Sample viewer

vx.netlux.org/Virus.DOS.VCL_MUT.Empire.379

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:59:51.361102687Z 47 PC: 12a76 | Get disk transfer address
2018-12-17T22:59:51.362929573Z 26 PC: 12a87 | Set disk transfer address
2018-12-17T22:59:51.363997301Z 78 PC: 12a8f | Find first file
2018-12-17T22:59:51.370040539Z 47 PC: 12aa7 | Get disk transfer address
2018-12-17T22:59:51.37192434Z 61 PC: 12aca | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:59:51.378599724Z 63 PC: 12ad5 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:59:51.38488134Z 62 PC: 12ad9 | Close file
2018-12-17T22:59:51.387048345Z 67 PC: 12af7 | Get or set file attributes
2018-12-17T22:59:51.402766558Z 61 PC: 12afc | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:59:51.409598873Z 64 PC: 12bcf | Write file or device (Write 379 bytes on handle 25605)
2018-12-17T22:59:51.412299203Z 87 PC: 12b0f | Get or set file date and time
2018-12-17T22:59:51.414639424Z 62 PC: 12b13 | Close file
2018-12-17T22:59:51.41649289Z 67 PC: 12b20 | Get or set file attributes
2018-12-17T22:59:51.426126247Z 26 PC: 12aa1 | Set disk transfer address
2018-12-17T22:59:51.427749402Z 47 PC: 12a76 | Get disk transfer address
2018-12-17T22:59:51.42884887Z 26 PC: 12a87 | Set disk transfer address
2018-12-17T22:59:51.429911544Z 78 PC: 12a8f | Find first file
2018-12-17T22:59:51.437207308Z 47 PC: 12aa7 | Get disk transfer address
2018-12-17T22:59:51.438698255Z 61 PC: 12aca | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:59:51.44551448Z 63 PC: 12ad5 | Read file or device (Read 4 bytes on handle 6)
2018-12-17T22:59:51.449049522Z 62 PC: 12ad9 | Close file
2018-12-17T22:59:51.45363813Z 67 PC: 12af7 | Get or set file attributes
2018-12-17T22:59:51.467473721Z 61 PC: 12afc | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:59:51.475248045Z 64 PC: 12bcf | Write file or device (Write 379 bytes on handle 6)
2018-12-17T22:59:51.478089838Z 87 PC: 12b0f | Get or set file date and time
2018-12-17T22:59:51.480211535Z 62 PC: 12b13 | Close file
2018-12-17T22:59:51.4890322Z 67 PC: 12b20 | Get or set file attributes
2018-12-17T22:59:51.499102502Z 26 PC: 12aa1 | Set disk transfer address
2018-12-17T22:59:51.500690446Z 47 PC: 12a76 | Get disk transfer address
2018-12-17T22:59:51.503015703Z 26 PC: 12a87 | Set disk transfer address
2018-12-17T22:59:51.504877944Z 78 PC: 12a8f | Find first file
2018-12-17T22:59:51.511289549Z 47 PC: 12aa7 | Get disk transfer address
2018-12-17T22:59:51.513140288Z 61 PC: 12aca | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:59:51.520481147Z 63 PC: 12ad5 | Read file or device (Read 4 bytes on handle 6)
2018-12-17T22:59:51.523817636Z 62 PC: 12ad9 | Close file
2018-12-17T22:59:51.526131261Z 79 PC: 12a8f | Find next file
2018-12-17T22:59:51.529560119Z 47 PC: 12aa7 | Get disk transfer address
2018-12-17T22:59:51.53104936Z 79 PC: 12a8f | Find next file
2018-12-17T22:59:51.533876363Z 47 PC: 12aa7 | Get disk transfer address
2018-12-17T22:59:51.535985422Z 79 PC: 12a8f | Find next file
2018-12-17T22:59:51.538783168Z 47 PC: 12aa7 | Get disk transfer address
2018-12-17T22:59:51.540205698Z 79 PC: 12a8f | Find next file
2018-12-17T22:59:51.543648932Z 47 PC: 12aa7 | Get disk transfer address
2018-12-17T22:59:51.544866681Z 79 PC: 12a8f | Find next file
2018-12-17T22:59:51.547402378Z 47 PC: 12aa7 | Get disk transfer address
2018-12-17T22:59:51.549486494Z 61 PC: 12aca | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:59:51.556853795Z 63 PC: 12ad5 | Read file or device (Read 4 bytes on handle 6)
2018-12-17T22:59:51.563402059Z 62 PC: 12ad9 | Close file
2018-12-17T22:59:51.566872108Z 67 PC: 12af7 | Get or set file attributes
2018-12-17T22:59:51.577809703Z 61 PC: 12afc | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:59:51.584868715Z 64 PC: 12bcf | Write file or device (Write 379 bytes on handle 25606)
2018-12-17T22:59:51.587620709Z 87 PC: 12b0f | Get or set file date and time
2018-12-17T22:59:51.589136106Z 62 PC: 12b13 | Close file
2018-12-17T22:59:51.590691264Z 67 PC: 12b20 | Get or set file attributes
2018-12-17T22:59:51.601302904Z 26 PC: 12aa1 | Set disk transfer address
2018-12-17T22:59:51.602685124Z 47 PC: 12a76 | Get disk transfer address
2018-12-17T22:59:51.604003861Z 26 PC: 12a87 | Set disk transfer address
2018-12-17T22:59:51.605980612Z 78 PC: 12a8f | Find first file
2018-12-17T22:59:51.611776233Z 47 PC: 12aa7 | Get disk transfer address
2018-12-17T22:59:51.612827528Z 61 PC: 12aca | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:59:51.624980769Z 63 PC: 12ad5 | Read file or device (Read 4 bytes on handle 7)
2018-12-17T22:59:51.629187686Z 62 PC: 12ad9 | Close file
2018-12-17T22:59:51.630431304Z 79 PC: 12a8f | Find next file
2018-12-17T22:59:51.632367788Z 47 PC: 12aa7 | Get disk transfer address
2018-12-17T22:59:51.633221285Z 79 PC: 12a8f | Find next file
2018-12-17T22:59:51.63477955Z 47 PC: 12aa7 | Get disk transfer address
2018-12-17T22:59:51.636054691Z 79 PC: 12a8f | Find next file
2018-12-17T22:59:51.637678025Z 47 PC: 12aa7 | Get disk transfer address
2018-12-17T22:59:51.638424941Z 79 PC: 12a8f | Find next file
2018-12-17T22:59:51.6405026Z 47 PC: 12aa7 | Get disk transfer address
2018-12-17T22:59:51.64208114Z 79 PC: 12a8f | Find next file
2018-12-17T22:59:51.644354253Z 47 PC: 12aa7 | Get disk transfer address
2018-12-17T22:59:51.645472563Z 61 PC: 12aca | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:59:51.651711435Z 63 PC: 12ad5 | Read file or device (Read 4 bytes on handle 7)
2018-12-17T22:59:51.657814272Z 62 PC: 12ad9 | Close file
2018-12-17T22:59:51.659851387Z 67 PC: 12af7 | Get or set file attributes
2018-12-17T22:59:51.670141731Z 61 PC: 12afc | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:59:51.676991653Z 64 PC: 12bcf | Write file or device (Write 379 bytes on handle 7)
2018-12-17T22:59:51.680245128Z 87 PC: 12b0f | Get or set file date and time
2018-12-17T22:59:51.681784175Z 62 PC: 12b13 | Close file
2018-12-17T22:59:51.688791374Z 67 PC: 12b20 | Get or set file attributes
2018-12-17T22:59:51.699909062Z 26 PC: 12aa1 | Set disk transfer address
2018-12-17T22:59:51.701564513Z 76 PC: 12a56 | Terminate with return code (Return code = '0')