Sample viewer

vx.netlux.org/Virus.DOS.Haldeman.614

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:54.332195043Z 26 PC: 12a61 | Set disk transfer address
2018-12-17T23:06:54.334571157Z 37 PC: 12a6c | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:06:54.33685935Z 37 PC: 12a70 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T23:06:54.338641417Z 78 PC: 12ab7 | Find first file
2018-12-17T23:06:54.34552383Z 61 PC: 12c57 | Open file (Filename = 'As')
2018-12-17T23:06:54.353000264Z 79 PC: 12ab7 | Find next file
2018-12-17T23:06:54.355754478Z 61 PC: 12c57 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:06:54.363365679Z 63 PC: 12c66 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:06:54.371718968Z 66 PC: 12c75 | Move file pointer
2018-12-17T23:06:54.373399611Z 66 PC: 12c84 | Move file pointer
2018-12-17T23:06:54.377305159Z 64 PC: 12c90 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:06:54.384030647Z 66 PC: 12c9c | Move file pointer
2018-12-17T23:06:54.38562649Z 64 PC: 12ca7 | Write file or device (Write 614 bytes on handle 5)
2018-12-17T23:06:54.401425353Z 62 PC: 12cab | Close file
2018-12-17T23:06:54.421021321Z 79 PC: 12ab7 | Find next file
2018-12-17T23:06:54.424189651Z 61 PC: 12c57 | Open file (Filename = 'PRINT.S')
2018-12-17T23:06:54.431297608Z 63 PC: 12c66 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:06:54.438576834Z 66 PC: 12c75 | Move file pointer
2018-12-17T23:06:54.440158305Z 66 PC: 12c84 | Move file pointer
2018-12-17T23:06:54.441510306Z 64 PC: 12c90 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:06:54.44430269Z 66 PC: 12c9c | Move file pointer
2018-12-17T23:06:54.446502727Z 64 PC: 12ca7 | Write file or device (Write 614 bytes on handle 5)
2018-12-17T23:06:54.455276354Z 62 PC: 12cab | Close file
2018-12-17T23:06:54.464141226Z 79 PC: 12ab7 | Find next file
2018-12-17T23:06:54.467341927Z 61 PC: 12c57 | Open file (Filename = 'Ap')
2018-12-17T23:06:54.474391621Z 79 PC: 12ab7 | Find next file
2018-12-17T23:06:54.47761268Z 61 PC: 12c57 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:06:54.487335922Z 63 PC: 12c66 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:06:54.494916042Z 66 PC: 12c75 | Move file pointer
2018-12-17T23:06:54.496609462Z 66 PC: 12c84 | Move file pointer
2018-12-17T23:06:54.499440528Z 64 PC: 12c90 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:06:54.502294366Z 66 PC: 12c9c | Move file pointer
2018-12-17T23:06:54.503710981Z 64 PC: 12ca7 | Write file or device (Write 614 bytes on handle 5)
2018-12-17T23:06:54.512941045Z 62 PC: 12cab | Close file
2018-12-17T23:06:54.521807704Z 79 PC: 12ab7 | Find next file
2018-12-17T23:06:54.524500995Z 61 PC: 12c57 | Open file (Filename = 'Ah')
2018-12-17T23:06:54.532038636Z 79 PC: 12ab7 | Find next file
2018-12-17T23:06:54.534980214Z 61 PC: 12c57 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:06:54.542161958Z 63 PC: 12c66 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:06:54.548972862Z 66 PC: 12c75 | Move file pointer
2018-12-17T23:06:54.551860643Z 66 PC: 12c84 | Move file pointer
2018-12-17T23:06:54.553210559Z 64 PC: 12c90 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:06:54.555962622Z 66 PC: 12c9c | Move file pointer
2018-12-17T23:06:54.55760748Z 64 PC: 12ca7 | Write file or device (Write 614 bytes on handle 5)
2018-12-17T23:06:54.566195465Z 62 PC: 12cab | Close file
2018-12-17T23:06:54.575273211Z 79 PC: 12ab7 | Find next file
2018-12-17T23:06:54.579993072Z 61 PC: 12c57 | Open file (Filename = 'Ap')
2018-12-17T23:06:54.586889902Z 79 PC: 12ab7 | Find next file
2018-12-17T23:06:54.589848972Z 61 PC: 12c57 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:06:54.602192263Z 63 PC: 12c66 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:06:54.609747292Z 66 PC: 12c75 | Move file pointer
2018-12-17T23:06:54.611972979Z 66 PC: 12c84 | Move file pointer
2018-12-17T23:06:54.614790631Z 64 PC: 12c90 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:06:54.617777175Z 66 PC: 12c9c | Move file pointer
2018-12-17T23:06:54.619276158Z 64 PC: 12ca7 | Write file or device (Write 614 bytes on handle 5)
2018-12-17T23:06:54.628910318Z 62 PC: 12cab | Close file
2018-12-17T23:06:54.638793498Z 79 PC: 12ab7 | Find next file
2018-12-17T23:06:54.641649546Z 61 PC: 12c57 | Open file (Filename = 'Bc')
2018-12-17T23:06:54.648346209Z 79 PC: 12ab7 | Find next file
2018-12-17T23:06:54.651095311Z 61 PC: 12c57 | Open file (Filename = 'p')
2018-12-17T23:06:54.655935575Z 79 PC: 12ab7 | Find next file
2018-12-17T23:06:54.659076273Z 61 PC: 12c57 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:06:54.667142112Z 63 PC: 12c66 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:06:54.674326143Z 66 PC: 12c75 | Move file pointer
2018-12-17T23:06:54.676108527Z 66 PC: 12c84 | Move file pointer
2018-12-17T23:06:54.678463728Z 64 PC: 12c90 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:06:54.681437222Z 66 PC: 12c9c | Move file pointer
2018-12-17T23:06:54.683083156Z 64 PC: 12ca7 | Write file or device (Write 614 bytes on handle 5)
2018-12-17T23:06:54.69304079Z 62 PC: 12cab | Close file
2018-12-17T23:06:54.703045105Z 79 PC: 12ab7 | Find next file
2018-12-17T23:06:54.706045522Z 61 PC: 12c57 | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:06:54.715112288Z 63 PC: 12c66 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:06:54.722907784Z 66 PC: 12c75 | Move file pointer
2018-12-17T23:06:54.724871194Z 66 PC: 12c84 | Move file pointer
2018-12-17T23:06:54.727615759Z 64 PC: 12c90 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:06:54.731453561Z 66 PC: 12c9c | Move file pointer
2018-12-17T23:06:54.733311213Z 64 PC: 12ca7 | Write file or device (Write 614 bytes on handle 5)
2018-12-17T23:06:54.743709591Z 62 PC: 12cab | Close file
2018-12-17T23:06:54.753937352Z 79 PC: 12ab7 | Find next file
2018-12-17T23:06:54.757009743Z 61 PC: 12c57 | Open file (Filename = 'PAH.COM')
2018-12-17T23:06:54.765021987Z 63 PC: 12c66 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:06:54.772947566Z 66 PC: 12c75 | Move file pointer
2018-12-17T23:06:54.774912349Z 66 PC: 12c84 | Move file pointer
2018-12-17T23:06:54.776804199Z 64 PC: 12c90 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:06:54.780619393Z 66 PC: 12c9c | Move file pointer
2018-12-17T23:06:54.782315418Z 64 PC: 12ca7 | Write file or device (Write 614 bytes on handle 5)
2018-12-17T23:06:54.79317302Z 62 PC: 12cab | Close file
2018-12-17T23:06:54.802846533Z 79 PC: 12ab7 | Find next file
2018-12-17T23:06:54.80620269Z 61 PC: 12c57 | Open file (Filename = 'TEST.COM')
2018-12-17T23:06:54.814055056Z 63 PC: 12c66 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:06:54.817469458Z 62 PC: 12cab | Close file
2018-12-17T23:06:54.819976605Z 79 PC: 12ab7 | Find next file
2018-12-17T23:06:54.82305373Z 59 PC: 12ac8 | Change current directory
2018-12-17T23:06:54.829080167Z 26 PC: 12ad1 | Set disk transfer address
2018-12-17T23:06:54.830375536Z 9 PC: 12ae3 | Display string (Could not find end pointer)