Sample viewer

vx.netlux.org/Virus.DOS.VCL_MUT.Empire.372

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:09:09.332297728Z 71 PC: 12a65 | Get current directory
2018-12-17T23:09:09.335780754Z 47 PC: 12a8d | Get disk transfer address
2018-12-17T23:09:09.33832175Z 26 PC: 12a9e | Set disk transfer address
2018-12-17T23:09:09.340061249Z 78 PC: 12aa6 | Find first file
2018-12-17T23:09:09.347138681Z 26 PC: 12ab8 | Set disk transfer address
2018-12-17T23:09:09.349286759Z 59 PC: 12a72 | Change current directory
2018-12-17T23:09:09.353821832Z 59 PC: 12a7b | Change current directory
2018-12-17T23:09:09.355829916Z 71 PC: 12a65 | Get current directory
2018-12-17T23:09:09.360438657Z 47 PC: 12a8d | Get disk transfer address
2018-12-17T23:09:09.364407397Z 26 PC: 12a9e | Set disk transfer address
2018-12-17T23:09:09.368976204Z 78 PC: 12aa6 | Find first file
2018-12-17T23:09:09.382901797Z 26 PC: 12ab8 | Set disk transfer address
2018-12-17T23:09:09.38589881Z 59 PC: 12a72 | Change current directory
2018-12-17T23:09:09.394324435Z 59 PC: 12a7b | Change current directory
2018-12-17T23:09:09.397558152Z 71 PC: 12a65 | Get current directory
2018-12-17T23:09:09.40094595Z 47 PC: 12a8d | Get disk transfer address
2018-12-17T23:09:09.402353836Z 26 PC: 12a9e | Set disk transfer address
2018-12-17T23:09:09.403702811Z 78 PC: 12aa6 | Find first file
2018-12-17T23:09:09.411208688Z 26 PC: 12ab8 | Set disk transfer address
2018-12-17T23:09:09.412935644Z 59 PC: 12a72 | Change current directory
2018-12-17T23:09:09.417906387Z 59 PC: 12a7b | Change current directory
2018-12-17T23:09:09.421060525Z 71 PC: 12a65 | Get current directory
2018-12-17T23:09:09.424421462Z 47 PC: 12a8d | Get disk transfer address
2018-12-17T23:09:09.425944745Z 26 PC: 12a9e | Set disk transfer address
2018-12-17T23:09:09.430911129Z 78 PC: 12aa6 | Find first file
2018-12-17T23:09:09.440995672Z 26 PC: 12ab8 | Set disk transfer address
2018-12-17T23:09:09.442579809Z 59 PC: 12a72 | Change current directory
2018-12-17T23:09:09.448212085Z 59 PC: 12a7b | Change current directory
2018-12-17T23:09:09.450297995Z 76 PC: 12a56 | Terminate with return code (Return code = '0')