Sample viewer

vx.netlux.org/Virus.DOS.Bizarre.2716

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:07:36.891616183Z 48 PC: 12aaa | Get DOS version
2018-12-17T23:07:36.897348138Z 77 PC: 11fe0 | Get program return code
2018-12-17T23:07:36.899984203Z 72 PC: 12174 | Allocate memory
2018-12-17T23:07:36.902880557Z 72 PC: 1218d | Allocate memory
2018-12-17T23:07:36.9058769Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:07:36.91301659Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:07:36.916295695Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:07:36.920230391Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:36.929180986Z 62 PC: 122ab | Close file
2018-12-17T23:07:36.932355723Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:36.935976289Z 62 PC: 122ab | Close file
2018-12-17T23:07:36.939364378Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:36.942758769Z 62 PC: 122ab | Close file
2018-12-17T23:07:36.945992197Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:36.953699795Z 62 PC: 122ab | Close file
2018-12-17T23:07:36.956892747Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:36.960083665Z 62 PC: 122ab | Close file
2018-12-17T23:07:36.96351742Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:36.967351988Z 62 PC: 122ab | Close file
2018-12-17T23:07:36.970369991Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:36.973196505Z 62 PC: 122ab | Close file
2018-12-17T23:07:36.976361063Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:36.97938625Z 62 PC: 122ab | Close file
2018-12-17T23:07:36.982254011Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:36.986028686Z 62 PC: 122ab | Close file
2018-12-17T23:07:36.989526882Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:36.992806296Z 62 PC: 122ab | Close file
2018-12-17T23:07:36.996651855Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:36.999422143Z 62 PC: 122ab | Close file
2018-12-17T23:07:37.003368221Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:37.00588967Z 62 PC: 122ab | Close file
2018-12-17T23:07:37.009418834Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:37.012697317Z 62 PC: 122ab | Close file
2018-12-17T23:07:37.015252099Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:37.018560237Z 62 PC: 122ab | Close file
2018-12-17T23:07:37.021130599Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:37.023871481Z 62 PC: 122ab | Close file
2018-12-17T23:07:37.028819142Z 61 PC: 12354 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T23:07:37.038966406Z 66 PC: 12372 | Move file pointer
2018-12-17T23:07:37.041326843Z 66 PC: 9e88f | Move file pointer
2018-12-17T23:07:37.0446606Z 66 PC: 9e88f | Move file pointer
2018-12-17T23:07:37.052941125Z 63 PC: 9e88f | Read file or device (Read 8 bytes on handle 5)
2018-12-17T23:07:37.056380841Z 66 PC: 9e985 | Move file pointer
2018-12-17T23:07:37.059703538Z 66 PC: 9e88f | Move file pointer
2018-12-17T23:07:37.062091917Z 63 PC: 12383 | Read file or device (Read 44693 bytes on handle 5)
2018-12-17T23:07:37.077706959Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:37.080995972Z 66 PC: 9e88f | Move file pointer
2018-12-17T23:07:37.084535715Z 63 PC: 9e88f | Read file or device (Read 2716 bytes on handle 6)
2018-12-17T23:07:37.092335367Z 66 PC: 9e88f | Move file pointer
2018-12-17T23:07:37.095924554Z 66 PC: 9e88f | Move file pointer
2018-12-17T23:07:37.097985508Z 64 PC: 9e88f | Write file or device (Write 2716 bytes on handle 6)
2018-12-17T23:07:37.460256691Z 66 PC: 9e88f | Move file pointer
2018-12-17T23:07:37.463686157Z 64 PC: 9e88f | Write file or device (Write 2716 bytes on handle 6)
2018-12-17T23:07:37.474034189Z 62 PC: 9e88f | Close file
2018-12-17T23:07:37.486699397Z 62 PC: 1238a | Close file
2018-12-17T23:07:37.492838517Z 99 PC: 98977 | Get DBCS lead byte table pointer
2018-12-17T23:07:37.498908166Z 56 PC: 93199 | Get or set country info
2018-12-17T23:07:37.504129441Z 64 PC: 98be8 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:07:37.510042988Z 25 PC: 93202 | Get default drive
2018-12-17T23:07:37.513685795Z 71 PC: 9547d | Get current directory
2018-12-17T23:07:37.519182688Z 64 PC: 98be8 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T23:07:37.523683658Z 2 PC: 95452 | Character output (Char = '3e')
2018-12-17T23:07:37.527787663Z 93 PC: 932c0 | File sharing functions
2018-12-17T23:07:37.53055773Z 93 PC: 932c7 | File sharing functions
2018-12-17T23:07:37.533446059Z 10 PC: 932d9 | Buffered keyboard input
2018-12-17T23:07:51.839836315Z 0 PC: 0 | Program terminate
2018-12-17T23:07:53.195784377Z 0 PC: 0 | Program terminate
2018-12-17T23:07:53.299860649Z 64 PC: 98be8 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:07:53.307133079Z 41 PC: 9334e | Parse filename
2018-12-17T23:07:53.311003525Z 41 PC: 933cf | Parse filename
2018-12-17T23:07:53.313953991Z 41 PC: 933ec | Parse filename
2018-12-17T23:07:53.316611647Z 26 PC: 96897 | Set disk transfer address
2018-12-17T23:07:53.318856216Z 71 PC: 96a93 | Get current directory
2018-12-17T23:07:53.328295408Z 78 PC: 9e88f | Find first file
2018-12-17T23:07:53.338898228Z 47 PC: 9e88f | Get disk transfer address
2018-12-17T23:07:53.341139972Z 71 PC: 9690c | Get current directory
2018-12-17T23:07:53.344990971Z 73 PC: 95fa9 | Release memory
2018-12-17T23:07:53.347809379Z 61 PC: 9e88f | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T23:07:53.355170416Z 66 PC: 9e88f | Move file pointer
2018-12-17T23:07:53.356798887Z 63 PC: 9e88f | Read file or device (Read 2716 bytes on handle 5)
2018-12-17T23:07:53.36886136Z 62 PC: 9e88f | Close file
2018-12-17T23:07:53.371258035Z 75 PC: 11821 | Execute program
2018-12-17T23:07:53.382899808Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T23:07:53.388869881Z 76 PC: 12a4b | Terminate with return code (Return code = '36')
2018-12-17T23:07:53.393238372Z 77 PC: 11fe0 | Get program return code
2018-12-17T23:07:53.395059094Z 72 PC: 12174 | Allocate memory
2018-12-17T23:07:53.39864257Z 72 PC: 1218d | Allocate memory
2018-12-17T23:07:53.410475332Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:07:53.412388097Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:07:53.414902885Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:07:53.416662763Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:53.418610484Z 62 PC: 122ab | Close file
2018-12-17T23:07:53.420781996Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:53.423038157Z 62 PC: 122ab | Close file
2018-12-17T23:07:53.425067351Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:53.426911948Z 62 PC: 122ab | Close file
2018-12-17T23:07:53.430311337Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:53.433346162Z 62 PC: 122ab | Close file
2018-12-17T23:07:53.435677945Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:53.439073267Z 62 PC: 122ab | Close file
2018-12-17T23:07:53.441087964Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:53.442997965Z 62 PC: 122ab | Close file
2018-12-17T23:07:53.445838504Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:53.447849444Z 62 PC: 122ab | Close file
2018-12-17T23:07:53.449802626Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:53.452553136Z 62 PC: 122ab | Close file
2018-12-17T23:07:53.454536965Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:53.456446905Z 62 PC: 122ab | Close file
2018-12-17T23:07:53.459469176Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:53.461325435Z 62 PC: 122ab | Close file
2018-12-17T23:07:53.463274429Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:53.466362413Z 62 PC: 122ab | Close file
2018-12-17T23:07:53.468358084Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:53.470263375Z 62 PC: 122ab | Close file
2018-12-17T23:07:53.472233388Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:53.474826583Z 62 PC: 122ab | Close file
2018-12-17T23:07:53.477024254Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:53.479161602Z 62 PC: 122ab | Close file
2018-12-17T23:07:53.481838323Z 69 PC: 9e88f | Duplicate handle
2018-12-17T23:07:53.483621575Z 62 PC: 122ab | Close file
2018-12-17T23:07:53.489467454Z 99 PC: 98977 | Get DBCS lead byte table pointer
2018-12-17T23:07:53.491938859Z 56 PC: 93199 | Get or set country info
2018-12-17T23:07:53.494400066Z 64 PC: 98be8 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:07:53.499364888Z 25 PC: 93202 | Get default drive
2018-12-17T23:07:53.502121138Z 71 PC: 9547d | Get current directory
2018-12-17T23:07:53.506608754Z 64 PC: 98be8 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T23:07:53.512081Z 2 PC: 95452 | Character output (Char = '3e')
2018-12-17T23:07:53.515669155Z 93 PC: 932c0 | File sharing functions
2018-12-17T23:07:53.519864361Z 93 PC: 932c7 | File sharing functions
2018-12-17T23:07:53.522346687Z 10 PC: 932d9 | Buffered keyboard input