Sample viewer

vx.netlux.org/Virus.DOS.Nomad.888.c

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:36.268699856Z 25 PC: 12b1a | Get default drive
2018-12-17T22:52:36.271228984Z 71 PC: 12b2c | Get current directory
2018-12-17T22:52:36.273686612Z 26 PC: 12b34 | Set disk transfer address
2018-12-17T22:52:36.274943301Z 78 PC: 12b6a | Find first file
2018-12-17T22:52:36.280821623Z 61 PC: 12b88 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:52:36.292602987Z 63 PC: 12b97 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:52:36.299506863Z 62 PC: 12b9b | Close file
2018-12-17T22:52:36.301533923Z 67 PC: 12bb1 | Get or set file attributes
2018-12-17T22:52:36.406081245Z 61 PC: 12bbf | Open file (Filename = 'TEST.EXE')
2018-12-17T22:52:36.413882782Z 63 PC: 12bcf | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:52:36.416766445Z 66 PC: 12bf7 | Move file pointer
2018-12-17T22:52:36.420001225Z 64 PC: 12c02 | Write file or device (Write 888 bytes on handle 5)
2018-12-17T22:52:36.430555878Z 66 PC: 12c43 | Move file pointer
2018-12-17T22:52:36.432338716Z 66 PC: 12c59 | Move file pointer
2018-12-17T22:52:36.435284949Z 64 PC: 12c64 | Write file or device (Write 28 bytes on handle 5)
2018-12-17T22:52:36.438288661Z 87 PC: 12c77 | Get or set file date and time
2018-12-17T22:52:36.440009042Z 62 PC: 12c7b | Close file
2018-12-17T22:52:36.448922816Z 67 PC: 12c8a | Get or set file attributes
2018-12-17T22:52:36.458788753Z 59 PC: 12cbd | Change current directory
2018-12-17T22:52:36.463644945Z 9 PC: 12cb8 | Display string (String= ' ******************************************************* * yO!!! I could have made some mischief to you but I * * lEfT it out. I'm the #Nomad Virus# - Mikee's World * ******************************************************* ')
2018-12-17T22:52:36.476486778Z 59 PC: 12c93 | Change current directory
2018-12-17T22:52:36.481807169Z 26 PC: 12ca2 | Set disk transfer address
2018-12-17T22:52:36.482888327Z 9 PC: 12f70 | Display string (Could not find end pointer)
2018-12-17T22:52:36.50319288Z 76 PC: 12f74 | Terminate with return code (Return code = '36')