Sample viewer

vx.netlux.org/Virus.DOS.BerlinHQ.434

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:01:06.694895083Z 78 PC: 22b55 | Find first file
2018-12-17T23:01:06.703613473Z 47 PC: 22b5b | Get disk transfer address
2018-12-17T23:01:06.705168385Z 61 PC: 22b77 | Open file (Filename = 'C:\DOS\EDIT.COM')
2018-12-17T23:01:06.711615173Z 63 PC: 22b85 | Read file or device (Read 434 bytes on handle 5)
2018-12-17T23:01:06.722133239Z 62 PC: 22b90 | Close file
2018-12-17T23:01:06.724639822Z 79 PC: 22b55 | Find next file
2018-12-17T23:01:06.728334966Z 47 PC: 22b5b | Get disk transfer address
2018-12-17T23:01:06.738473318Z 61 PC: 22b77 | Open file (Filename = 'C:\DOS\FORMAT.COM')
2018-12-17T23:01:06.746015826Z 63 PC: 22b85 | Read file or device (Read 434 bytes on handle 5)
2018-12-17T23:01:06.752010712Z 66 PC: 22bb9 | Move file pointer
2018-12-17T23:01:06.75392316Z 64 PC: 22bd3 | Write file or device (Write 434 bytes on handle 5)
2018-12-17T23:01:07.112872877Z 66 PC: 22be1 | Move file pointer
2018-12-17T23:01:07.114827281Z 64 PC: 22beb | Write file or device (Write 434 bytes on handle 5)
2018-12-17T23:01:07.118165788Z 62 PC: 22bef | Close file
2018-12-17T23:01:07.126927396Z 76 PC: 12a47 | Terminate with return code (Return code = '0')