Sample viewer

vx.netlux.org/Virus.DOS.Avispa.2048.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:11:36.916907975Z 75 PC: 17127 | Execute program
2018-12-17T22:11:36.918731387Z 74 PC: 12b61 | Reallocate memory
2018-12-17T22:11:36.920475382Z 53 PC: 12b66 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:11:36.921572625Z 53 PC: 12b73 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:11:36.923214894Z 37 PC: 12b83 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:11:36.924250035Z 37 PC: 12b8b | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:11:36.92526607Z 75 PC: 12bdc | Execute program
2018-12-17T22:11:36.941575575Z 74 PC: 1343f | Reallocate memory
2018-12-17T22:11:36.94404132Z 48 PC: 13459 | Get DOS version
2018-12-17T22:11:36.945157373Z 55 PC: 13468 | Get or set switch character
2018-12-17T22:11:36.951770388Z 56 PC: 1667d | Get or set country info
2018-12-17T22:11:36.953968082Z 2 PC: 16161 | Character output (Char = '51')
2018-12-17T22:11:36.956975277Z 2 PC: 16161 | Character output (Char = '55')
2018-12-17T22:11:36.959896376Z 2 PC: 16161 | Character output (Char = '2d')
2018-12-17T22:11:36.962606415Z 2 PC: 16161 | Character output (Char = '51')
2018-12-17T22:11:36.964826284Z 2 PC: 16161 | Character output (Char = '75')
2018-12-17T22:11:36.968266471Z 2 PC: 16161 | Character output (Char = '69')
2018-12-17T22:11:36.971168224Z 2 PC: 16161 | Character output (Char = '63')
2018-12-17T22:11:36.973937498Z 2 PC: 16161 | Character output (Char = '6b')
2018-12-17T22:11:36.976778378Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:36.979432983Z 2 PC: 16161 | Character output (Char = '55')
2018-12-17T22:11:36.981839819Z 2 PC: 16161 | Character output (Char = '6e')
2018-12-17T22:11:36.984438179Z 2 PC: 16161 | Character output (Char = '45')
2018-12-17T22:11:36.987218506Z 2 PC: 16161 | Character output (Char = '72')
2018-12-17T22:11:36.989872362Z 2 PC: 16161 | Character output (Char = '61')
2018-12-17T22:11:36.992567527Z 2 PC: 16161 | Character output (Char = '73')
2018-12-17T22:11:36.995154879Z 2 PC: 16161 | Character output (Char = '65')
2018-12-17T22:11:36.996865334Z 2 PC: 16161 | Character output (Char = '2c')
2018-12-17T22:11:36.998661275Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.001286437Z 2 PC: 16161 | Character output (Char = '41')
2018-12-17T22:11:37.003650831Z 2 PC: 16161 | Character output (Char = '64')
2018-12-17T22:11:37.006073844Z 2 PC: 16161 | Character output (Char = '76')
2018-12-17T22:11:37.008815089Z 2 PC: 16161 | Character output (Char = '61')
2018-12-17T22:11:37.0109685Z 2 PC: 16161 | Character output (Char = '6e')
2018-12-17T22:11:37.013147197Z 2 PC: 16161 | Character output (Char = '63')
2018-12-17T22:11:37.015851057Z 2 PC: 16161 | Character output (Char = '65')
2018-12-17T22:11:37.017980229Z 2 PC: 16161 | Character output (Char = '64')
2018-12-17T22:11:37.020264174Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.023038452Z 2 PC: 16161 | Character output (Char = '45')
2018-12-17T22:11:37.025282479Z 2 PC: 16161 | Character output (Char = '64')
2018-12-17T22:11:37.027444207Z 2 PC: 16161 | Character output (Char = '69')
2018-12-17T22:11:37.030438774Z 2 PC: 16161 | Character output (Char = '74')
2018-12-17T22:11:37.032608475Z 2 PC: 16161 | Character output (Char = '69')
2018-12-17T22:11:37.034718919Z 2 PC: 16161 | Character output (Char = '6f')
2018-12-17T22:11:37.038124004Z 2 PC: 16161 | Character output (Char = '6e')
2018-12-17T22:11:37.04064709Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.043152057Z 2 PC: 16161 | Character output (Char = '34')
2018-12-17T22:11:37.046236004Z 2 PC: 16161 | Character output (Char = '2e')
2018-12-17T22:11:37.049543215Z 2 PC: 16161 | Character output (Char = '35')
2018-12-17T22:11:37.051729545Z 2 PC: 16161 | Character output (Char = '30')
2018-12-17T22:11:37.055204771Z 2 PC: 16161 | Character output (Char = '2c')
2018-12-17T22:11:37.057967009Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.060590656Z 2 PC: 16161 | Character output (Char = '28')
2018-12-17T22:11:37.063571582Z 2 PC: 16161 | Character output (Char = '43')
2018-12-17T22:11:37.065759884Z 2 PC: 16161 | Character output (Char = '29')
2018-12-17T22:11:37.067830734Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.070637508Z 2 PC: 16161 | Character output (Char = '43')
2018-12-17T22:11:37.072787094Z 2 PC: 16161 | Character output (Char = '6f')
2018-12-17T22:11:37.074865255Z 2 PC: 16161 | Character output (Char = '70')
2018-12-17T22:11:37.077761536Z 2 PC: 16161 | Character output (Char = '72')
2018-12-17T22:11:37.081498573Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.083773951Z 2 PC: 16161 | Character output (Char = '31')
2018-12-17T22:11:37.086637522Z 2 PC: 16161 | Character output (Char = '39')
2018-12-17T22:11:37.089377229Z 2 PC: 16161 | Character output (Char = '38')
2018-12-17T22:11:37.091928187Z 2 PC: 16161 | Character output (Char = '37')
2018-12-17T22:11:37.095571639Z 2 PC: 16161 | Character output (Char = '2d')
2018-12-17T22:11:37.09714883Z 2 PC: 16161 | Character output (Char = '38')
2018-12-17T22:11:37.098615546Z 2 PC: 16161 | Character output (Char = '38')
2018-12-17T22:11:37.101464377Z 2 PC: 16161 | Character output (Char = '2c')
2018-12-17T22:11:37.103919749Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.106361602Z 2 PC: 16161 | Character output (Char = '50')
2018-12-17T22:11:37.109584208Z 2 PC: 16161 | Character output (Char = '65')
2018-12-17T22:11:37.111752041Z 2 PC: 16161 | Character output (Char = '74')
2018-12-17T22:11:37.113833435Z 2 PC: 16161 | Character output (Char = '65')
2018-12-17T22:11:37.116647876Z 2 PC: 16161 | Character output (Char = '72')
2018-12-17T22:11:37.118763022Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.120993753Z 2 PC: 16161 | Character output (Char = '4e')
2018-12-17T22:11:37.12399526Z 2 PC: 16161 | Character output (Char = '6f')
2018-12-17T22:11:37.126169416Z 2 PC: 16161 | Character output (Char = '72')
2018-12-17T22:11:37.128273038Z 2 PC: 16161 | Character output (Char = '74')
2018-12-17T22:11:37.131722611Z 2 PC: 16161 | Character output (Char = '6f')
2018-12-17T22:11:37.134136614Z 2 PC: 16161 | Character output (Char = '6e')
2018-12-17T22:11:37.136970324Z 2 PC: 1615c | Character output (Char = '0d')
2018-12-17T22:11:37.139115617Z 2 PC: 16161 | Character output (Char = '0a')
2018-12-17T22:11:37.143435344Z 2 PC: 1615c | Character output (Char = '0d')
2018-12-17T22:11:37.145192797Z 2 PC: 16161 | Character output (Char = '0a')
2018-12-17T22:11:37.148561842Z 13 PC: 150c8 | Disk reset
2018-12-17T22:11:37.150860152Z 25 PC: 16122 | Get default drive
2018-12-17T22:11:37.152682005Z 68 PC: 150e3 | I/O control for devices (Set for = '���؃�')
2018-12-17T22:11:37.154750894Z 37 PC: 14dba | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:11:37.156211621Z 25 PC: 16122 | Get default drive
2018-12-17T22:11:37.157191365Z 13 PC: 150c8 | Disk reset
2018-12-17T22:11:37.15858604Z 50 PC: 16610 | Get disk parameter block for specified drive
2018-12-17T22:11:37.161436133Z 72 PC: 1663d | Allocate memory
2018-12-17T22:11:37.167931549Z 73 PC: 1666c | Release memory
2018-12-17T22:11:37.169686969Z 72 PC: 16a13 | Allocate memory
2018-12-17T22:11:37.176389795Z 71 PC: 15a4e | Get current directory
2018-12-17T22:11:37.179475828Z 13 PC: 150c8 | Disk reset
2018-12-17T22:11:37.18089707Z 50 PC: 16610 | Get disk parameter block for specified drive
2018-12-17T22:11:37.18438675Z 74 PC: 16a6e | Reallocate memory
2018-12-17T22:11:37.185914207Z 74 PC: 16a6e | Reallocate memory
2018-12-17T22:11:37.193934704Z 2 PC: 16161 | Character output (Char = '44')
2018-12-17T22:11:37.197237795Z 2 PC: 16161 | Character output (Char = '69')
2018-12-17T22:11:37.19918754Z 2 PC: 16161 | Character output (Char = '72')
2018-12-17T22:11:37.201186652Z 2 PC: 16161 | Character output (Char = '65')
2018-12-17T22:11:37.204038608Z 2 PC: 16161 | Character output (Char = '63')
2018-12-17T22:11:37.205881768Z 2 PC: 16161 | Character output (Char = '74')
2018-12-17T22:11:37.207816899Z 2 PC: 16161 | Character output (Char = '6f')
2018-12-17T22:11:37.210753173Z 2 PC: 16161 | Character output (Char = '72')
2018-12-17T22:11:37.213120528Z 2 PC: 16161 | Character output (Char = '79')
2018-12-17T22:11:37.215110362Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.217678348Z 2 PC: 16161 | Character output (Char = '6f')
2018-12-17T22:11:37.220144188Z 2 PC: 16161 | Character output (Char = '66')
2018-12-17T22:11:37.222334333Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.224754302Z 2 PC: 16161 | Character output (Char = '41')
2018-12-17T22:11:37.226779006Z 2 PC: 16161 | Character output (Char = '3a')
2018-12-17T22:11:37.228749204Z 2 PC: 16161 | Character output (Char = '5c')
2018-12-17T22:11:37.231053877Z 2 PC: 1615c | Character output (Char = '0d')
2018-12-17T22:11:37.233087798Z 2 PC: 16161 | Character output (Char = '0a')
2018-12-17T22:11:37.237429347Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.240733908Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.243167457Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.245256284Z 2 PC: 16161 | Character output (Char = '45')
2018-12-17T22:11:37.24810346Z 2 PC: 16161 | Character output (Char = '72')
2018-12-17T22:11:37.250283161Z 2 PC: 16161 | Character output (Char = '61')
2018-12-17T22:11:37.252321298Z 2 PC: 16161 | Character output (Char = '73')
2018-12-17T22:11:37.255180925Z 2 PC: 16161 | Character output (Char = '65')
2018-12-17T22:11:37.257321644Z 2 PC: 16161 | Character output (Char = '64')
2018-12-17T22:11:37.259346967Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.261965703Z 2 PC: 16161 | Character output (Char = '66')
2018-12-17T22:11:37.264007533Z 2 PC: 16161 | Character output (Char = '69')
2018-12-17T22:11:37.266040621Z 2 PC: 16161 | Character output (Char = '6c')
2018-12-17T22:11:37.268478122Z 2 PC: 16161 | Character output (Char = '65')
2018-12-17T22:11:37.271360867Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.273417521Z 2 PC: 16161 | Character output (Char = '73')
2018-12-17T22:11:37.276085594Z 2 PC: 16161 | Character output (Char = '70')
2018-12-17T22:11:37.27803831Z 2 PC: 16161 | Character output (Char = '65')
2018-12-17T22:11:37.28000822Z 2 PC: 16161 | Character output (Char = '63')
2018-12-17T22:11:37.282264096Z 2 PC: 16161 | Character output (Char = '69')
2018-12-17T22:11:37.284283664Z 2 PC: 16161 | Character output (Char = '66')
2018-12-17T22:11:37.286306284Z 2 PC: 16161 | Character output (Char = '69')
2018-12-17T22:11:37.288389732Z 2 PC: 16161 | Character output (Char = '63')
2018-12-17T22:11:37.290310236Z 2 PC: 16161 | Character output (Char = '61')
2018-12-17T22:11:37.292460436Z 2 PC: 16161 | Character output (Char = '74')
2018-12-17T22:11:37.306469156Z 2 PC: 16161 | Character output (Char = '69')
2018-12-17T22:11:37.308680334Z 2 PC: 16161 | Character output (Char = '6f')
2018-12-17T22:11:37.311256378Z 2 PC: 16161 | Character output (Char = '6e')
2018-12-17T22:11:37.313803467Z 2 PC: 16161 | Character output (Char = '3a')
2018-12-17T22:11:37.315751772Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.318004428Z 2 PC: 16161 | Character output (Char = '2a')
2018-12-17T22:11:37.319477144Z 2 PC: 16161 | Character output (Char = '2e')
2018-12-17T22:11:37.321589405Z 2 PC: 16161 | Character output (Char = '2a')
2018-12-17T22:11:37.324217403Z 2 PC: 1615c | Character output (Char = '0d')
2018-12-17T22:11:37.326073169Z 2 PC: 16161 | Character output (Char = '0a')
2018-12-17T22:11:37.330437426Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.333008749Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.336752511Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.338797786Z 2 PC: 16161 | Character output (Char = '4e')
2018-12-17T22:11:37.341327905Z 2 PC: 16161 | Character output (Char = '75')
2018-12-17T22:11:37.343353809Z 2 PC: 16161 | Character output (Char = '6d')
2018-12-17T22:11:37.345389897Z 2 PC: 16161 | Character output (Char = '62')
2018-12-17T22:11:37.347877232Z 2 PC: 16161 | Character output (Char = '65')
2018-12-17T22:11:37.349915833Z 2 PC: 16161 | Character output (Char = '72')
2018-12-17T22:11:37.3519126Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.355229662Z 2 PC: 16161 | Character output (Char = '6f')
2018-12-17T22:11:37.357367552Z 2 PC: 16161 | Character output (Char = '66')
2018-12-17T22:11:37.359333244Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.36191548Z 2 PC: 16161 | Character output (Char = '65')
2018-12-17T22:11:37.364169015Z 2 PC: 16161 | Character output (Char = '72')
2018-12-17T22:11:37.366348397Z 2 PC: 16161 | Character output (Char = '61')
2018-12-17T22:11:37.369610144Z 2 PC: 16161 | Character output (Char = '73')
2018-12-17T22:11:37.371896391Z 2 PC: 16161 | Character output (Char = '65')
2018-12-17T22:11:37.374193158Z 2 PC: 16161 | Character output (Char = '64')
2018-12-17T22:11:37.377137299Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.379102582Z 2 PC: 16161 | Character output (Char = '66')
2018-12-17T22:11:37.381047725Z 2 PC: 16161 | Character output (Char = '69')
2018-12-17T22:11:37.38344368Z 2 PC: 16161 | Character output (Char = '6c')
2018-12-17T22:11:37.384819263Z 2 PC: 16161 | Character output (Char = '65')
2018-12-17T22:11:37.386378581Z 2 PC: 16161 | Character output (Char = '73')
2018-12-17T22:11:37.388828851Z 2 PC: 16161 | Character output (Char = '3a')
2018-12-17T22:11:37.390770651Z 2 PC: 16161 | Character output (Char = '20')
2018-12-17T22:11:37.392840204Z 2 PC: 16161 | Character output (Char = '30')
2018-12-17T22:11:37.395113174Z 2 PC: 1615c | Character output (Char = '0d')
2018-12-17T22:11:37.396828073Z 2 PC: 16161 | Character output (Char = '0a')
2018-12-17T22:11:37.400471767Z 13 PC: 150c8 | Disk reset
2018-12-17T22:11:37.4037057Z 76 PC: 134ba | Terminate with return code (Return code = '0')
2018-12-17T22:11:37.40678785Z 73 PC: 12be2 | Release memory
2018-12-17T22:11:37.409483264Z 49 PC: 12be9 | Terminate and stay resident (Return code = '125' | Memory size = '144')