Sample viewer

vx.netlux.org/Virus.DOS.Muhamor.4608

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:05.089152014Z 74 PC: 1329a | Reallocate memory
2018-12-17T23:04:05.104375914Z 37 PC: 132f1 | Set interrupt vector (Interrupt = '18' AKA 'Find next file')
2018-12-17T23:04:05.106156948Z 37 PC: 132f9 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:05.108645852Z 86 PC: 12ccb | Rename file
2018-12-17T23:04:05.136192273Z 67 PC: 12d35 | Get or set file attributes
2018-12-17T23:04:05.143361298Z 67 PC: 12d41 | Get or set file attributes
2018-12-17T23:04:05.155180251Z 61 PC: 12d4a | Open file (Filename = 'A:\TEST.EX~')
2018-12-17T23:04:05.163227589Z 63 PC: 12d5e | Read file or device (Read 28 bytes on handle 5)
2018-12-17T23:04:05.171728048Z 66 PC: 12ddc | Move file pointer
2018-12-17T23:04:05.173124064Z 62 PC: 130ac | Close file
2018-12-17T23:04:05.174829583Z 86 PC: 130c2 | Rename file
2018-12-17T23:04:05.18681657Z 75 PC: 1334b | Execute program
2018-12-17T23:04:06.113464363Z 53 PC: 15af2 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:04:06.11552934Z 53 PC: 15af2 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:04:06.118933123Z 53 PC: 15af2 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:04:06.120748474Z 53 PC: 15af2 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:06.122606005Z 53 PC: 15af2 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:04:06.125047714Z 53 PC: 15af2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:06.139174635Z 53 PC: 15af2 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:04:06.141000738Z 53 PC: 15af2 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:04:06.14300676Z 53 PC: 15af2 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:04:06.145175727Z 53 PC: 15af2 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:04:06.147019438Z 53 PC: 15af2 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:04:06.148855849Z 53 PC: 15af2 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:04:06.151597326Z 53 PC: 15af2 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:04:06.153198831Z 53 PC: 15af2 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:04:06.154836382Z 53 PC: 15af2 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:04:06.156988657Z 53 PC: 15af2 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:04:06.158545801Z 53 PC: 15af2 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:04:06.160236Z 53 PC: 15af2 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:04:06.163436898Z 53 PC: 15af2 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:04:06.165956913Z 37 PC: 15b07 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:04:06.16845995Z 37 PC: 15b0f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:04:06.17018939Z 37 PC: 15b17 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:06.171839073Z 37 PC: 15b1f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:04:06.17376245Z 68 PC: 15e8f | I/O control for devices (Set for = '')
2018-12-17T23:04:06.241879603Z 37 PC: 15515 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:04:06.244737052Z 25 PC: 16526 | Get default drive
2018-12-17T23:04:06.246502646Z 71 PC: 16539 | Get current directory
2018-12-17T23:04:06.250382145Z 59 PC: 165ed | Change current directory
2018-12-17T23:04:06.257872333Z 14 PC: 1657f | Set default drive (Drive = 'A')
2018-12-17T23:04:06.259674221Z 25 PC: 16583 | Get default drive
2018-12-17T23:04:06.261271141Z 59 PC: 165ed | Change current directory
2018-12-17T23:04:06.487771366Z 37 PC: 15c06 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:04:06.489616456Z 37 PC: 15c06 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:04:06.49142486Z 37 PC: 15c06 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:04:06.494089264Z 37 PC: 15c06 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:06.496118281Z 37 PC: 15c06 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:04:06.497830927Z 37 PC: 15c06 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:06.500295603Z 37 PC: 15c06 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:04:06.502317031Z 37 PC: 15c06 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:04:06.504035102Z 37 PC: 15c06 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:04:06.505755641Z 37 PC: 15c06 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:04:06.508216582Z 37 PC: 15c06 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:04:06.509761006Z 37 PC: 15c06 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:04:06.511471612Z 37 PC: 15c06 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:04:06.514192236Z 37 PC: 15c06 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:04:06.515591022Z 37 PC: 15c06 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:04:06.516942843Z 37 PC: 15c06 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:04:06.519149587Z 37 PC: 15c06 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:04:06.520816697Z 37 PC: 15c06 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:04:06.522551745Z 37 PC: 15c06 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:04:06.52479375Z 76 PC: 15c45 | Terminate with return code (Return code = '0')
2018-12-17T23:04:06.528515787Z 49 PC: 13372 | Terminate and stay resident (Return code = '0' | Memory size = '640')