Sample viewer

vx.netlux.org/Virus.DOS.Zlodic.666.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:09:59.187284257Z 53 PC: 12e5b | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:59.189500744Z 37 PC: 12e70 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:59.190870053Z 71 PC: 12e8e | Get current directory
2018-12-17T23:09:59.193912851Z 47 PC: 12e92 | Get disk transfer address
2018-12-17T23:09:59.195890767Z 26 PC: 12ea4 | Set disk transfer address
2018-12-17T23:09:59.196949562Z 78 PC: 12ee4 | Find first file
2018-12-17T23:09:59.202922348Z 61 PC: 12ef2 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:09:59.211620234Z 63 PC: 12efe | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:09:59.217841536Z 87 PC: 12f03 | Get or set file date and time
2018-12-17T23:09:59.219124661Z 66 PC: 12f16 | Move file pointer
2018-12-17T23:09:59.224648785Z 62 PC: 12f1b | Close file
2018-12-17T23:09:59.226581511Z 79 PC: 12ee4 | Find next file
2018-12-17T23:09:59.229146838Z 61 PC: 12ef2 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:09:59.237014958Z 63 PC: 12efe | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:09:59.244070805Z 87 PC: 12f03 | Get or set file date and time
2018-12-17T23:09:59.245494015Z 66 PC: 12f16 | Move file pointer
2018-12-17T23:09:59.246822804Z 62 PC: 12f1b | Close file
2018-12-17T23:09:59.248926844Z 79 PC: 12ee4 | Find next file
2018-12-17T23:09:59.251477004Z 61 PC: 12ef2 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:09:59.257784461Z 63 PC: 12efe | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:09:59.26457173Z 87 PC: 12f03 | Get or set file date and time
2018-12-17T23:09:59.266143551Z 66 PC: 12f16 | Move file pointer
2018-12-17T23:09:59.267721085Z 62 PC: 12f1b | Close file
2018-12-17T23:09:59.270470701Z 79 PC: 12ee4 | Find next file
2018-12-17T23:09:59.273201025Z 61 PC: 12ef2 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:09:59.279702718Z 63 PC: 12efe | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:09:59.28726685Z 87 PC: 12f03 | Get or set file date and time
2018-12-17T23:09:59.289139658Z 66 PC: 12f16 | Move file pointer
2018-12-17T23:09:59.290439391Z 62 PC: 12f1b | Close file
2018-12-17T23:09:59.292716321Z 79 PC: 12ee4 | Find next file
2018-12-17T23:09:59.295466673Z 61 PC: 12ef2 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:09:59.30181691Z 63 PC: 12efe | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:09:59.308922966Z 87 PC: 12f03 | Get or set file date and time
2018-12-17T23:09:59.310285937Z 66 PC: 12f16 | Move file pointer
2018-12-17T23:09:59.311586808Z 62 PC: 12f1b | Close file
2018-12-17T23:09:59.313886409Z 79 PC: 12ee4 | Find next file
2018-12-17T23:09:59.316398061Z 61 PC: 12ef2 | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:09:59.322943125Z 63 PC: 12efe | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:09:59.329859686Z 87 PC: 12f03 | Get or set file date and time
2018-12-17T23:09:59.331243352Z 66 PC: 12f16 | Move file pointer
2018-12-17T23:09:59.332506257Z 62 PC: 12f1b | Close file
2018-12-17T23:09:59.335024771Z 79 PC: 12ee4 | Find next file
2018-12-17T23:09:59.33755021Z 61 PC: 12ef2 | Open file (Filename = 'PAH.COM')
2018-12-17T23:09:59.343764648Z 63 PC: 12efe | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:09:59.350615959Z 87 PC: 12f03 | Get or set file date and time
2018-12-17T23:09:59.35210661Z 66 PC: 12f16 | Move file pointer
2018-12-17T23:09:59.353468121Z 62 PC: 12f1b | Close file
2018-12-17T23:09:59.356074281Z 79 PC: 12ee4 | Find next file
2018-12-17T23:09:59.358571918Z 61 PC: 12ef2 | Open file (Filename = 'TEST.COM')
2018-12-17T23:09:59.364970668Z 63 PC: 12efe | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:09:59.368408114Z 87 PC: 12f03 | Get or set file date and time
2018-12-17T23:09:59.369667628Z 66 PC: 12f16 | Move file pointer
2018-12-17T23:09:59.3708943Z 62 PC: 12f1b | Close file
2018-12-17T23:09:59.373067347Z 79 PC: 12ee4 | Find next file
2018-12-17T23:09:59.375340587Z 78 PC: 12ee4 | Find first file
2018-12-17T23:09:59.381417087Z 59 PC: 12f65 | Change current directory
2018-12-17T23:09:59.386669434Z 37 PC: 13054 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:59.387757642Z 26 PC: 13064 | Set disk transfer address
2018-12-17T23:09:59.388653901Z 59 PC: 1306d | Change current directory
2018-12-17T23:09:59.39092713Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=000003E8h/0000001000d bytes. ')
2018-12-17T23:09:59.395296854Z 76 PC: 12a86 | Terminate with return code (Return code = '36')