Sample viewer

vx.netlux.org/Virus.DOS.BenCurKle.928

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:46.930852909Z 74 PC: 12d52 | Reallocate memory
2018-12-17T22:53:46.932546022Z 53 PC: 12b2e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:46.933641328Z 37 PC: 21948 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:46.934626544Z 78 PC: 219de | Find first file
2018-12-17T22:53:46.939115915Z 61 PC: 21a8e | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:53:46.943639219Z 66 PC: 21a1c | Move file pointer
2018-12-17T22:53:46.944791741Z 63 PC: 21a27 | Read file or device (Read 13 bytes on handle 5)
2018-12-17T22:53:46.949592549Z 62 PC: 21a9a | Close file
2018-12-17T22:53:46.952018819Z 66 PC: 21aa8 | Move file pointer
2018-12-17T22:53:46.953267916Z 61 PC: 21a8e | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:53:46.960099091Z 87 PC: 21b14 | Get or set file date and time
2018-12-17T22:53:46.96197859Z 66 PC: 21aa8 | Move file pointer
2018-12-17T22:53:46.963199248Z 66 PC: 21a76 | Move file pointer
2018-12-17T22:53:46.964792927Z 72 PC: 21a66 | Allocate memory
2018-12-17T22:53:46.96662278Z 66 PC: 21aa8 | Move file pointer
2018-12-17T22:53:46.968003931Z 63 PC: 21ad2 | Read file or device (Read 407 bytes on handle 5)
2018-12-17T22:53:46.970507586Z 66 PC: 21aa8 | Move file pointer
2018-12-17T22:53:46.972823676Z 64 PC: 21aeb | Write file or device (Write 1335 bytes on handle 5)
2018-12-17T22:53:46.985097483Z 87 PC: 21afb | Get or set file date and time
2018-12-17T22:53:46.986562904Z 62 PC: 21a9a | Close file
2018-12-17T22:53:47.003720626Z 66 PC: 21aa8 | Move file pointer
2018-12-17T22:53:47.019046499Z 73 PC: 21b08 | Release memory
2018-12-17T22:53:47.020469341Z 25 PC: 21b35 | Get default drive
2018-12-17T22:53:47.022134787Z 71 PC: 21b45 | Get current directory
2018-12-17T22:53:47.025254508Z 59 PC: 21bac | Change current directory
2018-12-17T22:53:47.028839028Z 78 PC: 219de | Find first file
2018-12-17T22:53:47.0334644Z 61 PC: 21a8e | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:53:47.038745747Z 66 PC: 21a1c | Move file pointer
2018-12-17T22:53:47.0403447Z 63 PC: 21a27 | Read file or device (Read 13 bytes on handle 5)
2018-12-17T22:53:47.044938453Z 62 PC: 21a9a | Close file
2018-12-17T22:53:47.046976333Z 66 PC: 21aa8 | Move file pointer
2018-12-17T22:53:47.049368655Z 79 PC: 219f2 | Find next file
2018-12-17T22:53:47.052122539Z 61 PC: 21a8e | Open file (Filename = 'PRINT.COM')
2018-12-17T22:53:47.065640307Z 66 PC: 21a1c | Move file pointer
2018-12-17T22:53:47.067669913Z 63 PC: 21a27 | Read file or device (Read 13 bytes on handle 5)
2018-12-17T22:53:47.074685089Z 62 PC: 21a9a | Close file
2018-12-17T22:53:47.077223905Z 66 PC: 21aa8 | Move file pointer
2018-12-17T22:53:47.079830683Z 61 PC: 21a8e | Open file (Filename = 'PRINT.COM')
2018-12-17T22:53:47.086989789Z 87 PC: 21b14 | Get or set file date and time
2018-12-17T22:53:47.088677971Z 66 PC: 21aa8 | Move file pointer
2018-12-17T22:53:47.090973303Z 66 PC: 21a76 | Move file pointer
2018-12-17T22:53:47.092622483Z 72 PC: 21a66 | Allocate memory
2018-12-17T22:53:47.094638389Z 66 PC: 21aa8 | Move file pointer
2018-12-17T22:53:47.097114757Z 63 PC: 21ad2 | Read file or device (Read 27 bytes on handle 5)
2018-12-17T22:53:47.099926421Z 66 PC: 21aa8 | Move file pointer
2018-12-17T22:53:47.101537319Z 64 PC: 21aeb | Write file or device (Write 955 bytes on handle 5)
2018-12-17T22:53:47.111203164Z 87 PC: 21afb | Get or set file date and time
2018-12-17T22:53:47.113457904Z 62 PC: 21a9a | Close file
2018-12-17T22:53:47.121152777Z 66 PC: 21aa8 | Move file pointer
2018-12-17T22:53:47.123320378Z 73 PC: 21b08 | Release memory
2018-12-17T22:53:47.124775422Z 14 PC: 21bb5 | Set default drive (Drive = 'A')
2018-12-17T22:53:47.125993313Z 59 PC: 21bbd | Change current directory
2018-12-17T22:53:47.131379892Z 37 PC: 21983 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:47.132610239Z 81 PC: 1341b | Get current PSP
2018-12-17T22:53:47.133693515Z 61 PC: 13474 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:53:47.146093778Z 66 PC: 134cf | Move file pointer
2018-12-17T22:53:47.148178695Z 63 PC: 134e7 | Read file or device (Read 7 bytes on handle 5)
2018-12-17T22:53:47.155596017Z 66 PC: 13572 | Move file pointer
2018-12-17T22:53:47.157619859Z 63 PC: 1357d | Read file or device (Read 16 bytes on handle 5)
2018-12-17T22:53:47.164683799Z 63 PC: 135e1 | Read file or device (Read 968 bytes on handle 5)
2018-12-17T22:53:47.171762814Z 62 PC: 1348a | Close file
2018-12-17T22:53:47.1743214Z 48 PC: 12b67 | Get DOS version
2018-12-17T22:53:47.176030261Z 101 PC: 12b88 | Get extended country info
2018-12-17T22:53:47.177648651Z 2 PC: 12d4c | Character output (Char = '5b')
2018-12-17T22:53:47.180160926Z 2 PC: 12d52 | Character output (Char = '59')
2018-12-17T22:53:47.182636741Z 2 PC: 12d5e | Character output (Char = '2c')
2018-12-17T22:53:47.184886303Z 2 PC: 12d52 | Character output (Char = '4e')
2018-12-17T22:53:47.187211841Z 2 PC: 12d66 | Character output (Char = '5d')
2018-12-17T22:53:47.190459593Z 2 PC: 12d6c | Character output (Char = '3f')
2018-12-17T22:53:47.193084672Z 8 PC: 12da4 | Console input without echo