Sample viewer

vx.netlux.org/Virus.DOS.Ash.737

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:09:38.945318132Z 26 PC: 12a96 | Set disk transfer address
2018-12-17T22:09:38.94701793Z 86 PC: 12abf | Rename file
2018-12-17T22:09:39.295157093Z 60 PC: 12ac8 | Create or truncate file
2018-12-17T22:09:39.305731693Z 64 PC: 12ad7 | Write file or device (Write 8 bytes on handle 5)
2018-12-17T22:09:39.314421451Z 62 PC: 12adb | Close file
2018-12-17T22:09:39.321680311Z 61 PC: 12ae4 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:09:39.328519379Z 63 PC: 12b61 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:09:39.33177339Z 66 PC: 12b7a | Move file pointer
2018-12-17T22:09:39.333482361Z 64 PC: 12b94 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:09:39.33640707Z 64 PC: 12a69 | Write file or device (Write 733 bytes on handle 5)
2018-12-17T22:09:39.342674141Z 66 PC: 12bd7 | Move file pointer
2018-12-17T22:09:39.344366052Z 64 PC: 12bf9 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:09:39.350292416Z 62 PC: 12b20 | Close file
2018-12-17T22:09:39.357211166Z 78 PC: 12b34 | Find first file
2018-12-17T22:09:39.363666904Z 61 PC: 12b52 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:09:39.370290856Z 63 PC: 12b61 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:09:39.376908618Z 66 PC: 12b7a | Move file pointer
2018-12-17T22:09:39.379872303Z 64 PC: 12b94 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:09:39.383079455Z 64 PC: 12a69 | Write file or device (Write 733 bytes on handle 5)
2018-12-17T22:09:39.397801286Z 66 PC: 12bd7 | Move file pointer
2018-12-17T22:09:39.399940969Z 64 PC: 12bf9 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:09:39.40639042Z 62 PC: 12b20 | Close file
2018-12-17T22:09:39.41432802Z 79 PC: 12b34 | Find next file
2018-12-17T22:09:39.418324871Z 61 PC: 12b52 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:09:39.424667777Z 63 PC: 12b61 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:09:39.43088199Z 66 PC: 12b7a | Move file pointer
2018-12-17T22:09:39.433400222Z 64 PC: 12b94 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:09:39.436530477Z 64 PC: 12a69 | Write file or device (Write 733 bytes on handle 5)
2018-12-17T22:09:39.44501352Z 66 PC: 12bd7 | Move file pointer
2018-12-17T22:09:39.446728136Z 64 PC: 12bf9 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:09:39.453767466Z 53 PC: 12c86 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:09:39.455284339Z 37 PC: 12c97 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:09:39.456989115Z 9 PC: 12c9f | Display string (Could not find end pointer)
2018-12-17T22:09:39.462653139Z 49 PC: 12ca2 | Terminate and stay resident (Return code = '0' | Memory size = '63')