Sample viewer

vx.netlux.org/Virus.DOS.Ash.708

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:00:37.037375726Z 26 PC: 14133 | Set disk transfer address
2018-12-17T23:00:37.039925918Z 86 PC: 1415a | Rename file
2018-12-17T23:00:37.48779844Z 60 PC: 14163 | Create or truncate file
2018-12-17T23:00:37.501279162Z 64 PC: 14172 | Write file or device (Write 8 bytes on handle 5)
2018-12-17T23:00:37.510336833Z 62 PC: 14176 | Close file
2018-12-17T23:00:37.519414391Z 61 PC: 1417f | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T23:00:37.526403315Z 63 PC: 141f7 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:00:37.529589572Z 66 PC: 1420e | Move file pointer
2018-12-17T23:00:37.53194622Z 64 PC: 14227 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:00:37.535143408Z 64 PC: 14109 | Write file or device (Write 704 bytes on handle 5)
2018-12-17T23:00:37.542171445Z 66 PC: 1426a | Move file pointer
2018-12-17T23:00:37.544338087Z 64 PC: 14288 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:00:37.55041186Z 62 PC: 141b9 | Close file
2018-12-17T23:00:37.55803225Z 78 PC: 141cc | Find first file
2018-12-17T23:00:37.564953186Z 61 PC: 141e8 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:00:37.571956947Z 63 PC: 141f7 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:00:37.57872242Z 66 PC: 1420e | Move file pointer
2018-12-17T23:00:37.580775398Z 64 PC: 14227 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:00:37.584852589Z 64 PC: 14109 | Write file or device (Write 704 bytes on handle 5)
2018-12-17T23:00:37.602707792Z 66 PC: 1426a | Move file pointer
2018-12-17T23:00:37.604332345Z 64 PC: 14288 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:00:37.611606905Z 62 PC: 141b9 | Close file
2018-12-17T23:00:37.62037927Z 79 PC: 141cc | Find next file
2018-12-17T23:00:37.623512708Z 61 PC: 141e8 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:00:37.631145351Z 63 PC: 141f7 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:00:37.647663982Z 66 PC: 1420e | Move file pointer
2018-12-17T23:00:37.649184309Z 64 PC: 14227 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:00:37.652968039Z 64 PC: 14109 | Write file or device (Write 704 bytes on handle 5)
2018-12-17T23:00:37.669800971Z 66 PC: 1426a | Move file pointer
2018-12-17T23:00:37.671982019Z 64 PC: 14288 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:00:37.680112147Z 53 PC: 1430e | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:00:37.681548205Z 37 PC: 1431f | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:00:37.683266294Z 9 PC: 14327 | Display string (Could not find end pointer)
2018-12-17T23:00:37.689022882Z 49 PC: 1432a | Terminate and stay resident (Return code = '0' | Memory size = '423')