Sample viewer

vx.netlux.org/Virus.DOS.A_morph.367.c

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:43.523480049Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:52:43.525332843Z 37 PC: 12a97 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:52:43.526803979Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:43.528353259Z 78 PC: 12a8f | Find first file
2018-12-17T22:52:43.535204706Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:43.53671433Z 61 PC: 12a8f | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:52:43.543458441Z 53 PC: 12a8f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:43.545559956Z 37 PC: 12b6e | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:43.54672704Z 64 PC: 12b7e | Write file or device (Write 367 bytes on handle 5)
2018-12-17T22:52:43.553142702Z 62 PC: 12a8f | Close file
2018-12-17T22:52:43.568710572Z 79 PC: 12a8f | Find next file
2018-12-17T22:52:43.572217295Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:43.573510824Z 61 PC: 12a8f | Open file (Filename = 'PRINT.COM')
2018-12-17T22:52:43.5819673Z 53 PC: 12a8f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:43.583491791Z 37 PC: 12b6e | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:43.584728387Z 64 PC: 12b7e | Write file or device (Write 367 bytes on handle 5)
2018-12-17T22:52:43.59208989Z 62 PC: 12a8f | Close file
2018-12-17T22:52:43.600058183Z 79 PC: 12a8f | Find next file
2018-12-17T22:52:43.602998805Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:43.605131987Z 61 PC: 12a8f | Open file (Filename = 'HELLO.COM')
2018-12-17T22:52:43.611605291Z 53 PC: 12a8f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:43.612735621Z 37 PC: 12b6e | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:43.614926642Z 64 PC: 12b7e | Write file or device (Write 367 bytes on handle 5)
2018-12-17T22:52:43.621607628Z 62 PC: 12a8f | Close file
2018-12-17T22:52:43.629421242Z 79 PC: 12a8f | Find next file
2018-12-17T22:52:43.632575884Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:43.635160141Z 61 PC: 12a8f | Open file (Filename = 'PHANG.COM')
2018-12-17T22:52:43.643462854Z 53 PC: 12a8f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:43.644629166Z 37 PC: 12b6e | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:43.645971536Z 64 PC: 12b7e | Write file or device (Write 367 bytes on handle 5)
2018-12-17T22:52:43.65276403Z 62 PC: 12a8f | Close file
2018-12-17T22:52:43.660805611Z 79 PC: 12a8f | Find next file
2018-12-17T22:52:43.66479339Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:43.666174821Z 61 PC: 12a8f | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:52:43.68189083Z 53 PC: 12a8f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:43.686576895Z 37 PC: 12b6e | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:43.687767953Z 64 PC: 12b7e | Write file or device (Write 367 bytes on handle 5)
2018-12-17T22:52:43.694359167Z 62 PC: 12a8f | Close file
2018-12-17T22:52:43.703308988Z 79 PC: 12a8f | Find next file
2018-12-17T22:52:43.70626082Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:43.707607659Z 61 PC: 12a8f | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:52:43.714900598Z 53 PC: 12a8f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:43.716428789Z 37 PC: 12b6e | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:43.71785203Z 64 PC: 12b7e | Write file or device (Write 367 bytes on handle 5)
2018-12-17T22:52:43.724612081Z 62 PC: 12a8f | Close file
2018-12-17T22:52:43.733066905Z 79 PC: 12a8f | Find next file
2018-12-17T22:52:43.736081537Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:43.737743253Z 61 PC: 12a8f | Open file (Filename = 'PAH.COM')
2018-12-17T22:52:43.744805287Z 53 PC: 12a8f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:43.745984046Z 37 PC: 12b6e | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:43.747058434Z 64 PC: 12b7e | Write file or device (Write 367 bytes on handle 5)
2018-12-17T22:52:43.754038832Z 62 PC: 12a8f | Close file
2018-12-17T22:52:43.762640084Z 79 PC: 12a8f | Find next file
2018-12-17T22:52:43.765718162Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:43.768509495Z 61 PC: 12a8f | Open file (Filename = 'TEST.COM')
2018-12-17T22:52:43.775335148Z 53 PC: 12a8f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:43.776850453Z 37 PC: 12b6e | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:43.7792218Z 64 PC: 12b7e | Write file or device (Write 367 bytes on handle 5)
2018-12-17T22:52:43.783025072Z 62 PC: 12a8f | Close file
2018-12-17T22:52:43.791042016Z 79 PC: 12a8f | Find next file
2018-12-17T22:52:43.794287617Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')