Sample viewer

vx.netlux.org/Virus.DOS.Search.1589

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:28.969920924Z 47 PC: 13e43 | Get disk transfer address
2018-12-17T22:55:28.972163249Z 71 PC: 13e5e | Get current directory
2018-12-17T22:55:28.9757347Z 59 PC: 13e7e | Change current directory
2018-12-17T22:55:28.980694933Z 26 PC: 14033 | Set disk transfer address
2018-12-17T22:55:28.982454206Z 78 PC: 14052 | Find first file
2018-12-17T22:55:28.989630519Z 61 PC: 14065 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:55:28.997162634Z 66 PC: 1407a | Move file pointer
2018-12-17T22:55:28.998918221Z 62 PC: 14084 | Close file
2018-12-17T22:55:29.001233371Z 61 PC: 13ec1 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:55:29.014438655Z 63 PC: 13ed3 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:55:29.019693839Z 62 PC: 13ed7 | Close file
2018-12-17T22:55:29.022317078Z 67 PC: 13f22 | Get or set file attributes
2018-12-17T22:55:29.044216137Z 61 PC: 13f2b | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:55:29.051553039Z 63 PC: 13f3c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:55:29.05915878Z 66 PC: 13f64 | Move file pointer
2018-12-17T22:55:29.060608193Z 64 PC: 13f6d | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:55:29.062834363Z 66 PC: 13f78 | Move file pointer
2018-12-17T22:55:29.064959825Z 64 PC: 13fb4 | Write file or device (Write 1589 bytes on handle 5)
2018-12-17T22:55:29.075417021Z 87 PC: 13fca | Get or set file date and time
2018-12-17T22:55:29.077466205Z 67 PC: 13fd8 | Get or set file attributes
2018-12-17T22:55:29.083401203Z 26 PC: 13ffa | Set disk transfer address
2018-12-17T22:55:29.085365928Z 59 PC: 14008 | Change current directory
2018-12-17T22:55:29.09044703Z 2 PC: 13e0a | Character output (Char = '0d')
2018-12-17T22:55:29.093289594Z 2 PC: 13e0a | Character output (Char = '0a')
2018-12-17T22:55:29.097918077Z 2 PC: 13e0a | Character output (Char = '48')
2018-12-17T22:55:29.100245126Z 2 PC: 13e0a | Character output (Char = '65')
2018-12-17T22:55:29.102561422Z 2 PC: 13e0a | Character output (Char = '6c')
2018-12-17T22:55:29.109360814Z 2 PC: 13e0a | Character output (Char = '6c')
2018-12-17T22:55:29.113371891Z 2 PC: 13e0a | Character output (Char = '6f')
2018-12-17T22:55:29.115640187Z 2 PC: 13e0a | Character output (Char = '2c')
2018-12-17T22:55:29.118335902Z 2 PC: 13e0a | Character output (Char = '20')
2018-12-17T22:55:29.120611197Z 2 PC: 13e0a | Character output (Char = '74')
2018-12-17T22:55:29.122863096Z 2 PC: 13e0a | Character output (Char = '68')
2018-12-17T22:55:29.125654493Z 2 PC: 13e0a | Character output (Char = '65')
2018-12-17T22:55:29.127991082Z 2 PC: 13e0a | Character output (Char = '72')
2018-12-17T22:55:29.130276407Z 2 PC: 13e0a | Character output (Char = '65')
2018-12-17T22:55:29.146021785Z 2 PC: 13e0a | Character output (Char = '21')
2018-12-17T22:55:29.148452228Z 2 PC: 13e0a | Character output (Char = '20')
2018-12-17T22:55:29.150332355Z 2 PC: 13e0a | Character output (Char = '20')
2018-12-17T22:55:29.15185063Z 2 PC: 13e0a | Character output (Char = '41')
2018-12-17T22:55:29.153487995Z 2 PC: 13e0a | Character output (Char = '6e')
2018-12-17T22:55:29.15510802Z 2 PC: 13e0a | Character output (Char = '79')
2018-12-17T22:55:29.156622954Z 2 PC: 13e0a | Character output (Char = '6f')
2018-12-17T22:55:29.158777895Z 2 PC: 13e0a | Character output (Char = '6e')
2018-12-17T22:55:29.16086364Z 2 PC: 13e0a | Character output (Char = '65')
2018-12-17T22:55:29.162992145Z 2 PC: 13e0a | Character output (Char = '20')
2018-12-17T22:55:29.165286121Z 2 PC: 13e0a | Character output (Char = '6c')
2018-12-17T22:55:29.166813277Z 2 PC: 13e0a | Character output (Char = '6f')
2018-12-17T22:55:29.16830639Z 2 PC: 13e0a | Character output (Char = '6f')
2018-12-17T22:55:29.17034934Z 2 PC: 13e0a | Character output (Char = '6b')
2018-12-17T22:55:29.172021624Z 2 PC: 13e0a | Character output (Char = '69')
2018-12-17T22:55:29.173477849Z 2 PC: 13e0a | Character output (Char = '6e')
2018-12-17T22:55:29.175492582Z 2 PC: 13e0a | Character output (Char = '67')
2018-12-17T22:55:29.177065835Z 2 PC: 13e0a | Character output (Char = '20')
2018-12-17T22:55:29.178793282Z 2 PC: 13e0a | Character output (Char = '66')
2018-12-17T22:55:29.180848965Z 2 PC: 13e0a | Character output (Char = '6f')
2018-12-17T22:55:29.183153165Z 2 PC: 13e0a | Character output (Char = '72')
2018-12-17T22:55:29.185448676Z 2 PC: 13e0a | Character output (Char = '20')
2018-12-17T22:55:29.18907853Z 2 PC: 13e0a | Character output (Char = '61')
2018-12-17T22:55:29.191652506Z 2 PC: 13e0a | Character output (Char = '20')
2018-12-17T22:55:29.193966883Z 2 PC: 13e0a | Character output (Char = '68')
2018-12-17T22:55:29.196477261Z 2 PC: 13e0a | Character output (Char = '6f')
2018-12-17T22:55:29.199776734Z 2 PC: 13e0a | Character output (Char = '6d')
2018-12-17T22:55:29.202160425Z 2 PC: 13e0a | Character output (Char = '65')
2018-12-17T22:55:29.204368705Z 2 PC: 13e0a | Character output (Char = '3f')
2018-12-17T22:55:29.207236166Z 2 PC: 13e0a | Character output (Char = '0d')
2018-12-17T22:55:29.210669883Z 2 PC: 13e0a | Character output (Char = '0a')
2018-12-17T22:55:29.214820924Z 76 PC: 13e10 | Terminate with return code (Return code = '10')