Sample viewer

vx.netlux.org/Virus.DOS.ThatsAll.618

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:00:05.672270704Z 221 PC: 12be9 | UNKNOWN!
2018-12-17T23:00:05.673908945Z 78 PC: 12c51 | Find first file
2018-12-17T23:00:05.680170979Z 53 PC: 12c58 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:05.681708022Z 37 PC: 12c6d | Set interrupt vector (Interrupt = '48' AKA 'Get DOS version')
2018-12-17T23:00:05.683206827Z 37 PC: 12c77 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:05.68538431Z 53 PC: 12c7c | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:00:05.686748644Z 37 PC: 12c91 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:00:05.688050062Z 74 PC: 12a54 | Reallocate memory
2018-12-17T23:00:05.690602429Z 48 PC: 12ab6 | Get DOS version
2018-12-17T23:00:05.692022646Z 67 PC: 9fa4c | Get or set file attributes
2018-12-17T23:00:05.69805347Z 67 PC: 9fb1b | Get or set file attributes
2018-12-17T23:00:05.704624386Z 75 PC: 12af4 | Execute program
2018-12-17T23:00:05.712582804Z 67 PC: 9fa4c | Get or set file attributes
2018-12-17T23:00:05.71868241Z 67 PC: 9fb1b | Get or set file attributes
2018-12-17T23:00:05.725493186Z 75 PC: 12af4 | Execute program
2018-12-17T23:00:05.732574106Z 67 PC: 9fa4c | Get or set file attributes
2018-12-17T23:00:05.743019255Z 67 PC: 9fa5c | Get or set file attributes
2018-12-17T23:00:06.091047283Z 61 PC: 9fa66 | Open file (Filename = 'C:\DOS\QBASIC.EXE')
2018-12-17T23:00:06.099205502Z 87 PC: 9fa74 | Get or set file date and time
2018-12-17T23:00:06.100784209Z 63 PC: 9fa80 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:00:06.108967356Z 87 PC: 9fb0f | Get or set file date and time
2018-12-17T23:00:06.112316571Z 62 PC: 9fb13 | Close file
2018-12-17T23:00:06.119821417Z 67 PC: 9fb1b | Get or set file attributes
2018-12-17T23:00:06.130589963Z 75 PC: 12af4 | Execute program
2018-12-17T23:00:06.242430078Z 48 PC: 38db4 | Get DOS version
2018-12-17T23:00:06.244569339Z 74 PC: 38e04 | Reallocate memory
2018-12-17T23:00:06.246924094Z 48 PC: 38e68 | Get DOS version
2018-12-17T23:00:06.251756444Z 53 PC: 38e70 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:06.255178859Z 37 PC: 38e82 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:06.256485023Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:06.258917561Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:06.260536031Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:06.262061283Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:06.263832377Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:06.264886538Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:06.266009211Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:06.267333655Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:06.270341011Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:06.27186182Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:06.273167815Z 53 PC: 3fb6f | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:00:06.276199026Z 37 PC: 3fb9e | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:06.277631099Z 37 PC: 3fb9e | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:06.278607231Z 37 PC: 3fb9e | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:06.280127722Z 37 PC: 3fb9e | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:06.281267077Z 37 PC: 3fb9e | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:06.282177045Z 37 PC: 3fb9e | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:06.283773348Z 37 PC: 3fb9e | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:06.284976768Z 37 PC: 3fb9e | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:06.285944912Z 37 PC: 3fba5 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:06.287447182Z 37 PC: 3fbaa | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:06.289497425Z 68 PC: 38f13 | I/O control for devices (Set for = '��r��R')
2018-12-17T23:00:06.291466995Z 68 PC: 38f13 | I/O control for devices (Set for = '@�')
2018-12-17T23:00:06.293794433Z 68 PC: 38f13 | I/O control for devices (Set for = 'B�N;�tC��vb�F u\� �W� ��� ')
2018-12-17T23:00:06.295431086Z 68 PC: 38f13 | I/O control for devices (Set for = '� �W� ��� ')
2018-12-17T23:00:06.297248602Z 68 PC: 38f13 | I/O control for devices (Set for = '� �W� ��� ')
2018-12-17T23:00:06.301054803Z 53 PC: 29ea3 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:06.302382207Z 37 PC: 29eb5 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:06.303591869Z 53 PC: 2f8ee | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:06.304772356Z 53 PC: 2f8fb | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:00:06.307058375Z 53 PC: 2f908 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:06.308509829Z 37 PC: 2f91d | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:06.309801356Z 37 PC: 2f925 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:00:06.31191087Z 37 PC: 2f92d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:06.313004472Z 53 PC: 33650 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T23:00:06.313940443Z 53 PC: 3365d | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T23:00:06.31561996Z 53 PC: 3366c | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:00:06.316723967Z 37 PC: 33679 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T23:00:06.317770244Z 53 PC: 33680 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:00:06.320068993Z 37 PC: 3368d | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T23:00:06.321325725Z 53 PC: 33699 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:00:06.327282913Z 48 PC: 3375e | Get DOS version
2018-12-17T23:00:06.329169491Z 74 PC: 3440b | Reallocate memory
2018-12-17T23:00:06.333494905Z 74 PC: 3440b | Reallocate memory
2018-12-17T23:00:06.335070575Z 68 PC: 33565 | I/O control for devices (Set for = 'pt������n~�:4*P')
2018-12-17T23:00:06.336528504Z 68 PC: 33565 | I/O control for devices (Set for = '')
2018-12-17T23:00:06.339649296Z 51 PC: 33583 | Get or set Ctrl-Break
2018-12-17T23:00:06.341191662Z 51 PC: 3358f | Get or set Ctrl-Break
2018-12-17T23:00:06.342804375Z 72 PC: 33bc6 | Allocate memory
2018-12-17T23:00:06.346543964Z 74 PC: 3440b | Reallocate memory
2018-12-17T23:00:06.34845383Z 72 PC: 33bc6 | Allocate memory
2018-12-17T23:00:06.350342224Z 37 PC: 2ef71 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:00:06.367495298Z 48 PC: 23cdf | Get DOS version
2018-12-17T23:00:06.369221508Z 61 PC: 23aec | Open file (Filename = 'C:\DOS\qbasic.ini')
2018-12-17T23:00:06.379945847Z 63 PC: 23aec | Read file or device (Read 120 bytes on handle 5)
2018-12-17T23:00:06.388397286Z 63 PC: 23aec | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:00:06.394129265Z 63 PC: 23aec | Read file or device (Read 1 bytes on handle 5)
2018-12-17T23:00:06.397264037Z 63 PC: 23aec | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:00:06.400348305Z 63 PC: 23aec | Read file or device (Read 1 bytes on handle 5)
2018-12-17T23:00:06.403994056Z 63 PC: 23aec | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:00:06.407027899Z 63 PC: 23aec | Read file or device (Read 1 bytes on handle 5)
2018-12-17T23:00:06.410134797Z 63 PC: 23aec | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:00:06.413800881Z 63 PC: 23aec | Read file or device (Read 1 bytes on handle 5)
2018-12-17T23:00:06.416732928Z 62 PC: 23aec | Close file
2018-12-17T23:00:06.418815619Z 53 PC: 2f1fa | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T23:00:06.421327248Z 37 PC: 2f207 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:00:06.42742378Z 53 PC: 4c428 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T23:00:06.428673767Z 37 PC: 4c434 | Set interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T23:00:06.434692698Z 53 PC: 41ea5 | Get interrupt vector (Interrupt = '51' AKA 'Get or set Ctrl-Break')
2018-12-17T23:00:06.441707466Z 37 PC: 2ef71 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:00:06.443796057Z 53 PC: 2f1fa | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T23:00:06.445723527Z 37 PC: 2f207 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:00:06.448052903Z 53 PC: 41ea5 | Get interrupt vector (Interrupt = '51' AKA 'Get or set Ctrl-Break')
2018-12-17T23:00:06.450080373Z 53 PC: 4cd19 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:06.451663707Z 37 PC: 4cd2c | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:06.45355362Z 53 PC: 4cd19 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:00:06.454870724Z 37 PC: 4cd2c | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:00:06.456092672Z 53 PC: 4cd19 | Get interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-17T23:00:06.462701697Z 37 PC: 4cd2c | Set interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-17T23:00:06.46408251Z 53 PC: 4cd19 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:00:06.465505949Z 37 PC: 4cd2c | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:00:06.466867671Z 48 PC: 4ccda | Get DOS version
2018-12-17T23:00:06.468108922Z 53 PC: 4ccf8 | Get interrupt vector (Interrupt = '21' AKA 'Sequential write')
2018-12-17T23:00:06.469206641Z 37 PC: 4cd0d | Set interrupt vector (Interrupt = '21' AKA 'Sequential write')