17T21:57:17.408725691Z 79 PC: 153c7 | Find next file
2018-12-17T21:57:17.411635566Z 79 PC: 153c7 | Find next file
2018-12-17T21:57:17.415130422Z 79 PC: 153c7 | Find next file
2018-12-17T21:57:17.417699482Z 79 PC: 153c7 | Find next file
2018-12-17T21:57:17.420419912Z 79 PC: 153c7 | Find next file
2018-12-17T21:57:17.423923544Z 79 PC: 153c7 | Find next file
2018-12-17T21:57:17.426788355Z 79 PC: 153c7 | Find next file
2018-12-17T21:57:17.429572123Z 79 PC: 153c7 | Find next file
2018-12-17T21:57:17.433734622Z 78 PC: 153c1 | Find first file
2018-12-17T21:57:17.442843172Z 79 PC: 153c7 | Find next file
2018-12-17T21:57:17.446018157Z 67 PC: 153fa | Get or set file attributes
2018-12-17T21:57:17.452721466Z 67 PC: 1540a | Get or set file attributes
2018-12-17T21:57:18.472909521Z 61 PC: 15419 | Open file (Filename = 'C:\DOS\FORMAT.COM')
2018-12-17T21:57:18.482664847Z 87 PC: 15427 | Get or set file date and time
2018-12-17T21:57:18.485311351Z 63 PC: 15439 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T21:57:18.49235696Z 66 PC: 15473 | Move file pointer
2018-12-17T21:57:18.494326557Z 64 PC: 15496 | Write file or device (Write 1024 bytes on handle 5)
2018-12-17T21:57:18.503733264Z 66 PC: 154a3 | Move file pointer
2018-12-17T21:57:18.505885074Z 64 PC: 154b9 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:57:18.510022259Z 87 PC: 154ca | Get or set file date and time
2018-12-17T21:57:18.51225269Z 62 PC: 154ce | Close file
2018-12-17T21:57:18.521739612Z 67 PC: 154db | Get or set file attributes
2018-12-17T21:57:18.533937612Z 26 PC: 151f6 | Set disk transfer address
2018-12-17T21:57:18.53552145Z 37 PC: 15336 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:57:18.538142023Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=00002710h/0000010000d bytes. ')
2018-12-17T21:57:18.542504341Z 76 PC: 12a86 | Terminate with return code (Return code = '36')