Sample viewer

vx.netlux.org/Virus.DOS.Vienna.Bloodspill.666

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:07:08.579502106Z 53 PC: 1522f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:07:08.582210738Z 37 PC: 1523c | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:07:08.584051799Z 47 PC: 1516c | Get disk transfer address
2018-12-17T23:07:08.585690189Z 26 PC: 1517a | Set disk transfer address
2018-12-17T23:07:08.587276651Z 78 PC: 152d4 | Find first file
2018-12-17T23:07:08.594892498Z 79 PC: 152da | Find next file
2018-12-17T23:07:08.601763305Z 79 PC: 152da | Find next file
2018-12-17T23:07:08.604908137Z 79 PC: 152da | Find next file
2018-12-17T23:07:08.611339887Z 79 PC: 152da | Find next file
2018-12-17T23:07:08.614599255Z 79 PC: 152da | Find next file
2018-12-17T23:07:08.617410459Z 79 PC: 152da | Find next file
2018-12-17T23:07:08.622977354Z 79 PC: 152da | Find next file
2018-12-17T23:07:08.627031185Z 67 PC: 1530b | Get or set file attributes
2018-12-17T23:07:08.633322993Z 67 PC: 15319 | Get or set file attributes
2018-12-17T23:07:08.651742569Z 61 PC: 15321 | Open file (Filename = 'TEST.COM')
2018-12-17T23:07:08.658894134Z 87 PC: 1532d | Get or set file date and time
2018-12-17T23:07:08.660404062Z 63 PC: 1533d | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:07:08.663742418Z 66 PC: 1534d | Move file pointer
2018-12-17T23:07:08.665522113Z 64 PC: 15370 | Write file or device (Write 666 bytes on handle 5)
2018-12-17T23:07:08.675001203Z 66 PC: 1537b | Move file pointer
2018-12-17T23:07:08.677862382Z 64 PC: 15391 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:07:08.682178074Z 87 PC: 153a2 | Get or set file date and time
2018-12-17T23:07:08.684131657Z 62 PC: 153a6 | Close file
2018-12-17T23:07:08.693238456Z 67 PC: 153b1 | Get or set file attributes
2018-12-17T23:07:08.705391062Z 26 PC: 1519f | Set disk transfer address
2018-12-17T23:07:08.707112147Z 37 PC: 15251 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')