Sample viewer

vx.netlux.org/Virus.DOS.Joe.589.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:34.134397107Z 53 PC: 12f33 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:34.135811597Z 37 PC: 12f40 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:34.136900796Z 26 PC: 12f48 | Set disk transfer address
2018-12-17T22:51:34.137797528Z 78 PC: 12f50 | Find first file
2018-12-17T22:51:34.144082574Z 61 PC: 13008 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:51:34.16338181Z 63 PC: 1302a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:51:34.170418062Z 66 PC: 1303f | Move file pointer
2018-12-17T22:51:34.171826373Z 64 PC: 1304b | Write file or device (Write 589 bytes on handle 5)
2018-12-17T22:51:34.187052089Z 66 PC: 13061 | Move file pointer
2018-12-17T22:51:34.188494658Z 64 PC: 1306c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:51:34.195672052Z 62 PC: 13070 | Close file
2018-12-17T22:51:34.219283426Z 79 PC: 12f50 | Find next file
2018-12-17T22:51:34.222210064Z 61 PC: 13008 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:51:34.229589013Z 63 PC: 1302a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:51:34.237155232Z 66 PC: 1303f | Move file pointer
2018-12-17T22:51:34.239090764Z 64 PC: 1304b | Write file or device (Write 589 bytes on handle 5)
2018-12-17T22:51:34.248711626Z 66 PC: 13061 | Move file pointer
2018-12-17T22:51:34.25037338Z 64 PC: 1306c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:51:34.257794265Z 62 PC: 13070 | Close file
2018-12-17T22:51:34.26746091Z 79 PC: 12f50 | Find next file
2018-12-17T22:51:34.270989134Z 61 PC: 13008 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:51:34.279264747Z 63 PC: 1302a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:51:34.299148884Z 66 PC: 1303f | Move file pointer
2018-12-17T22:51:34.300760164Z 64 PC: 1304b | Write file or device (Write 589 bytes on handle 5)
2018-12-17T22:51:34.627791578Z 66 PC: 13061 | Move file pointer
2018-12-17T22:51:34.62935294Z 64 PC: 1306c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:51:34.642483012Z 62 PC: 13070 | Close file
2018-12-17T22:51:34.651140934Z 79 PC: 12f50 | Find next file
2018-12-17T22:51:34.655428069Z 61 PC: 13008 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:51:34.663568488Z 63 PC: 1302a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:51:34.671166898Z 66 PC: 1303f | Move file pointer
2018-12-17T22:51:34.674105879Z 64 PC: 1304b | Write file or device (Write 589 bytes on handle 5)
2018-12-17T22:51:34.683142061Z 66 PC: 13061 | Move file pointer
2018-12-17T22:51:34.686342007Z 64 PC: 1306c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:51:34.699327711Z 62 PC: 13070 | Close file
2018-12-17T22:51:34.709259318Z 79 PC: 12f50 | Find next file
2018-12-17T22:51:34.712783495Z 61 PC: 13008 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:51:34.721648877Z 63 PC: 1302a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:51:34.729361699Z 66 PC: 1303f | Move file pointer
2018-12-17T22:51:34.731279671Z 64 PC: 1304b | Write file or device (Write 589 bytes on handle 5)
2018-12-17T22:51:34.74068828Z 66 PC: 13061 | Move file pointer
2018-12-17T22:51:34.744050798Z 64 PC: 1306c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:51:34.752418076Z 62 PC: 13070 | Close file
2018-12-17T22:51:34.762680011Z 79 PC: 12f50 | Find next file
2018-12-17T22:51:34.767237729Z 61 PC: 13008 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:51:34.775458341Z 63 PC: 1302a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:51:34.783112668Z 66 PC: 1303f | Move file pointer
2018-12-17T22:51:34.786300055Z 64 PC: 1304b | Write file or device (Write 589 bytes on handle 5)
2018-12-17T22:51:34.796744366Z 66 PC: 13061 | Move file pointer
2018-12-17T22:51:34.798930675Z 64 PC: 1306c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:51:34.807588807Z 62 PC: 13070 | Close file
2018-12-17T22:51:34.818162943Z 79 PC: 12f50 | Find next file
2018-12-17T22:51:34.821724147Z 61 PC: 13008 | Open file (Filename = 'PAH.COM')
2018-12-17T22:51:34.831562706Z 63 PC: 1302a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:51:34.839472513Z 66 PC: 1303f | Move file pointer
2018-12-17T22:51:34.841669101Z 64 PC: 1304b | Write file or device (Write 589 bytes on handle 5)
2018-12-17T22:51:34.851333526Z 66 PC: 13061 | Move file pointer
2018-12-17T22:51:34.854649537Z 64 PC: 1306c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:51:34.863162353Z 62 PC: 13070 | Close file
2018-12-17T22:51:34.877473711Z 79 PC: 12f50 | Find next file
2018-12-17T22:51:34.881275071Z 61 PC: 13008 | Open file (Filename = 'TEST.COM')
2018-12-17T22:51:34.889385288Z 63 PC: 1302a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:51:34.893455801Z 62 PC: 13070 | Close file
2018-12-17T22:51:34.896918281Z 79 PC: 12f50 | Find next file
2018-12-17T22:51:34.900589405Z 26 PC: 12f60 | Set disk transfer address
2018-12-17T22:51:34.901990582Z 37 PC: 12f67 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:34.904156945Z 25 PC: 12eb8 | Get default drive
2018-12-17T22:51:34.906172493Z 14 PC: 12ec3 | Set default drive (Drive = 'C')
2018-12-17T22:51:34.90788912Z 53 PC: 12f33 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:34.910519625Z 37 PC: 12f40 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:34.912161973Z 26 PC: 12f48 | Set disk transfer address
2018-12-17T22:51:34.913530519Z 78 PC: 12f50 | Find first file
2018-12-17T22:51:34.930886771Z 61 PC: 13008 | Open file (Filename = 'COMMAND.COM')
2018-12-17T22:51:34.942278868Z 63 PC: 1302a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:51:34.95084938Z 66 PC: 1303f | Move file pointer
2018-12-17T22:51:34.952849191Z 64 PC: 1304b | Write file or device (Write 589 bytes on handle 5)
2018-12-17T22:51:35.293257772Z 66 PC: 13061 | Move file pointer
2018-12-17T22:51:35.295609447Z 64 PC: 1306c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:51:35.300193045Z 62 PC: 13070 | Close file
2018-12-17T22:51:35.309157107Z 79 PC: 12f50 | Find next file
2018-12-17T22:51:35.312251888Z 26 PC: 12f60 | Set disk transfer address
2018-12-17T22:51:35.313612043Z 37 PC: 12f67 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:35.316084672Z 14 PC: 12ecb | Set default drive (Drive = 'A')