Sample viewer

vx.netlux.org/Virus.DOS.Fivem.921

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:47:57.998251036Z 77 PC: 12bac | Get program return code
2018-12-17T22:47:57.99986568Z 74 PC: 12eac | Reallocate memory
2018-12-17T22:47:58.002450287Z 72 PC: 12eba | Allocate memory
2018-12-17T22:47:58.004416672Z 53 PC: 12edb | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:58.006101397Z 37 PC: 12f03 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:58.009085274Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-17T22:47:58.013664068Z 76 PC: 12a86 | Terminate with return code (Return code = '36')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":9402,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:23:03.143843963Z 77 PC: 12bac | Get program return code
2018-12-25T12:23:03.146065344Z 74 PC: 12eac | Reallocate memory
2018-12-25T12:23:03.147541092Z 72 PC: 12eba | Allocate memory
2018-12-25T12:23:03.149080601Z 53 PC: 12edb | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:23:03.15035259Z 37 PC: 12f03 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:23:03.152279436Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-25T12:23:03.158211303Z 76 PC: 12a86 | Terminate with return code (Return code = '36')

{"DateBased":true,"Day":18,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":9402,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:23:03.538922976Z 77 PC: 12bac | Get program return code
2018-12-25T12:23:03.540797819Z 74 PC: 12eac | Reallocate memory
2018-12-25T12:23:03.542565856Z 72 PC: 12eba | Allocate memory
2018-12-25T12:23:03.54425743Z 53 PC: 12edb | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:23:03.546193018Z 37 PC: 12f03 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:23:03.548453578Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-25T12:23:03.554061705Z 76 PC: 12a86 | Terminate with return code (Return code = '36')