Sample viewer

vx.netlux.org/Virus.DOS.Sandworm.1503

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:07:56.896176357Z 47 PC: 12da2 | Get disk transfer address
2018-12-17T23:07:56.8974655Z 26 PC: 12db3 | Set disk transfer address
2018-12-17T23:07:56.899661829Z 9 PC: 12dbc | Display string (String= 'Wormsign ! ')
2018-12-17T23:07:56.904057752Z 25 PC: 12dec | Get default drive
2018-12-17T23:07:56.905811018Z 78 PC: 12e01 | Find first file
2018-12-17T23:07:56.919086932Z 79 PC: 13003 | Find next file
2018-12-17T23:07:56.921906592Z 79 PC: 13003 | Find next file
2018-12-17T23:07:56.924669596Z 79 PC: 13003 | Find next file
2018-12-17T23:07:56.928513331Z 79 PC: 13003 | Find next file
2018-12-17T23:07:56.931327972Z 79 PC: 13003 | Find next file
2018-12-17T23:07:56.934294678Z 79 PC: 13003 | Find next file
2018-12-17T23:07:56.937885788Z 79 PC: 13003 | Find next file
2018-12-17T23:07:56.940661316Z 67 PC: 12e27 | Get or set file attributes
2018-12-17T23:07:56.946736635Z 67 PC: 12e32 | Get or set file attributes
2018-12-17T23:07:56.974641648Z 61 PC: 12e3c | Open file (Filename = 'TEST.COM')
2018-12-17T23:07:56.983088295Z 82 PC: 12e49 | Get DOS internal pointers (SYSVARS)
2018-12-17T23:07:56.9850168Z 63 PC: 12e65 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:07:56.989033901Z 62 PC: 12fe9 | Close file
2018-12-17T23:07:56.991482714Z 67 PC: 12ff7 | Get or set file attributes
2018-12-17T23:07:57.002739273Z 79 PC: 13003 | Find next file
2018-12-17T23:07:57.00572785Z 14 PC: 13029 | Set default drive (Drive = 'A')
2018-12-17T23:07:57.008663989Z 26 PC: 13038 | Set disk transfer address