Sample viewer

vx.netlux.org/Virus.DOS.TakeControl

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:34.988880706Z 67 PC: 13df1 | Get or set file attributes
2018-12-17T22:54:35.000052354Z 67 PC: 13e00 | Get or set file attributes
2018-12-17T22:54:35.355054001Z 61 PC: 13ee3 | Open file (Filename = '')
2018-12-17T22:54:35.361428917Z 87 PC: 13e24 | Get or set file date and time
2018-12-17T22:54:35.363468394Z 63 PC: 13ef9 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:54:35.366129758Z 66 PC: 13f0e | Move file pointer
2018-12-17T22:54:35.367545172Z 63 PC: 13f1a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:54:35.373679018Z 66 PC: 13f30 | Move file pointer
2018-12-17T22:54:35.375083531Z 64 PC: 13f5a | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:54:35.37825561Z 66 PC: 13f6d | Move file pointer
2018-12-17T22:54:35.380205415Z 64 PC: 13f89 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:54:35.38291523Z 66 PC: 13f9c | Move file pointer
2018-12-17T22:54:35.385315918Z 64 PC: 13fc9 | Write file or device (Write 256 bytes on handle 5)
2018-12-17T22:54:35.392562293Z 64 PC: 13fc9 | Write file or device (Write 256 bytes on handle 5)
2018-12-17T22:54:35.395369196Z 64 PC: 13fc9 | Write file or device (Write 256 bytes on handle 5)
2018-12-17T22:54:35.407490859Z 64 PC: 13fc9 | Write file or device (Write 256 bytes on handle 5)
2018-12-17T22:54:35.410495633Z 64 PC: 13fc9 | Write file or device (Write 256 bytes on handle 5)
2018-12-17T22:54:35.418087422Z 64 PC: 13fc9 | Write file or device (Write 256 bytes on handle 5)
2018-12-17T22:54:35.421253225Z 64 PC: 13fc9 | Write file or device (Write 256 bytes on handle 5)
2018-12-17T22:54:35.437685155Z 64 PC: 13fc9 | Write file or device (Write 256 bytes on handle 5)
2018-12-17T22:54:35.445385153Z 64 PC: 13fc9 | Write file or device (Write 256 bytes on handle 5)
2018-12-17T22:54:35.454581941Z 64 PC: 13fc9 | Write file or device (Write 256 bytes on handle 5)
2018-12-17T22:54:35.457239575Z 64 PC: 13fc9 | Write file or device (Write 256 bytes on handle 5)
2018-12-17T22:54:35.464920575Z 64 PC: 13fc9 | Write file or device (Write 256 bytes on handle 5)
2018-12-17T22:54:35.468035049Z 64 PC: 13fc9 | Write file or device (Write 256 bytes on handle 5)
2018-12-17T22:54:35.475015331Z 64 PC: 13fc9 | Write file or device (Write 256 bytes on handle 5)
2018-12-17T22:54:35.47855786Z 64 PC: 13fc9 | Write file or device (Write 256 bytes on handle 5)
2018-12-17T22:54:35.490547007Z 64 PC: 13fc9 | Write file or device (Write 256 bytes on handle 5)
2018-12-17T22:54:35.493827869Z 64 PC: 13fc9 | Write file or device (Write 256 bytes on handle 5)
2018-12-17T22:54:35.508476741Z 64 PC: 13fc9 | Write file or device (Write 144 bytes on handle 5)
2018-12-17T22:54:35.511211442Z 64 PC: 1402a | Write file or device (Write 6 bytes on handle 5)
2018-12-17T22:54:35.513825349Z 87 PC: 13e3e | Get or set file date and time
2018-12-17T22:54:35.516302238Z 62 PC: 14033 | Close file
2018-12-17T22:54:35.569361482Z 67 PC: 13e17 | Get or set file attributes
2018-12-17T22:54:35.584236344Z 67 PC: 13df1 | Get or set file attributes
2018-12-17T22:54:35.594550381Z 61 PC: 13ee3 | Open file (Filename = 'C:\dOs\CoMmAnD.cOm')
2018-12-17T22:54:35.602304132Z 67 PC: 13e17 | Get or set file attributes
2018-12-17T22:54:35.608507735Z 98 PC: 13eca | Get current PSP
2018-12-17T22:54:35.610666975Z 53 PC: 12aea | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:54:35.611715398Z 53 PC: 12aea | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:54:35.61274695Z 53 PC: 12aea | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:54:35.614211749Z 53 PC: 12aea | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:54:35.615258288Z 53 PC: 12aea | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:54:35.616265998Z 53 PC: 12aea | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:35.61806758Z 53 PC: 12aea | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:54:35.619061906Z 53 PC: 12aea | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:54:35.620045296Z 53 PC: 12aea | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:54:35.621837256Z 53 PC: 12aea | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:54:35.62287312Z 53 PC: 12aea | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:54:35.624715645Z 53 PC: 12aea | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:54:35.625978311Z 53 PC: 12aea | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:54:35.627038542Z 53 PC: 12aea | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:54:35.628041777Z 53 PC: 12aea | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:54:35.629197995Z 53 PC: 12aea | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:54:35.630275433Z 53 PC: 12aea | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:54:35.631370956Z 53 PC: 12aea | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:54:35.632513209Z 53 PC: 12aea | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:54:35.6337231Z 37 PC: 12aff | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:54:35.634577324Z 37 PC: 12b07 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:54:35.635634845Z 37 PC: 12b0f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:35.636738383Z 37 PC: 12b17 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:54:35.637806967Z 68 PC: 13175 | I/O control for devices (Set for = '�n$P3�&���t&�&�>�t��&�')
2018-12-17T22:54:35.639252556Z 64 PC: 12f08 | Write file or device (Write 13 bytes on handle 1)
2018-12-17T22:54:35.64131297Z 64 PC: 12f08 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:54:35.642450997Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:54:35.64365851Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:54:35.644903118Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:54:35.645877807Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:54:35.647027343Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:54:35.647977163Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:54:35.649044653Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:54:35.650171542Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:54:35.6512935Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:54:35.652268995Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:54:35.653459586Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:54:35.654463863Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:54:35.655461369Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:54:35.656617833Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:54:35.657894726Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:54:35.658876429Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:54:35.659999253Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:54:35.660975593Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:54:35.661967564Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:54:35.663065138Z 76 PC: 12c80 | Terminate with return code (Return code = '0')