Sample viewer

vx.netlux.org/Virus.DOS.SillyC.253.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:10:49.010953861Z 53 PC: 13280 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:10:49.013079063Z 78 PC: 132b6 | Find first file
2018-12-17T23:10:49.019975533Z 61 PC: 132f5 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:10:49.027931743Z 87 PC: 132fc | Get or set file date and time
2018-12-17T23:10:49.029523115Z 66 PC: 13364 | Move file pointer
2018-12-17T23:10:49.033807083Z 62 PC: 132c4 | Close file
2018-12-17T23:10:49.036275389Z 79 PC: 132d1 | Find next file
2018-12-17T23:10:49.039556835Z 61 PC: 132f5 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:10:49.047920404Z 87 PC: 132fc | Get or set file date and time
2018-12-17T23:10:49.049483505Z 66 PC: 13364 | Move file pointer
2018-12-17T23:10:49.051093211Z 62 PC: 132c4 | Close file
2018-12-17T23:10:49.05791464Z 79 PC: 132d1 | Find next file
2018-12-17T23:10:49.059959307Z 61 PC: 132f5 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:10:49.064579908Z 87 PC: 132fc | Get or set file date and time
2018-12-17T23:10:49.068203397Z 66 PC: 13364 | Move file pointer
2018-12-17T23:10:49.071057288Z 62 PC: 132c4 | Close file
2018-12-17T23:10:49.074152174Z 79 PC: 132d1 | Find next file
2018-12-17T23:10:49.0784769Z 61 PC: 132f5 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:10:49.086033808Z 87 PC: 132fc | Get or set file date and time
2018-12-17T23:10:49.087657936Z 66 PC: 13364 | Move file pointer
2018-12-17T23:10:49.089424974Z 62 PC: 132c4 | Close file
2018-12-17T23:10:49.103994797Z 79 PC: 132d1 | Find next file
2018-12-17T23:10:49.106764051Z 61 PC: 132f5 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:10:49.113948706Z 87 PC: 132fc | Get or set file date and time
2018-12-17T23:10:49.115863882Z 66 PC: 13364 | Move file pointer
2018-12-17T23:10:49.117249344Z 62 PC: 132c4 | Close file
2018-12-17T23:10:49.118959237Z 79 PC: 132d1 | Find next file
2018-12-17T23:10:49.128512811Z 61 PC: 132f5 | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:10:49.133321437Z 87 PC: 132fc | Get or set file date and time
2018-12-17T23:10:49.134836402Z 66 PC: 13364 | Move file pointer
2018-12-17T23:10:49.136823306Z 62 PC: 132c4 | Close file
2018-12-17T23:10:49.138327629Z 79 PC: 132d1 | Find next file
2018-12-17T23:10:49.140363851Z 61 PC: 132f5 | Open file (Filename = 'PAH.COM')
2018-12-17T23:10:49.145205863Z 87 PC: 132fc | Get or set file date and time
2018-12-17T23:10:49.146689573Z 66 PC: 13364 | Move file pointer
2018-12-17T23:10:49.148045037Z 62 PC: 132c4 | Close file
2018-12-17T23:10:49.150490951Z 79 PC: 132d1 | Find next file
2018-12-17T23:10:49.153115153Z 61 PC: 132f5 | Open file (Filename = 'TEST.COM')
2018-12-17T23:10:49.160178804Z 87 PC: 132fc | Get or set file date and time
2018-12-17T23:10:49.162289362Z 66 PC: 13364 | Move file pointer
2018-12-17T23:10:49.16378619Z 66 PC: 13364 | Move file pointer
2018-12-17T23:10:49.165185528Z 63 PC: 13321 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:10:49.16808743Z 66 PC: 13364 | Move file pointer
2018-12-17T23:10:49.169866553Z 66 PC: 13364 | Move file pointer
2018-12-17T23:10:49.171312846Z 64 PC: 13341 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:10:49.174103428Z 66 PC: 13364 | Move file pointer
2018-12-17T23:10:49.175677532Z 64 PC: 13350 | Write file or device (Write 253 bytes on handle 5)
2018-12-17T23:10:49.191912594Z 87 PC: 1335b | Get or set file date and time
2018-12-17T23:10:49.193219956Z 62 PC: 132c4 | Close file
2018-12-17T23:10:49.202011195Z 79 PC: 132d1 | Find next file
2018-12-17T23:10:49.205141635Z 9 PC: 12a86 | Display string (String= 'Goat file (COM/....). Size=00000834h/0000002100d bytes. ')
2018-12-17T23:10:49.212019963Z 48 PC: 12a8f | Get DOS version
2018-12-17T23:10:49.213953243Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-17T23:10:49.218449467Z 93 PC: 12afe | File sharing functions
2018-12-17T23:10:49.219794705Z 9 PC: 12a86 | Display string (String= 'Size change=01FAh/00506d. ')
2018-12-17T23:10:49.223042822Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')