Sample viewer

vx.netlux.org/Virus.DOS.T_Power.Zarma.2322.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:31.410127496Z 53 PC: 134b6 | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T23:02:31.412536699Z 53 PC: 134b6 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:02:31.414156598Z 74 PC: 12e8e | Reallocate memory
2018-12-17T23:02:31.415763346Z 88 PC: 12e96 | case 0xGet or set allocation strateg:
2018-12-17T23:02:31.417241918Z 72 PC: 12ea3 | Allocate memory
2018-12-17T23:02:31.420037798Z 53 PC: 134b6 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:02:31.421292403Z 53 PC: 134b6 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:02:31.42253899Z 37 PC: 134bb | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:02:31.424318815Z 37 PC: 134bb | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:02:31.425556088Z 74 PC: 12f1b | Reallocate memory
2018-12-17T23:02:31.427120485Z 88 PC: 12f25 | case 0xGet or set allocation strateg:
2018-12-17T23:02:31.4296706Z 250 PC: 12f3d | UNKNOWN!
2018-12-17T23:02:31.430574144Z 47 PC: 12f41 | Get disk transfer address
2018-12-17T23:02:31.431763808Z 26 PC: 12f51 | Set disk transfer address
2018-12-17T23:02:31.434048922Z 71 PC: 12f5b | Get current directory
2018-12-17T23:02:31.437217026Z 53 PC: 134b6 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:31.438721722Z 37 PC: 134bb | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:31.441059454Z 88 PC: 9eb9c | case 0xGet or set allocation strateg:
2018-12-17T23:02:31.442730722Z 250 PC: 9ebb4 | UNKNOWN!
2018-12-17T23:02:31.44377974Z 47 PC: 9ebb8 | Get disk transfer address
2018-12-17T23:02:31.4458066Z 26 PC: 9ebc8 | Set disk transfer address
2018-12-17T23:02:31.447764813Z 71 PC: 9ebd2 | Get current directory
2018-12-17T23:02:31.450699487Z 53 PC: 9f12d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:31.451941434Z 37 PC: 9f132 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:31.454205245Z 67 PC: 9f140 | Get or set file attributes
2018-12-17T23:02:31.794499185Z 61 PC: 9ec38 | Open file (Filename = '')
2018-12-17T23:02:31.80096478Z 87 PC: 9ecbb | Get or set file date and time
2018-12-17T23:02:31.803970831Z 63 PC: 9f11e | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:02:31.806851445Z 66 PC: 9f10c | Move file pointer
2018-12-17T23:02:31.80830343Z 66 PC: 9f10c | Move file pointer
2018-12-17T23:02:31.812737135Z 64 PC: 9f0b0 | Write file or device (Write 2322 bytes on handle 5)
2018-12-17T23:02:31.818950699Z 66 PC: 9ed0c | Move file pointer
2018-12-17T23:02:31.820194647Z 64 PC: 9f115 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:02:31.822708896Z 78 PC: 9ee51 | Find first file
2018-12-17T23:02:31.826438546Z 78 PC: 9ee51 | Find first file
2018-12-17T23:02:31.830011113Z 78 PC: 9ee51 | Find first file
2018-12-17T23:02:31.834266653Z 78 PC: 9ee51 | Find first file
2018-12-17T23:02:31.837865462Z 78 PC: 9ee51 | Find first file
2018-12-17T23:02:31.841424544Z 78 PC: 9ee51 | Find first file
2018-12-17T23:02:31.845575366Z 78 PC: 9ee51 | Find first file
2018-12-17T23:02:31.849169532Z 87 PC: 9ee72 | Get or set file date and time
2018-12-17T23:02:31.850200689Z 87 PC: 9ee80 | Get or set file date and time
2018-12-17T23:02:31.851889878Z 62 PC: 9ee88 | Close file
2018-12-17T23:02:31.856692842Z 59 PC: 9f137 | Change current directory
2018-12-17T23:02:31.859815832Z 59 PC: 9f137 | Change current directory
2018-12-17T23:02:31.861271253Z 37 PC: 9f132 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:31.862893966Z 26 PC: 9eeb8 | Set disk transfer address
2018-12-17T23:02:31.864124879Z 61 PC: 12fab | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T23:02:31.87133925Z 62 PC: 12fb0 | Close file
2018-12-17T23:02:31.873810469Z 59 PC: 134c0 | Change current directory
2018-12-17T23:02:31.877816028Z 59 PC: 134c0 | Change current directory
2018-12-17T23:02:31.880518563Z 37 PC: 134bb | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:31.882306068Z 26 PC: 13241 | Set disk transfer address
2018-12-17T23:02:31.883535989Z 9 PC: 12b40 | Display string (Could not find end pointer)
2018-12-17T23:02:31.88769609Z 76 PC: 12b44 | Terminate with return code (Return code = '36')