Sample viewer

vx.netlux.org/Virus.DOS.Zorm.1475

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:38.513898828Z 61 PC: 12add | Open file (Filename = 'Í ÀŸ')
2018-12-17T22:55:38.519743385Z 105 PC: 12b0a | Get or set media id
2018-12-17T22:55:38.522156153Z 37 PC: 12b88 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:38.523622952Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.525237609Z 9 PC: 12a47 | Display string (String= 'HOOPS! i m afraid your puter is now infected by zorm-d virus')
2018-12-17T22:55:38.532747217Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.534383091Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:55:38.535844619Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.537709124Z 72 PC: 12174 | Allocate memory
2018-12-17T22:55:38.540919486Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.542956142Z 72 PC: 1218d | Allocate memory
2018-12-17T22:55:38.54773046Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.549406128Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:55:38.550926038Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.552487039Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:38.561880868Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.563546999Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.565064026Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.568027495Z 66 PC: 9f019 | Move file pointer
2018-12-17T22:55:38.57055449Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.573046792Z 63 PC: 9f019 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:55:38.576593964Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.590702798Z 62 PC: 122ab | Close file
2018-12-17T22:55:38.593376807Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.595698447Z 66 PC: 9f019 | Move file pointer
2018-12-17T22:55:38.59784453Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.60453611Z 63 PC: 9f019 | Read file or device (Read 28 bytes on handle 6)
2018-12-17T22:55:38.606482158Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.609323665Z 62 PC: 122ab | Close file
2018-12-17T22:55:38.611544588Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.613584502Z 66 PC: 9f019 | Move file pointer
2018-12-17T22:55:38.616825904Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.618700118Z 63 PC: 9f019 | Read file or device (Read 28 bytes on handle 7)
2018-12-17T22:55:38.620526142Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.628017078Z 62 PC: 122ab | Close file
2018-12-17T22:55:38.63873463Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.640781296Z 66 PC: 9f019 | Move file pointer
2018-12-17T22:55:38.64336566Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.645598565Z 63 PC: 9f019 | Read file or device (Read 28 bytes on handle 8)
2018-12-17T22:55:38.647506713Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.650552747Z 62 PC: 122ab | Close file
2018-12-17T22:55:38.652613757Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.654589999Z 66 PC: 9f019 | Move file pointer
2018-12-17T22:55:38.656828168Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.659926745Z 63 PC: 9f019 | Read file or device (Read 28 bytes on handle 9)
2018-12-17T22:55:38.662118345Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.664348691Z 62 PC: 122ab | Close file
2018-12-17T22:55:38.671862217Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.673990903Z 66 PC: 9f019 | Move file pointer
2018-12-17T22:55:38.676317463Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.679133044Z 63 PC: 9f019 | Read file or device (Read 28 bytes on handle 10)
2018-12-17T22:55:38.681135393Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.683092547Z 62 PC: 122ab | Close file
2018-12-17T22:55:38.685762826Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.68764366Z 66 PC: 9f019 | Move file pointer
2018-12-17T22:55:38.690474473Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.693120926Z 63 PC: 9f019 | Read file or device (Read 28 bytes on handle 11)
2018-12-17T22:55:38.695244439Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.697377191Z 62 PC: 122ab | Close file
2018-12-17T22:55:38.699460058Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.70207519Z 66 PC: 9f019 | Move file pointer
2018-12-17T22:55:38.704050411Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.706032459Z 63 PC: 9f019 | Read file or device (Read 28 bytes on handle 12)
2018-12-17T22:55:38.708815917Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.71081564Z 62 PC: 122ab | Close file
2018-12-17T22:55:38.712737103Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.717185182Z 66 PC: 9f019 | Move file pointer
2018-12-17T22:55:38.719233191Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.721422664Z 63 PC: 9f019 | Read file or device (Read 28 bytes on handle 13)
2018-12-17T22:55:38.724141022Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.726645875Z 62 PC: 122ab | Close file
2018-12-17T22:55:38.728655205Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.731003942Z 66 PC: 9f019 | Move file pointer
2018-12-17T22:55:38.732893097Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.734963328Z 63 PC: 9f019 | Read file or device (Read 28 bytes on handle 14)
2018-12-17T22:55:38.737445238Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.739669458Z 62 PC: 122ab | Close file
2018-12-17T22:55:38.741748696Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.743763402Z 66 PC: 9f019 | Move file pointer
2018-12-17T22:55:38.746566806Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.74860695Z 63 PC: 9f019 | Read file or device (Read 28 bytes on handle 15)
2018-12-17T22:55:38.750679799Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.753705654Z 62 PC: 122ab | Close file
2018-12-17T22:55:38.755787947Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.757614661Z 66 PC: 9f019 | Move file pointer
2018-12-17T22:55:38.760447046Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.762782007Z 63 PC: 9f019 | Read file or device (Read 28 bytes on handle 16)
2018-12-17T22:55:38.764863336Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.767704221Z 62 PC: 122ab | Close file
2018-12-17T22:55:38.770060151Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.771869926Z 66 PC: 9f019 | Move file pointer
2018-12-17T22:55:38.774110947Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.776894643Z 63 PC: 9f019 | Read file or device (Read 28 bytes on handle 17)
2018-12-17T22:55:38.779806688Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.781911105Z 62 PC: 122ab | Close file
2018-12-17T22:55:38.784891283Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.786720261Z 66 PC: 9f019 | Move file pointer
2018-12-17T22:55:38.78876188Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.791557597Z 63 PC: 9f019 | Read file or device (Read 28 bytes on handle 18)
2018-12-17T22:55:38.793891132Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.795971018Z 62 PC: 122ab | Close file
2018-12-17T22:55:38.798732431Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.800823928Z 66 PC: 9f019 | Move file pointer
2018-12-17T22:55:38.802864594Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.805086571Z 63 PC: 9f019 | Read file or device (Read 28 bytes on handle 19)
2018-12-17T22:55:38.807995387Z 87 PC: 9f019 | Get or set file date and time
2018-12-17T22:55:38.810010359Z 62 PC: 122ab | Close file
2018-12-17T22:55:38.813895518Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.81619366Z 99 PC: 996c7 | Get DBCS lead byte table pointer
2018-12-17T22:55:38.817815188Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.821795614Z 56 PC: 93ee9 | Get or set country info
2018-12-17T22:55:38.841405527Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.843247379Z 64 PC: 99938 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:55:38.84879531Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.851260698Z 25 PC: 93f52 | Get default drive
2018-12-17T22:55:38.853358129Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.855978408Z 71 PC: 961cd | Get current directory
2018-12-17T22:55:38.862804076Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.864868235Z 64 PC: 99938 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:55:38.868948775Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.871513148Z 2 PC: 961a2 | Character output (Char = '3e')
2018-12-17T22:55:38.874711781Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.876510674Z 93 PC: 94010 | File sharing functions
2018-12-17T22:55:38.878901324Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.881146217Z 93 PC: 94017 | File sharing functions
2018-12-17T22:55:38.883819819Z 37 PC: 9f019 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:38.892007658Z 10 PC: 94029 | Buffered keyboard input