Sample viewer

vx.netlux.org/Virus.DOS.Sylvia.c

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:27.843921003Z 53 PC: 12c80 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:27.846869579Z 37 PC: 12c93 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:27.849202016Z 74 PC: 12c9a | Reallocate memory
2018-12-17T23:11:27.851383478Z 72 PC: 12caa | Allocate memory
2018-12-17T23:11:27.853730462Z 25 PC: 12cca | Get default drive
2018-12-17T23:11:27.856625427Z 14 PC: 12cd3 | Set default drive (Drive = 'C')
2018-12-17T23:11:27.858675282Z 26 PC: 12cdb | Set disk transfer address
2018-12-17T23:11:27.860559206Z 78 PC: 12cfa | Find first file
2018-12-17T23:11:27.868293582Z 79 PC: 12f01 | Find next file
2018-12-17T23:11:27.871559194Z 14 PC: 12f1c | Set default drive (Drive = 'A')
2018-12-17T23:11:27.873624068Z 78 PC: 12cfa | Find first file
2018-12-17T23:11:27.881364645Z 61 PC: 12d65 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:11:27.88888546Z 66 PC: 12d7c | Move file pointer
2018-12-17T23:11:27.891047106Z 63 PC: 12d90 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:11:27.90165134Z 67 PC: 12df9 | Get or set file attributes
2018-12-17T23:11:27.919359695Z 67 PC: 12e03 | Get or set file attributes
2018-12-17T23:11:27.925862104Z 60 PC: 12e0e | Create or truncate file
2018-12-17T23:11:27.937097165Z 64 PC: 12e26 | Write file or device (Write 1301 bytes on handle 6)
2018-12-17T23:11:27.946108433Z 66 PC: 12e54 | Move file pointer
2018-12-17T23:11:27.947588497Z 63 PC: 12e6f | Read file or device (Read 407 bytes on handle 5)
2018-12-17T23:11:27.950295367Z 64 PC: 12e86 | Write file or device (Write 407 bytes on handle 6)
2018-12-17T23:11:27.960548431Z 64 PC: 12e9d | Write file or device (Write 31 bytes on handle 6)
2018-12-17T23:11:27.963776272Z 87 PC: 12ebf | Get or set file date and time
2018-12-17T23:11:27.966275181Z 62 PC: 12ec7 | Close file
2018-12-17T23:11:27.970321652Z 62 PC: 12ecf | Close file
2018-12-17T23:11:27.978816479Z 65 PC: 12ed6 | Delete file (Filename = 'SLEEP.COM')
2018-12-17T23:11:27.99138138Z 86 PC: 12ee8 | Rename file
2018-12-17T23:11:28.004841676Z 67 PC: 12efd | Get or set file attributes
2018-12-17T23:11:28.015784998Z 79 PC: 12f01 | Find next file
2018-12-17T23:11:28.019134818Z 61 PC: 12d65 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:11:28.032655116Z 66 PC: 12d7c | Move file pointer
2018-12-17T23:11:28.035064938Z 63 PC: 12d90 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:11:28.042389615Z 67 PC: 12df9 | Get or set file attributes
2018-12-17T23:11:28.053837465Z 67 PC: 12e03 | Get or set file attributes
2018-12-17T23:11:28.064827624Z 60 PC: 12e0e | Create or truncate file
2018-12-17T23:11:28.346024216Z 64 PC: 12e26 | Write file or device (Write 1301 bytes on handle 6)
2018-12-17T23:11:28.396709081Z 66 PC: 12e54 | Move file pointer
2018-12-17T23:11:28.399892027Z 63 PC: 12e6f | Read file or device (Read 27 bytes on handle 5)
2018-12-17T23:11:28.403909603Z 64 PC: 12e86 | Write file or device (Write 27 bytes on handle 6)
2018-12-17T23:11:28.407260916Z 64 PC: 12e9d | Write file or device (Write 31 bytes on handle 6)
2018-12-17T23:11:28.411958682Z 87 PC: 12ebf | Get or set file date and time
2018-12-17T23:11:28.414176753Z 62 PC: 12ec7 | Close file
2018-12-17T23:11:28.417807973Z 62 PC: 12ecf | Close file
2018-12-17T23:11:28.428633312Z 65 PC: 12ed6 | Delete file (Filename = 'PRINT.COM')
2018-12-17T23:11:28.441725536Z 86 PC: 12ee8 | Rename file
2018-12-17T23:11:28.454429409Z 67 PC: 12efd | Get or set file attributes
2018-12-17T23:11:28.466731055Z 79 PC: 12f01 | Find next file
2018-12-17T23:11:28.471340144Z 61 PC: 12d65 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:11:28.479004218Z 66 PC: 12d7c | Move file pointer
2018-12-17T23:11:28.481049935Z 63 PC: 12d90 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:11:28.48903352Z 67 PC: 12df9 | Get or set file attributes
2018-12-17T23:11:28.500218206Z 67 PC: 12e03 | Get or set file attributes
2018-12-17T23:11:28.507144903Z 60 PC: 12e0e | Create or truncate file
2018-12-17T23:11:28.519621839Z 64 PC: 12e26 | Write file or device (Write 1301 bytes on handle 6)
2018-12-17T23:11:28.528790213Z 66 PC: 12e54 | Move file pointer
2018-12-17T23:11:28.53085167Z 63 PC: 12e6f | Read file or device (Read 92 bytes on handle 5)
2018-12-17T23:11:28.534611331Z 64 PC: 12e86 | Write file or device (Write 92 bytes on handle 6)
2018-12-17T23:11:28.538832179Z 64 PC: 12e9d | Write file or device (Write 31 bytes on handle 6)
2018-12-17T23:11:28.542226082Z 87 PC: 12ebf | Get or set file date and time
2018-12-17T23:11:28.544917033Z 62 PC: 12ec7 | Close file
2018-12-17T23:11:28.547053822Z 62 PC: 12ecf | Close file
2018-12-17T23:11:28.555641123Z 65 PC: 12ed6 | Delete file (Filename = 'HELLO.COM')
2018-12-17T23:11:28.568722275Z 86 PC: 12ee8 | Rename file
2018-12-17T23:11:28.581560751Z 67 PC: 12efd | Get or set file attributes
2018-12-17T23:11:28.592384237Z 79 PC: 12f01 | Find next file
2018-12-17T23:11:28.596557236Z 61 PC: 12d65 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:11:28.610407144Z 66 PC: 12d7c | Move file pointer
2018-12-17T23:11:28.612068208Z 63 PC: 12d90 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:11:28.619487562Z 67 PC: 12df9 | Get or set file attributes
2018-12-17T23:11:28.631196032Z 67 PC: 12e03 | Get or set file attributes
2018-12-17T23:11:28.641309002Z 60 PC: 12e0e | Create or truncate file
2018-12-17T23:11:28.653430239Z 64 PC: 12e26 | Write file or device (Write 1301 bytes on handle 6)
2018-12-17T23:11:28.663722006Z 66 PC: 12e54 | Move file pointer
2018-12-17T23:11:28.665705907Z 63 PC: 12e6f | Read file or device (Read 29 bytes on handle 5)
2018-12-17T23:11:28.669701031Z 64 PC: 12e86 | Write file or device (Write 29 bytes on handle 6)
2018-12-17T23:11:28.674139779Z 64 PC: 12e9d | Write file or device (Write 31 bytes on handle 6)
2018-12-17T23:11:28.677840008Z 87 PC: 12ebf | Get or set file date and time
2018-12-17T23:11:28.679874575Z 62 PC: 12ec7 | Close file
2018-12-17T23:11:28.683218654Z 62 PC: 12ecf | Close file
2018-12-17T23:11:28.692674989Z 65 PC: 12ed6 | Delete file (Filename = 'PHANG.COM')
2018-12-17T23:11:28.705188594Z 86 PC: 12ee8 | Rename file
2018-12-17T23:11:28.717752283Z 67 PC: 12efd | Get or set file attributes
2018-12-17T23:11:28.729623801Z 79 PC: 12f01 | Find next file
2018-12-17T23:11:28.732969182Z 61 PC: 12d65 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:11:28.741204722Z 66 PC: 12d7c | Move file pointer
2018-12-17T23:11:28.743796125Z 63 PC: 12d90 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:11:28.751092578Z 62 PC: 12db9 | Close file
2018-12-17T23:11:28.753423282Z 73 PC: 12f28 | Release memory
2018-12-17T23:11:28.756339877Z 74 PC: 12f33 | Reallocate memory
2018-12-17T23:11:28.758926281Z 74 PC: 12f39 | Reallocate memory
2018-12-17T23:11:28.760802009Z 37 PC: 12f4a | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')