Sample viewer

vx.netlux.org/Virus.DOS.Chang.1759

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:58:45.539589857Z 74 PC: 12da5 | Reallocate memory
2018-12-17T22:58:45.54233636Z 74 PC: 12a54 | Reallocate memory
2018-12-17T22:58:45.543963418Z 48 PC: 12ab6 | Get DOS version
2018-12-17T22:58:45.546027536Z 67 PC: 9f8a0 | Get or set file attributes
2018-12-17T22:58:45.553509991Z 75 PC: 12af4 | Execute program
2018-12-17T22:58:45.559954873Z 25 PC: 9f876 | Get default drive
2018-12-17T22:58:45.561899339Z 67 PC: 9f8a0 | Get or set file attributes
2018-12-17T22:58:45.568658334Z 75 PC: 12af4 | Execute program
2018-12-17T22:58:45.57601731Z 67 PC: 9f8a0 | Get or set file attributes
2018-12-17T22:58:45.585348315Z 78 PC: 9f8a6 | Find first file
2018-12-17T22:58:45.591876438Z 47 PC: 9f8ad | Get disk transfer address
2018-12-17T22:58:45.595092036Z 61 PC: 9f8ea | Open file (Filename = '�.����Zu ��^_ZY[X���>:����gs���>: ')
2018-12-17T22:58:45.602965078Z 63 PC: 9f902 | Read file or device (Read 32 bytes on handle 5)
2018-12-17T22:58:45.608444457Z 66 PC: 9f907 | Move file pointer
2018-12-17T22:58:45.610462309Z 63 PC: 9f902 | Read file or device (Read 8 bytes on handle 5)
2018-12-17T22:58:45.613115964Z 66 PC: 9f907 | Move file pointer
2018-12-17T22:58:45.614599474Z 64 PC: 9f8fd | Write file or device (Write 11 bytes on handle 5)
2018-12-17T22:58:45.62189992Z 64 PC: 9f8fd | Write file or device (Write 1759 bytes on handle 5)
2018-12-17T22:58:45.992046057Z 66 PC: 9f907 | Move file pointer
2018-12-17T22:58:45.994087114Z 64 PC: 9f8fd | Write file or device (Write 32 bytes on handle 5)
2018-12-17T22:58:45.998591568Z 62 PC: 9f8ef | Close file
2018-12-17T22:58:46.007862015Z 67 PC: 9f8c9 | Get or set file attributes
2018-12-17T22:58:46.018188489Z 61 PC: 9f8d3 | Open file (Filename = '�.����Zu ��^_ZY[X���>:����gs���>: ')
2018-12-17T22:58:46.02724913Z 87 PC: 9f8e0 | Get or set file date and time
2018-12-17T22:58:46.028900641Z 62 PC: 9f8e5 | Close file
2018-12-17T22:58:46.03498811Z 75 PC: 12af4 | Execute program
2018-12-17T22:58:46.136513779Z 48 PC: 38db4 | Get DOS version
2018-12-17T22:58:46.139642136Z 74 PC: 38e04 | Reallocate memory
2018-12-17T22:58:46.14186882Z 48 PC: 38e68 | Get DOS version
2018-12-17T22:58:46.143572811Z 53 PC: 38e70 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:46.146320628Z 37 PC: 38e82 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:46.148195163Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:58:46.149687538Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:58:46.152124297Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:58:46.153584889Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:58:46.155034273Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:58:46.157425035Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:58:46.159048418Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:58:46.160731566Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:58:46.162592651Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:58:46.168522088Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:58:46.169809177Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:58:46.172209558Z 37 PC: 3fb9e | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:58:46.17359077Z 37 PC: 3fb9e | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:58:46.174865353Z 37 PC: 3fb9e | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:58:46.176703692Z 37 PC: 3fb9e | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:58:46.177977136Z 37 PC: 3fb9e | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:58:46.179258893Z 37 PC: 3fb9e | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:58:46.180919328Z 37 PC: 3fb9e | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:58:46.182044021Z 37 PC: 3fb9e | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:58:46.183479573Z 37 PC: 3fba5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:58:46.186475454Z 37 PC: 3fbaa | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:58:46.187872002Z 68 PC: 38f13 | I/O control for devices (Set for = '��r��R')
2018-12-17T22:58:46.189222137Z 68 PC: 38f13 | I/O control for devices (Set for = '@�')
2018-12-17T22:58:46.19138165Z 68 PC: 38f13 | I/O control for devices (Set for = 'B�N;�tC��vb�F u\� �W� ��� ')
2018-12-17T22:58:46.192951712Z 68 PC: 38f13 | I/O control for devices (Set for = '� �W� ��� ')
2018-12-17T22:58:46.194529922Z 68 PC: 38f13 | I/O control for devices (Set for = '� �W� ��� ')
2018-12-17T22:58:46.197475477Z 53 PC: 29ea3 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:58:46.198638076Z 37 PC: 29eb5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:58:46.199796891Z 53 PC: 2f8ee | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:46.202165877Z 53 PC: 2f8fb | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:58:46.203610457Z 53 PC: 2f908 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:46.205003659Z 37 PC: 2f91d | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:58:46.20651678Z 37 PC: 2f925 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:58:46.208395616Z 37 PC: 2f92d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:46.209666374Z 53 PC: 33650 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:58:46.210757022Z 53 PC: 3365d | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:58:46.212441986Z 53 PC: 3366c | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:58:46.213854115Z 37 PC: 33679 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:58:46.21516799Z 53 PC: 33680 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:58:46.217041537Z 37 PC: 3368d | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T22:58:46.21813913Z 53 PC: 33699 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:58:46.225349017Z 48 PC: 3375e | Get DOS version
2018-12-17T22:58:46.227658767Z 74 PC: 3440b | Reallocate memory
2018-12-17T22:58:46.229304876Z 74 PC: 3440b | Reallocate memory
2018-12-17T22:58:46.230731353Z 68 PC: 33565 | I/O control for devices (Set for = 'pt������n~�:4*P')
2018-12-17T22:58:46.232607742Z 68 PC: 33565 | I/O control for devices (Set for = '')
2018-12-17T22:58:46.234746804Z 51 PC: 33583 | Get or set Ctrl-Break
2018-12-17T22:58:46.235585449Z 51 PC: 3358f | Get or set Ctrl-Break
2018-12-17T22:58:46.238015918Z 72 PC: 33bc6 | Allocate memory
2018-12-17T22:58:46.240680324Z 74 PC: 3440b | Reallocate memory
2018-12-17T22:58:46.242411757Z 72 PC: 33bc6 | Allocate memory
2018-12-17T22:58:46.245238492Z 37 PC: 2ef71 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:58:46.255782058Z 48 PC: 23cdf | Get DOS version
2018-12-17T22:58:46.257433193Z 61 PC: 23aec | Open file (Filename = 'C:\DOS\qbasic.ini')
2018-12-17T22:58:46.267672466Z 63 PC: 23aec | Read file or device (Read 120 bytes on handle 5)
2018-12-17T22:58:46.27382935Z 63 PC: 23aec | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:58:46.276219207Z 63 PC: 23aec | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:58:46.279296552Z 63 PC: 23aec | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:58:46.281766406Z 63 PC: 23aec | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:58:46.284539213Z 63 PC: 23aec | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:58:46.287899672Z 63 PC: 23aec | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:58:46.290371358Z 63 PC: 23aec | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:58:46.293153498Z 63 PC: 23aec | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:58:46.300313589Z 62 PC: 23aec | Close file
2018-12-17T22:58:46.302068403Z 53 PC: 2f1fa | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:58:46.303147069Z 37 PC: 2f207 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:58:46.307895478Z 53 PC: 4c428 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:58:46.309177377Z 37 PC: 4c434 | Set interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:58:46.314124036Z 53 PC: 41ea5 | Get interrupt vector (Interrupt = '51' AKA 'Get or set Ctrl-Break')
2018-12-17T22:58:46.322431399Z 37 PC: 2ef71 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:58:46.324767773Z 53 PC: 2f1fa | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T22:58:46.32614862Z 37 PC: 2f207 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:58:46.328393185Z 53 PC: 41ea5 | Get interrupt vector (Interrupt = '51' AKA 'Get or set Ctrl-Break')
2018-12-17T22:58:46.330431307Z 53 PC: 4cd19 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:58:46.331745353Z 37 PC: 4cd2c | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:58:46.333254913Z 53 PC: 4cd19 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:58:46.334707773Z 37 PC: 4cd2c | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:58:46.335865356Z 53 PC: 4cd19 | Get interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-17T22:58:46.338437331Z 37 PC: 4cd2c | Set interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-17T22:58:46.339748384Z 53 PC: 4cd19 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:58:46.348291898Z 37 PC: 4cd2c | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:58:46.349788776Z 48 PC: 4ccda | Get DOS version
2018-12-17T22:58:46.354357333Z 53 PC: 4ccf8 | Get interrupt vector (Interrupt = '21' AKA 'Sequential write')
2018-12-17T22:58:46.355424295Z 37 PC: 4cd0d | Set interrupt vector (Interrupt = '21' AKA 'Sequential write')