Sample viewer

vx.netlux.org/Virus.DOS.Intruder.1317.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:00:29.714391275Z 47 PC: 130c3 | Get disk transfer address
2018-12-17T22:00:29.716152948Z 26 PC: 130d7 | Set disk transfer address
2018-12-17T22:00:29.717965212Z 71 PC: 12d88 | Get current directory
2018-12-17T22:00:29.720708706Z 26 PC: 12e07 | Set disk transfer address
2018-12-17T22:00:29.721665112Z 78 PC: 12e1b | Find first file
2018-12-17T22:00:29.727691128Z 61 PC: 12ec1 | Open file (Filename = '\TEST.EXE')
2018-12-17T22:00:29.735305578Z 63 PC: 12ed2 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:00:29.738481967Z 66 PC: 12f03 | Move file pointer
2018-12-17T22:00:29.740912815Z 63 PC: 12f11 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:00:29.747542695Z 79 PC: 12e36 | Find next file
2018-12-17T22:00:29.750011582Z 26 PC: 12e48 | Set disk transfer address
2018-12-17T22:00:29.75304592Z 78 PC: 12e52 | Find first file
2018-12-17T22:00:29.758800743Z 26 PC: 12e6b | Set disk transfer address
2018-12-17T22:00:29.760369471Z 79 PC: 12e6f | Find next file
2018-12-17T22:00:29.763620341Z 26 PC: 12e6b | Set disk transfer address
2018-12-17T22:00:29.764651315Z 79 PC: 12e6f | Find next file
2018-12-17T22:00:29.767150154Z 26 PC: 12e6b | Set disk transfer address
2018-12-17T22:00:29.769383723Z 79 PC: 12e6f | Find next file
2018-12-17T22:00:29.771882554Z 26 PC: 12e6b | Set disk transfer address
2018-12-17T22:00:29.772842282Z 79 PC: 12e6f | Find next file
2018-12-17T22:00:29.775584768Z 26 PC: 12e6b | Set disk transfer address
2018-12-17T22:00:29.777698142Z 79 PC: 12e6f | Find next file
2018-12-17T22:00:29.780578313Z 26 PC: 12e6b | Set disk transfer address
2018-12-17T22:00:29.781888032Z 79 PC: 12e6f | Find next file
2018-12-17T22:00:29.785437286Z 26 PC: 12e6b | Set disk transfer address
2018-12-17T22:00:29.786317388Z 79 PC: 12e6f | Find next file
2018-12-17T22:00:29.790528767Z 26 PC: 12e6b | Set disk transfer address
2018-12-17T22:00:29.796629116Z 79 PC: 12e6f | Find next file
2018-12-17T22:00:29.799243079Z 26 PC: 12e6b | Set disk transfer address
2018-12-17T22:00:29.800415991Z 79 PC: 12e6f | Find next file
2018-12-17T22:00:29.804055674Z 26 PC: 12e07 | Set disk transfer address
2018-12-17T22:00:29.805464172Z 78 PC: 12e1b | Find first file
2018-12-17T22:00:29.811219097Z 61 PC: 12ec1 | Open file (Filename = '\TEST.EXE')
2018-12-17T22:00:29.818323601Z 63 PC: 12ed2 | Read file or device (Read 28 bytes on handle 6)
2018-12-17T22:00:29.821615421Z 66 PC: 12f03 | Move file pointer
2018-12-17T22:00:29.823482719Z 63 PC: 12f11 | Read file or device (Read 2 bytes on handle 6)
2018-12-17T22:00:29.82784997Z 79 PC: 12e36 | Find next file
2018-12-17T22:00:29.830889Z 26 PC: 12e48 | Set disk transfer address
2018-12-17T22:00:29.831974282Z 78 PC: 12e52 | Find first file
2018-12-17T22:00:29.843160689Z 26 PC: 12e6b | Set disk transfer address
2018-12-17T22:00:29.844323502Z 79 PC: 12e6f | Find next file
2018-12-17T22:00:29.847018652Z 26 PC: 12e6b | Set disk transfer address
2018-12-17T22:00:29.849380276Z 79 PC: 12e6f | Find next file
2018-12-17T22:00:29.851998358Z 26 PC: 12e6b | Set disk transfer address
2018-12-17T22:00:29.853309195Z 79 PC: 12e6f | Find next file
2018-12-17T22:00:29.85589356Z 26 PC: 12e6b | Set disk transfer address
2018-12-17T22:00:29.857708528Z 79 PC: 12e6f | Find next file
2018-12-17T22:00:29.860095055Z 26 PC: 12e6b | Set disk transfer address
2018-12-17T22:00:29.861069987Z 79 PC: 12e6f | Find next file
2018-12-17T22:00:29.863713821Z 26 PC: 12e6b | Set disk transfer address
2018-12-17T22:00:29.864714643Z 79 PC: 12e6f | Find next file
2018-12-17T22:00:29.867148008Z 26 PC: 12e6b | Set disk transfer address
2018-12-17T22:00:29.872805873Z 79 PC: 12e6f | Find next file
2018-12-17T22:00:29.877567268Z 26 PC: 12e6b | Set disk transfer address
2018-12-17T22:00:29.878591734Z 79 PC: 12e6f | Find next file
2018-12-17T22:00:29.8823854Z 26 PC: 12e6b | Set disk transfer address
2018-12-17T22:00:29.88333326Z 79 PC: 12e6f | Find next file
2018-12-17T22:00:29.885597282Z 76 PC: 12c28 | Terminate with return code (Return code = '0')