Sample viewer

vx.netlux.org/Virus.DOS.Avvaddon.1100

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:47:46.444780478Z 74 PC: 12a66 | Reallocate memory
2018-12-17T22:47:46.455161288Z 53 PC: 12a76 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:46.456855072Z 37 PC: 12a87 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:46.459028478Z 61 PC: 12ad9 | Open file (Filename = '')
2018-12-17T22:47:46.467183574Z 66 PC: 12aec | Move file pointer
2018-12-17T22:47:46.468743497Z 63 PC: 12af6 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T22:47:46.475714021Z 66 PC: 12b16 | Move file pointer
2018-12-17T22:47:46.482829881Z 63 PC: 12b20 | Read file or device (Read 1100 bytes on handle 5)
2018-12-17T22:47:46.490238009Z 66 PC: 12b29 | Move file pointer
2018-12-17T22:47:46.491646379Z 64 PC: 12b33 | Write file or device (Write 1100 bytes on handle 5)
2018-12-17T22:47:46.505958208Z 66 PC: 12b38 | Move file pointer
2018-12-17T22:47:46.523365396Z 64 PC: 12b3e | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:47:46.53122952Z 62 PC: 12b42 | Close file
2018-12-17T22:47:46.53860943Z 75 PC: 12aa7 | Execute program
2018-12-17T22:47:46.554666981Z 9 PC: 134e6 | Display string (String= 'Goat file (EXE/k...). Size=00001A90h/0000006800d bytes. ')
2018-12-17T22:47:46.560427613Z 48 PC: 134ef | Get DOS version
2018-12-17T22:47:46.561643044Z 61 PC: 12b7d | Open file (Filename = '')
2018-12-17T22:47:46.569921409Z 63 PC: 12b90 | Read file or device (Read 1100 bytes on handle 5)
2018-12-17T22:47:46.57455792Z 66 PC: 12bbf | Move file pointer
2018-12-17T22:47:46.575760182Z 64 PC: 12bd9 | Write file or device (Write 1100 bytes on handle 5)
2018-12-17T22:47:46.581505568Z 66 PC: 12be2 | Move file pointer
2018-12-17T22:47:46.582618791Z 64 PC: 12bec | Write file or device (Write 32 bytes on handle 5)
2018-12-17T22:47:46.584487478Z 66 PC: 12bf6 | Move file pointer
2018-12-17T22:47:46.58607927Z 64 PC: 12bff | Write file or device (Write 572 bytes on handle 5)
2018-12-17T22:47:46.591083017Z 62 PC: 12c03 | Close file
2018-12-17T22:47:46.59640898Z 61 PC: 135bc | Open file (Filename = '')
2018-12-17T22:47:46.601310457Z 93 PC: 1355e | File sharing functions
2018-12-17T22:47:46.602727101Z 9 PC: 134e6 | Display string (String= 'Size change=044Ch/01100d. ')
2018-12-17T22:47:46.605276207Z 76 PC: 13543 | Terminate with return code (Return code = '1')
2018-12-17T22:47:46.613720514Z 77 PC: 12aab | Get program return code
2018-12-17T22:47:46.615110874Z 76 PC: 12aaf | Terminate with return code (Return code = '1')