Sample viewer

vx.netlux.org/Virus.DOS.Randall.3072

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:13:23.044037133Z 26 PC: 12fbd | Set disk transfer address
2018-12-17T22:13:23.048599084Z 78 PC: 12fe6 | Find first file
2018-12-17T22:13:23.055156385Z 61 PC: 136b9 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:13:23.0620807Z 63 PC: 136db | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:13:23.068994325Z 66 PC: 13048 | Move file pointer
2018-12-17T22:13:23.073405604Z 64 PC: 13ab0 | Write file or device (Write 3072 bytes on handle 5)
2018-12-17T22:13:23.089475507Z 66 PC: 135bb | Move file pointer
2018-12-17T22:13:23.091100534Z 64 PC: 136cc | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:13:23.09850601Z 87 PC: 131f9 | Get or set file date and time
2018-12-17T22:13:23.100206512Z 65 PC: 1311a | Delete file (Filename = 'CHKLIST.MS')
2018-12-17T22:13:23.106619263Z 62 PC: 13245 | Close file
2018-12-17T22:13:23.125891847Z 78 PC: 12fe6 | Find first file
2018-12-17T22:13:23.13215873Z 71 PC: 131c0 | Get current directory
2018-12-17T22:13:23.135550587Z 14 PC: 131c7 | Set default drive (Drive = 'C')
2018-12-17T22:13:23.138157214Z 59 PC: 131d0 | Change current directory
2018-12-17T22:13:23.144142842Z 78 PC: 12fe6 | Find first file
2018-12-17T22:13:23.153120206Z 61 PC: 136b9 | Open file (Filename = 'EDIT.COM')
2018-12-17T22:13:23.161120786Z 63 PC: 136db | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:13:23.166664911Z 66 PC: 13048 | Move file pointer
2018-12-17T22:13:23.170832139Z 64 PC: 13ab0 | Write file or device (Write 3072 bytes on handle 5)
2018-12-17T22:13:23.526532669Z 66 PC: 135bb | Move file pointer
2018-12-17T22:13:23.528757168Z 64 PC: 136cc | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:13:23.540861614Z 87 PC: 131f9 | Get or set file date and time
2018-12-17T22:13:23.542787849Z 65 PC: 1311a | Delete file (Filename = 'CHKLIST.MS')
2018-12-17T22:13:23.552276959Z 62 PC: 13245 | Close file
2018-12-17T22:13:23.55923483Z 78 PC: 12fe6 | Find first file
2018-12-17T22:13:23.565398883Z 61 PC: 136b9 | Open file (Filename = 'ATTRIB.EXE')
2018-12-17T22:13:23.572737592Z 63 PC: 13021 | Read file or device (Read 40 bytes on handle 5)
2018-12-17T22:13:23.579452323Z 66 PC: 13048 | Move file pointer
2018-12-17T22:13:23.583389003Z 64 PC: 13ab0 | Write file or device (Write 3072 bytes on handle 5)
2018-12-17T22:13:23.592902129Z 66 PC: 135bb | Move file pointer
2018-12-17T22:13:23.594391708Z 64 PC: 1310d | Write file or device (Write 40 bytes on handle 5)
2018-12-17T22:13:23.597426683Z 87 PC: 131f9 | Get or set file date and time
2018-12-17T22:13:23.599462444Z 65 PC: 1311a | Delete file (Filename = 'CHKLIST.MS')
2018-12-17T22:13:23.605301066Z 62 PC: 13245 | Close file
2018-12-17T22:13:23.616485969Z 14 PC: 131e0 | Set default drive (Drive = 'A')
2018-12-17T22:13:23.618457493Z 59 PC: 131e9 | Change current directory
2018-12-17T22:13:23.62237107Z 26 PC: 13161 | Set disk transfer address