Sample viewer

vx.netlux.org/Virus.DOS.Gimon.2266

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:29.537735497Z 67 PC: 151ac | Get or set file attributes
2018-12-17T22:56:29.890158049Z 90 PC: 151b9 | Create unique file
2018-12-17T22:56:29.913435176Z 62 PC: 151be | Close file
2018-12-17T22:56:29.915869864Z 65 PC: 151c3 | Delete file (Filename = 'c:\ABAFDFDL')
2018-12-17T22:56:29.926644403Z 91 PC: 151db | Create new file
2018-12-17T22:56:29.938647042Z 64 PC: 151e7 | Write file or device (Write 2266 bytes on handle 5)
2018-12-17T22:56:29.948712367Z 62 PC: 151eb | Close file
2018-12-17T22:56:29.965361713Z 61 PC: 151fa | Open file (Filename = 'c:\config.sys')
2018-12-17T22:56:29.975232953Z 63 PC: 15206 | Read file or device (Read 1000 bytes on handle 5)
2018-12-17T22:56:29.982294671Z 64 PC: 15235 | Write file or device (Write 21 bytes on handle 5)
2018-12-17T22:56:29.985831542Z 62 PC: 15239 | Close file
2018-12-17T22:56:29.994911775Z 58 PC: 1523e | Remove subdirectory
2018-12-17T22:56:30.001579352Z 53 PC: 15254 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:56:30.003393022Z 37 PC: 1525f | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:56:30.006374868Z 37 PC: 1526e | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:56:30.008624939Z 9 PC: 1514b | Display string (String= 'Generic triage goat. ')
2018-12-17T22:56:30.013318274Z 76 PC: 15150 | Terminate with return code (Return code = '0')