Sample viewer

vx.netlux.org/Virus.DOS.Ming.1017

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:59:54.371256403Z 71 PC: 12b75 | Get current directory
2018-12-17T21:59:54.374331505Z 26 PC: 12b7d | Set disk transfer address
2018-12-17T21:59:54.377222388Z 59 PC: 12b85 | Change current directory
2018-12-17T21:59:54.383183306Z 59 PC: 12bc7 | Change current directory
2018-12-17T21:59:54.401239095Z 59 PC: 12bcf | Change current directory
2018-12-17T21:59:54.402984941Z 78 PC: 12c08 | Find first file
2018-12-17T21:59:54.408802581Z 61 PC: 12c23 | Open file (Filename = 'SLEEP.COM')
2018-12-17T21:59:54.420107607Z 63 PC: 12c30 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T21:59:54.426861261Z 62 PC: 12c4b | Close file
2018-12-17T21:59:54.42863308Z 61 PC: 12c54 | Open file (Filename = 'SLEEP.COM')
2018-12-17T21:59:54.440425719Z 87 PC: 12c5b | Get or set file date and time
2018-12-17T21:59:54.443235992Z 64 PC: 12c68 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:59:54.450190293Z 66 PC: 12c70 | Move file pointer
2018-12-17T21:59:54.451584445Z 64 PC: 12c7b | Write file or device (Write 1017 bytes on handle 5)
2018-12-17T21:59:54.694323945Z 87 PC: 12c82 | Get or set file date and time
2018-12-17T21:59:54.696830484Z 62 PC: 12c86 | Close file
2018-12-17T21:59:54.704266196Z 59 PC: 12c90 | Change current directory
2018-12-17T21:59:54.708622149Z 59 PC: 12c98 | Change current directory
2018-12-17T21:59:54.710590192Z 26 PC: 12c9f | Set disk transfer address
2018-12-17T21:59:54.71189709Z 9 PC: 12ae0 | Display string (String= 'FDREAD2 - Ver 2.00 - written by: J.Armengaud & C.Hochst„tter ')
2018-12-17T21:59:54.718944938Z 73 PC: 12ae8 | Release memory
2018-12-17T21:59:54.720349575Z 53 PC: 12b01 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T21:59:54.721400629Z 37 PC: 12b11 | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T21:59:54.723547662Z 49 PC: 12b18 | Terminate and stay resident (Return code = '0' | Memory size = '16')