Sample viewer

vx.netlux.org/Virus.DOS.Kaszana.1992

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:03:00.149112406Z 26 PC: 13227 | Set disk transfer address
2018-12-17T22:03:00.150979343Z 53 PC: 1322d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:03:00.15236773Z 37 PC: 1323b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:03:00.153777517Z 37 PC: 13242 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:03:00.158955317Z 78 PC: 132ed | Find first file
2018-12-17T22:03:00.165045986Z 79 PC: 13301 | Find next file
2018-12-17T22:03:00.167780382Z 79 PC: 13301 | Find next file
2018-12-17T22:03:00.172176891Z 79 PC: 13301 | Find next file
2018-12-17T22:03:00.176463662Z 79 PC: 13301 | Find next file
2018-12-17T22:03:00.179576295Z 79 PC: 13301 | Find next file
2018-12-17T22:03:00.18283408Z 79 PC: 13301 | Find next file
2018-12-17T22:03:00.185484727Z 79 PC: 13301 | Find next file
2018-12-17T22:03:00.188343908Z 67 PC: 13332 | Get or set file attributes
2018-12-17T22:03:00.210832109Z 61 PC: 13339 | Open file (Filename = 'TEST.COM')
2018-12-17T22:03:00.218429637Z 63 PC: 1334a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:03:00.221304999Z 66 PC: 13355 | Move file pointer
2018-12-17T22:03:00.223558036Z 64 PC: 134b2 | Write file or device (Write 996 bytes on handle 5)
2018-12-17T22:03:00.233235497Z 66 PC: 13503 | Move file pointer
2018-12-17T22:03:00.234502348Z 63 PC: 13510 | Read file or device (Read 996 bytes on handle 5)
2018-12-17T22:03:00.241946354Z 66 PC: 13523 | Move file pointer
2018-12-17T22:03:00.24414444Z 64 PC: 1352d | Write file or device (Write 996 bytes on handle 5)
2018-12-17T22:03:00.253036178Z 66 PC: 13540 | Move file pointer
2018-12-17T22:03:00.254377126Z 64 PC: 13551 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:03:00.257675071Z 87 PC: 1337f | Get or set file date and time
2018-12-17T22:03:00.259408212Z 62 PC: 1338a | Close file
2018-12-17T22:03:00.26714476Z 67 PC: 13399 | Get or set file attributes
2018-12-17T22:03:00.277933752Z 78 PC: 132ed | Find first file
2018-12-17T22:03:00.287346296Z 79 PC: 13301 | Find next file
2018-12-17T22:03:00.290501463Z 67 PC: 13332 | Get or set file attributes
2018-12-17T22:03:00.625038928Z 61 PC: 13339 | Open file (Filename = 'C:\DOS\FORMAT.COM')
2018-12-17T22:03:00.632391415Z 63 PC: 1334a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:03:00.638223416Z 66 PC: 13355 | Move file pointer
2018-12-17T22:03:00.722920064Z 64 PC: 134b2 | Write file or device (Write 996 bytes on handle 5)
2018-12-17T22:03:00.731094372Z 66 PC: 13503 | Move file pointer
2018-12-17T22:03:00.732816797Z 63 PC: 13510 | Read file or device (Read 996 bytes on handle 5)
2018-12-17T22:03:00.740826026Z 66 PC: 13523 | Move file pointer
2018-12-17T22:03:00.742754651Z 64 PC: 1352d | Write file or device (Write 996 bytes on handle 5)
2018-12-17T22:03:00.752316845Z 66 PC: 13540 | Move file pointer
2018-12-17T22:03:00.753991646Z 64 PC: 13551 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:03:00.758134366Z 87 PC: 1337f | Get or set file date and time
2018-12-17T22:03:00.759888763Z 62 PC: 1338a | Close file
2018-12-17T22:03:00.766891672Z 67 PC: 13399 | Get or set file attributes
2018-12-17T22:03:00.777293925Z 26 PC: 133a9 | Set disk transfer address
2018-12-17T22:03:00.778450525Z 37 PC: 133b5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:03:00.779888818Z 9 PC: 12e26 | Display string (String= 'Hello - This is a 1000 COM test file, 1993 ')