Sample viewer

vx.netlux.org/Virus.DOS.Ash.712

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:09:49.475907655Z 26 PC: 20b8e | Set disk transfer address
2018-12-17T23:09:49.478266861Z 86 PC: 20bb5 | Rename file
2018-12-17T23:09:49.82238635Z 60 PC: 20bbe | Create or truncate file
2018-12-17T23:09:49.834514967Z 64 PC: 20bcd | Write file or device (Write 8 bytes on handle 5)
2018-12-17T23:09:49.847089344Z 62 PC: 20bd1 | Close file
2018-12-17T23:09:49.861020882Z 61 PC: 20bda | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T23:09:49.868500395Z 63 PC: 20c52 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:09:49.87301728Z 66 PC: 20c69 | Move file pointer
2018-12-17T23:09:49.875150688Z 64 PC: 20c82 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:09:49.879120366Z 64 PC: 20b64 | Write file or device (Write 708 bytes on handle 5)
2018-12-17T23:09:49.8880161Z 66 PC: 20cc5 | Move file pointer
2018-12-17T23:09:49.89040041Z 64 PC: 20ce3 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:09:49.89737046Z 62 PC: 20c14 | Close file
2018-12-17T23:09:49.906535404Z 79 PC: 20c27 | Find next file
2018-12-17T23:09:49.909495922Z 59 PC: 20d09 | Change current directory
2018-12-17T23:09:49.914607195Z 53 PC: 20d69 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:09:49.916254746Z 37 PC: 20d7a | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:09:49.922844872Z 9 PC: 20d82 | Display string (Could not find end pointer)
2018-12-17T23:09:49.927834343Z 49 PC: 20d85 | Terminate and stay resident (Return code = '0' | Memory size = '3661')