Sample viewer

vx.netlux.org/Virus.DOS.Kaszana.1920

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:12:08.034151163Z 26 PC: 13203 | Set disk transfer address
2018-12-17T23:12:08.035842801Z 53 PC: 13209 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:08.037415192Z 37 PC: 13217 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:08.038903076Z 37 PC: 1321e | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:12:08.047821501Z 78 PC: 132c9 | Find first file
2018-12-17T23:12:08.054430168Z 79 PC: 132dd | Find next file
2018-12-17T23:12:08.057464416Z 79 PC: 132dd | Find next file
2018-12-17T23:12:08.060511862Z 79 PC: 132dd | Find next file
2018-12-17T23:12:08.063796501Z 79 PC: 132dd | Find next file
2018-12-17T23:12:08.066663175Z 79 PC: 132dd | Find next file
2018-12-17T23:12:08.06934916Z 79 PC: 132dd | Find next file
2018-12-17T23:12:08.072404897Z 79 PC: 132dd | Find next file
2018-12-17T23:12:08.075110956Z 67 PC: 1330e | Get or set file attributes
2018-12-17T23:12:08.089930635Z 61 PC: 13315 | Open file (Filename = 'TEST.COM')
2018-12-17T23:12:08.097255809Z 63 PC: 13326 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:12:08.099738242Z 66 PC: 13331 | Move file pointer
2018-12-17T23:12:08.101661412Z 64 PC: 1346a | Write file or device (Write 960 bytes on handle 5)
2018-12-17T23:12:08.112688052Z 66 PC: 134bb | Move file pointer
2018-12-17T23:12:08.114413764Z 63 PC: 134c8 | Read file or device (Read 960 bytes on handle 5)
2018-12-17T23:12:08.122186372Z 66 PC: 134db | Move file pointer
2018-12-17T23:12:08.124876678Z 64 PC: 134e5 | Write file or device (Write 960 bytes on handle 5)
2018-12-17T23:12:08.133350043Z 66 PC: 134f8 | Move file pointer
2018-12-17T23:12:08.134812141Z 64 PC: 13509 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:12:08.1380619Z 87 PC: 1335c | Get or set file date and time
2018-12-17T23:12:08.140031086Z 62 PC: 13367 | Close file
2018-12-17T23:12:08.148351435Z 67 PC: 13376 | Get or set file attributes
2018-12-17T23:12:08.159840676Z 78 PC: 132c9 | Find first file
2018-12-17T23:12:08.168634118Z 79 PC: 132dd | Find next file
2018-12-17T23:12:08.171963835Z 67 PC: 1330e | Get or set file attributes
2018-12-17T23:12:08.529348917Z 61 PC: 13315 | Open file (Filename = 'C:\DOS\FORMAT.COM')
2018-12-17T23:12:08.536276178Z 63 PC: 13326 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:12:08.543405993Z 66 PC: 13331 | Move file pointer
2018-12-17T23:12:08.545946934Z 64 PC: 1346a | Write file or device (Write 960 bytes on handle 5)
2018-12-17T23:12:08.657644688Z 66 PC: 134bb | Move file pointer
2018-12-17T23:12:08.658744285Z 63 PC: 134c8 | Read file or device (Read 960 bytes on handle 5)
2018-12-17T23:12:08.663580784Z 66 PC: 134db | Move file pointer
2018-12-17T23:12:08.665551533Z 64 PC: 134e5 | Write file or device (Write 960 bytes on handle 5)
2018-12-17T23:12:08.85377126Z 66 PC: 134f8 | Move file pointer
2018-12-17T23:12:08.855305492Z 64 PC: 13509 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:12:08.859094042Z 87 PC: 1335c | Get or set file date and time
2018-12-17T23:12:08.860851727Z 62 PC: 13367 | Close file
2018-12-17T23:12:08.867556391Z 67 PC: 13376 | Get or set file attributes
2018-12-17T23:12:08.877726701Z 26 PC: 13386 | Set disk transfer address
2018-12-17T23:12:08.878697687Z 37 PC: 13392 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:08.880004748Z 9 PC: 12e26 | Display string (String= 'Hello - This is a 1000 COM test file, 1993 ')