Sample viewer

vx.netlux.org/Virus.DOS.A_morph.367.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:07:59.049150916Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T23:07:59.055814088Z 37 PC: 12a97 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:07:59.057010848Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:59.058164567Z 78 PC: 12a8f | Find first file
2018-12-17T23:07:59.064369473Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:59.066290274Z 61 PC: 12a8f | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:07:59.072853681Z 53 PC: 12a8f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:59.074227652Z 37 PC: 12b6e | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:59.07542938Z 64 PC: 12b7e | Write file or device (Write 367 bytes on handle 5)
2018-12-17T23:07:59.081799876Z 62 PC: 12a8f | Close file
2018-12-17T23:07:59.096423087Z 79 PC: 12a8f | Find next file
2018-12-17T23:07:59.099780367Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:59.100974574Z 61 PC: 12a8f | Open file (Filename = 'PRINT.COM')
2018-12-17T23:07:59.108521545Z 53 PC: 12a8f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:59.110373474Z 37 PC: 12b6e | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:59.111611951Z 64 PC: 12b7e | Write file or device (Write 367 bytes on handle 5)
2018-12-17T23:07:59.11830964Z 62 PC: 12a8f | Close file
2018-12-17T23:07:59.126780279Z 79 PC: 12a8f | Find next file
2018-12-17T23:07:59.129314986Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:59.130431712Z 61 PC: 12a8f | Open file (Filename = 'HELLO.COM')
2018-12-17T23:07:59.137325095Z 53 PC: 12a8f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:59.138566052Z 37 PC: 12b6e | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:59.139764053Z 64 PC: 12b7e | Write file or device (Write 367 bytes on handle 5)
2018-12-17T23:07:59.147035243Z 62 PC: 12a8f | Close file
2018-12-17T23:07:59.154603559Z 79 PC: 12a8f | Find next file
2018-12-17T23:07:59.15707186Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:59.158768696Z 61 PC: 12a8f | Open file (Filename = 'PHANG.COM')
2018-12-17T23:07:59.165168343Z 53 PC: 12a8f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:59.166195233Z 37 PC: 12b6e | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:59.167990421Z 64 PC: 12b7e | Write file or device (Write 367 bytes on handle 5)
2018-12-17T23:07:59.174475857Z 62 PC: 12a8f | Close file
2018-12-17T23:07:59.181986975Z 79 PC: 12a8f | Find next file
2018-12-17T23:07:59.185235526Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:59.186408723Z 61 PC: 12a8f | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:07:59.193499718Z 53 PC: 12a8f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:59.194992422Z 37 PC: 12b6e | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:59.196349955Z 64 PC: 12b7e | Write file or device (Write 367 bytes on handle 5)
2018-12-17T23:07:59.202665204Z 62 PC: 12a8f | Close file
2018-12-17T23:07:59.210291892Z 79 PC: 12a8f | Find next file
2018-12-17T23:07:59.212773463Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:59.213861653Z 61 PC: 12a8f | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:07:59.220205971Z 53 PC: 12a8f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:59.221337429Z 37 PC: 12b6e | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:59.222260437Z 64 PC: 12b7e | Write file or device (Write 367 bytes on handle 5)
2018-12-17T23:07:59.228407982Z 62 PC: 12a8f | Close file
2018-12-17T23:07:59.235882909Z 79 PC: 12a8f | Find next file
2018-12-17T23:07:59.238357997Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:59.239630949Z 61 PC: 12a8f | Open file (Filename = 'PAH.COM')
2018-12-17T23:07:59.246327613Z 53 PC: 12a8f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:59.247350074Z 37 PC: 12b6e | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:59.248328458Z 64 PC: 12b7e | Write file or device (Write 367 bytes on handle 5)
2018-12-17T23:07:59.255700576Z 62 PC: 12a8f | Close file
2018-12-17T23:07:59.263550321Z 79 PC: 12a8f | Find next file
2018-12-17T23:07:59.26624637Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:59.268365025Z 61 PC: 12a8f | Open file (Filename = 'TEST.COM')
2018-12-17T23:07:59.275482018Z 53 PC: 12a8f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:59.276764852Z 37 PC: 12b6e | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:59.278645255Z 64 PC: 12b7e | Write file or device (Write 367 bytes on handle 5)
2018-12-17T23:07:59.281545606Z 62 PC: 12a8f | Close file
2018-12-17T23:07:59.289341413Z 79 PC: 12a8f | Find next file
2018-12-17T23:07:59.292458442Z 37 PC: 12a8f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')