Sample viewer

vx.netlux.org/Virus.DOS.SillyC.138

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:57.087649931Z 26 PC: 1334d | Set disk transfer address
2018-12-17T22:51:57.089311002Z 78 PC: 13353 | Find first file
2018-12-17T22:51:57.097098381Z 61 PC: 13369 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:51:57.104373547Z 63 PC: 13373 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:51:57.111666808Z 66 PC: 1337c | Move file pointer
2018-12-17T22:51:57.114481765Z 64 PC: 1338c | Write file or device (Write 138 bytes on handle 5)
2018-12-17T22:51:57.130335016Z 66 PC: 13395 | Move file pointer
2018-12-17T22:51:57.131905096Z 64 PC: 1339f | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:51:57.139971078Z 87 PC: 133ad | Get or set file date and time
2018-12-17T22:51:57.143227144Z 62 PC: 133b1 | Close file
2018-12-17T22:51:57.153121792Z 254 PC: 12c0a | UNKNOWN!
2018-12-17T22:51:57.154631758Z 53 PC: 12d14 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:51:57.157600235Z 53 PC: 12e0c | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:51:57.159229355Z 37 PC: 12e18 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:51:57.163742223Z 37 PC: 12e3c | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:51:57.507642371Z 53 PC: 12ddf | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:57.50936646Z 53 PC: 12e0c | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:51:57.511074769Z 37 PC: 12e18 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:51:57.513621213Z 48 PC: 12e29 | Get DOS version
2018-12-17T22:51:57.515069754Z 37 PC: 12e3c | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:51:57.51669648Z 37 PC: 12e02 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:57.519360164Z 9 PC: 12a47 | Display string (String= ' WLASNIE WGRALES WIRUSA FLIP (OMICRON) ! ')
2018-12-17T22:51:57.525115475Z 76 PC: 12a4b | Terminate with return code (Return code = '36')