Sample viewer

vx.netlux.org/Virus.DOS.Tricks.193

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:25.431072983Z 37 PC: 12ad9 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:25.432822769Z 78 PC: 12a58 | Find first file
2018-12-17T22:56:25.440553675Z 61 PC: 12a62 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:56:25.448201775Z 63 PC: 12a6f | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:56:25.455615604Z 66 PC: 12a7f | Move file pointer
2018-12-17T22:56:25.457875608Z 37 PC: 12ad9 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:25.460222188Z 64 PC: 12ac9 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T22:56:25.475695355Z 37 PC: 12ad9 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:25.485468122Z 66 PC: 12aa0 | Move file pointer
2018-12-17T22:56:25.488246313Z 64 PC: 12aab | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:56:25.496591432Z 62 PC: 12aaf | Close file
2018-12-17T22:56:25.505556015Z 79 PC: 12ab6 | Find next file
2018-12-17T22:56:25.509450642Z 61 PC: 12a62 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:56:25.517030971Z 63 PC: 12a6f | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:56:25.524448095Z 66 PC: 12a7f | Move file pointer
2018-12-17T22:56:25.527350217Z 37 PC: 12ad9 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:25.529435226Z 64 PC: 12ac9 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T22:56:25.53280467Z 37 PC: 12ad9 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:25.534761853Z 66 PC: 12aa0 | Move file pointer
2018-12-17T22:56:25.537122447Z 64 PC: 12aab | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:56:25.540381092Z 62 PC: 12aaf | Close file
2018-12-17T22:56:25.550438424Z 79 PC: 12ab6 | Find next file
2018-12-17T22:56:25.554850443Z 61 PC: 12a62 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:56:25.577622349Z 63 PC: 12a6f | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:56:25.596400963Z 66 PC: 12a7f | Move file pointer
2018-12-17T22:56:25.599145901Z 37 PC: 12ad9 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:25.600781098Z 64 PC: 12ac9 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T22:56:25.604106399Z 37 PC: 12ad9 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:25.618346943Z 66 PC: 12aa0 | Move file pointer
2018-12-17T22:56:25.620393277Z 64 PC: 12aab | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:56:25.623795242Z 62 PC: 12aaf | Close file
2018-12-17T22:56:25.633366161Z 79 PC: 12ab6 | Find next file
2018-12-17T22:56:25.636312681Z 61 PC: 12a62 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:56:25.659366206Z 63 PC: 12a6f | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:56:25.67002054Z 66 PC: 12a7f | Move file pointer
2018-12-17T22:56:25.672114179Z 37 PC: 12ad9 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:25.684771347Z 64 PC: 12ac9 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T22:56:25.688251449Z 37 PC: 12ad9 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:25.690248688Z 66 PC: 12aa0 | Move file pointer
2018-12-17T22:56:25.691900649Z 64 PC: 12aab | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:56:25.706633801Z 62 PC: 12aaf | Close file
2018-12-17T22:56:25.716264944Z 79 PC: 12ab6 | Find next file
2018-12-17T22:56:25.719776195Z 61 PC: 12a62 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:56:25.727533409Z 63 PC: 12a6f | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:56:25.735837332Z 66 PC: 12a7f | Move file pointer
2018-12-17T22:56:25.737861887Z 37 PC: 12ad9 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:25.739663557Z 64 PC: 12ac9 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T22:56:25.743649653Z 37 PC: 12ad9 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:25.74560812Z 66 PC: 12aa0 | Move file pointer
2018-12-17T22:56:25.747739177Z 64 PC: 12aab | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:56:25.751508197Z 62 PC: 12aaf | Close file
2018-12-17T22:56:25.761194434Z 79 PC: 12ab6 | Find next file
2018-12-17T22:56:25.764571069Z 61 PC: 12a62 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:56:25.773636528Z 63 PC: 12a6f | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:56:25.780892297Z 66 PC: 12a7f | Move file pointer
2018-12-17T22:56:25.78253657Z 37 PC: 12ad9 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:25.784901965Z 64 PC: 12ac9 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T22:56:25.794338055Z 37 PC: 12ad9 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:25.796238016Z 66 PC: 12aa0 | Move file pointer
2018-12-17T22:56:25.798231934Z 64 PC: 12aab | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:56:25.806919638Z 62 PC: 12aaf | Close file
2018-12-17T22:56:25.816422877Z 79 PC: 12ab6 | Find next file
2018-12-17T22:56:25.819682237Z 61 PC: 12a62 | Open file (Filename = 'PAH.COM')
2018-12-17T22:56:25.828091821Z 63 PC: 12a6f | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:56:25.836280863Z 66 PC: 12a7f | Move file pointer
2018-12-17T22:56:25.838326273Z 37 PC: 12ad9 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:25.840849504Z 64 PC: 12ac9 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T22:56:25.844510503Z 37 PC: 12ad9 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:25.846272351Z 66 PC: 12aa0 | Move file pointer
2018-12-17T22:56:25.848383478Z 64 PC: 12aab | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:56:25.85245365Z 62 PC: 12aaf | Close file
2018-12-17T22:56:25.861766501Z 79 PC: 12ab6 | Find next file
2018-12-17T22:56:25.865030004Z 61 PC: 12a62 | Open file (Filename = 'TEST.COM')
2018-12-17T22:56:25.873606548Z 63 PC: 12a6f | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:56:25.87684157Z 66 PC: 12a7f | Move file pointer
2018-12-17T22:56:25.87881417Z 37 PC: 12ad9 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:25.881369898Z 64 PC: 12ac9 | Write file or device (Write 193 bytes on handle 5)
2018-12-17T22:56:25.885046525Z 37 PC: 12ad9 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:56:25.886809656Z 66 PC: 12aa0 | Move file pointer
2018-12-17T22:56:25.889458743Z 64 PC: 12aab | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:56:25.893013294Z 62 PC: 12aaf | Close file
2018-12-17T22:56:25.901989938Z 79 PC: 12ab6 | Find next file