Sample viewer

vx.netlux.org/Virus.DOS.Intruder.1413

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:07.61493587Z 47 PC: 15441 | Get disk transfer address
2018-12-17T22:53:07.618466481Z 26 PC: 15455 | Set disk transfer address
2018-12-17T22:53:07.619859279Z 71 PC: 150c8 | Get current directory
2018-12-17T22:53:07.623152351Z 26 PC: 15147 | Set disk transfer address
2018-12-17T22:53:07.624844518Z 78 PC: 1515c | Find first file
2018-12-17T22:53:07.632443074Z 61 PC: 15202 | Open file (Filename = '\TEST.EXE')
2018-12-17T22:53:07.639775385Z 63 PC: 15213 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:53:07.642860715Z 66 PC: 15244 | Move file pointer
2018-12-17T22:53:07.644952193Z 63 PC: 15252 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:53:07.652569923Z 79 PC: 15177 | Find next file
2018-12-17T22:53:07.656125115Z 26 PC: 15189 | Set disk transfer address
2018-12-17T22:53:07.658690601Z 78 PC: 15193 | Find first file
2018-12-17T22:53:07.665621152Z 26 PC: 151ac | Set disk transfer address
2018-12-17T22:53:07.666952329Z 79 PC: 151b0 | Find next file
2018-12-17T22:53:07.671865018Z 26 PC: 151ac | Set disk transfer address
2018-12-17T22:53:07.673066917Z 79 PC: 151b0 | Find next file
2018-12-17T22:53:07.675774784Z 26 PC: 151ac | Set disk transfer address
2018-12-17T22:53:07.677134364Z 79 PC: 151b0 | Find next file
2018-12-17T22:53:07.680477129Z 26 PC: 151ac | Set disk transfer address
2018-12-17T22:53:07.681758627Z 79 PC: 151b0 | Find next file
2018-12-17T22:53:07.684944813Z 26 PC: 151ac | Set disk transfer address
2018-12-17T22:53:07.686475165Z 79 PC: 151b0 | Find next file
2018-12-17T22:53:07.689426014Z 26 PC: 151ac | Set disk transfer address
2018-12-17T22:53:07.690541071Z 79 PC: 151b0 | Find next file
2018-12-17T22:53:07.694141834Z 26 PC: 151ac | Set disk transfer address
2018-12-17T22:53:07.695689885Z 79 PC: 151b0 | Find next file
2018-12-17T22:53:07.69881798Z 26 PC: 151ac | Set disk transfer address
2018-12-17T22:53:07.701130539Z 79 PC: 151b0 | Find next file
2018-12-17T22:53:07.705174285Z 26 PC: 151ac | Set disk transfer address
2018-12-17T22:53:07.707241753Z 79 PC: 151b0 | Find next file
2018-12-17T22:53:07.71149055Z 26 PC: 15147 | Set disk transfer address
2018-12-17T22:53:07.713418454Z 78 PC: 1515c | Find first file
2018-12-17T22:53:07.720400448Z 61 PC: 15202 | Open file (Filename = '\TEST.EXE')
2018-12-17T22:53:07.728932992Z 63 PC: 15213 | Read file or device (Read 28 bytes on handle 6)
2018-12-17T22:53:07.731881664Z 66 PC: 15244 | Move file pointer
2018-12-17T22:53:07.733271034Z 63 PC: 15252 | Read file or device (Read 2 bytes on handle 6)
2018-12-17T22:53:07.737136547Z 79 PC: 15177 | Find next file
2018-12-17T22:53:07.740052933Z 26 PC: 15189 | Set disk transfer address
2018-12-17T22:53:07.741061231Z 78 PC: 15193 | Find first file
2018-12-17T22:53:07.74859846Z 26 PC: 151ac | Set disk transfer address
2018-12-17T22:53:07.750068588Z 79 PC: 151b0 | Find next file
2018-12-17T22:53:07.752924946Z 26 PC: 151ac | Set disk transfer address
2018-12-17T22:53:07.754151368Z 79 PC: 151b0 | Find next file
2018-12-17T22:53:07.763933757Z 26 PC: 151ac | Set disk transfer address
2018-12-17T22:53:07.765440325Z 79 PC: 151b0 | Find next file
2018-12-17T22:53:07.768630162Z 26 PC: 151ac | Set disk transfer address
2018-12-17T22:53:07.770741264Z 79 PC: 151b0 | Find next file
2018-12-17T22:53:07.776836923Z 26 PC: 151ac | Set disk transfer address
2018-12-17T22:53:07.778141007Z 79 PC: 151b0 | Find next file
2018-12-17T22:53:07.781813987Z 26 PC: 151ac | Set disk transfer address
2018-12-17T22:53:07.783383979Z 79 PC: 151b0 | Find next file
2018-12-17T22:53:07.786478492Z 26 PC: 151ac | Set disk transfer address
2018-12-17T22:53:07.788576218Z 79 PC: 151b0 | Find next file
2018-12-17T22:53:07.791462972Z 26 PC: 151ac | Set disk transfer address
2018-12-17T22:53:07.792705429Z 79 PC: 151b0 | Find next file
2018-12-17T22:53:07.795783514Z 26 PC: 151ac | Set disk transfer address
2018-12-17T22:53:07.797223505Z 79 PC: 151b0 | Find next file
2018-12-17T22:53:07.799839723Z 26 PC: 15463 | Set disk transfer address
2018-12-17T22:53:07.801120117Z 9 PC: 14f4c | Display string (String= ' Phalcon/Skism EXE goat file - 10000 bytes (c) 1995, Night Crawler ')
2018-12-17T22:53:07.811044778Z 76 PC: 14f50 | Terminate with return code (Return code = '36')