Sample viewer

vx.netlux.org/Virus.DOS.I13.Paraguay.2858

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:09:01.589422211Z 219 PC: 12ecf | UNKNOWN!
2018-12-17T23:09:01.590709149Z 205 PC: 12edb | UNKNOWN!
2018-12-17T23:09:01.592619476Z 53 PC: 12ee9 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:01.594761314Z 53 PC: 12f02 | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T23:09:01.596755438Z 74 PC: 12f57 | Reallocate memory
2018-12-17T23:09:01.599223103Z 72 PC: 12f5e | Allocate memory
2018-12-17T23:09:01.601894736Z 53 PC: 9e91a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:01.604076548Z 37 PC: 9e92e | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:01.60639423Z 250 PC: 9e938 | UNKNOWN!
2018-12-17T23:09:01.607563484Z 61 PC: 9e9d2 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T23:09:01.615016867Z 67 PC: 9e9ea | Get or set file attributes
2018-12-17T23:09:01.622534743Z 65 PC: 9e9f1 | Delete file (Filename = 'G�!3���݌�')
2018-12-17T23:09:01.629531197Z 65 PC: 9e9f8 | Delete file (Filename = '�')
2018-12-17T23:09:01.636513772Z 65 PC: 9e9ff | Delete file (Filename = '����.�����#')
2018-12-17T23:09:01.644313947Z 65 PC: 9ea06 | Delete file (Filename = '�#')
2018-12-17T23:09:01.650922375Z 87 PC: 9ea0f | Get or set file date and time
2018-12-17T23:09:01.653669997Z 63 PC: 9ea31 | Read file or device (Read 45 bytes on handle 5)
2018-12-17T23:09:01.657283837Z 48 PC: 9ea44 | Get DOS version
2018-12-17T23:09:01.660408885Z 66 PC: 9ef48 | Move file pointer
2018-12-17T23:09:01.663428299Z 64 PC: 9ea81 | Write file or device (Write 2858 bytes on handle 5)
2018-12-17T23:09:02.007746082Z 64 PC: 9ea97 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:09:02.011965678Z 87 PC: 9ef3f | Get or set file date and time
2018-12-17T23:09:02.013581515Z 62 PC: 9eb87 | Close file
2018-12-17T23:09:02.020040605Z 37 PC: 9eb97 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:02.022089776Z 250 PC: 9eba7 | UNKNOWN!
2018-12-17T23:09:02.023265809Z 86 PC: 13017 | Rename file