Sample viewer

vx.netlux.org/Virus.DOS.CivilWar.144

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:52:39.91880096Z 26 PC: 12a59 | Set disk transfer address
2018-12-17T21:52:39.920165413Z 78 PC: 12a61 | Find first file
2018-12-17T21:52:39.925803578Z 61 PC: 12a6c | Open file (Filename = 'SLEEP.COM')
2018-12-17T21:52:39.932142739Z 63 PC: 12a7a | Read file or device (Read 4 bytes on handle 5)
2018-12-17T21:52:39.938708854Z 66 PC: 12a89 | Move file pointer
2018-12-17T21:52:39.940100796Z 64 PC: 12a9b | Write file or device (Write 144 bytes on handle 5)
2018-12-17T21:52:39.953268754Z 66 PC: 12aa3 | Move file pointer
2018-12-17T21:52:39.955307602Z 64 PC: 12aae | Write file or device (Write 4 bytes on handle 5)
2018-12-17T21:52:39.96167862Z 62 PC: 12ab2 | Close file
2018-12-17T21:52:39.969431271Z 79 PC: 12a61 | Find next file
2018-12-17T21:52:39.972840925Z 61 PC: 12a6c | Open file (Filename = 'PRINT.COM')
2018-12-17T21:52:39.977014554Z 63 PC: 12a7a | Read file or device (Read 4 bytes on handle 5)
2018-12-17T21:52:39.980832416Z 66 PC: 12a89 | Move file pointer
2018-12-17T21:52:39.981775508Z 64 PC: 12a9b | Write file or device (Write 144 bytes on handle 5)
2018-12-17T21:52:39.984775103Z 66 PC: 12aa3 | Move file pointer
2018-12-17T21:52:39.985997661Z 64 PC: 12aae | Write file or device (Write 4 bytes on handle 5)
2018-12-17T21:52:39.988335933Z 62 PC: 12ab2 | Close file
2018-12-17T21:52:39.995810999Z 79 PC: 12a61 | Find next file
2018-12-17T21:52:39.998347805Z 61 PC: 12a6c | Open file (Filename = 'HELLO.COM')
2018-12-17T21:52:40.004562719Z 63 PC: 12a7a | Read file or device (Read 4 bytes on handle 5)
2018-12-17T21:52:40.011043193Z 66 PC: 12a89 | Move file pointer
2018-12-17T21:52:40.012305528Z 64 PC: 12a9b | Write file or device (Write 144 bytes on handle 5)
2018-12-17T21:52:40.014878401Z 66 PC: 12aa3 | Move file pointer
2018-12-17T21:52:40.016548099Z 64 PC: 12aae | Write file or device (Write 4 bytes on handle 5)
2018-12-17T21:52:40.019045418Z 62 PC: 12ab2 | Close file
2018-12-17T21:52:40.026601412Z 79 PC: 12a61 | Find next file
2018-12-17T21:52:40.029495053Z 61 PC: 12a6c | Open file (Filename = 'PHANG.COM')
2018-12-17T21:52:40.036395451Z 63 PC: 12a7a | Read file or device (Read 4 bytes on handle 5)
2018-12-17T21:52:40.042693221Z 66 PC: 12a89 | Move file pointer
2018-12-17T21:52:40.044482073Z 64 PC: 12a9b | Write file or device (Write 144 bytes on handle 5)
2018-12-17T21:52:40.047088453Z 66 PC: 12aa3 | Move file pointer
2018-12-17T21:52:40.048353216Z 64 PC: 12aae | Write file or device (Write 4 bytes on handle 5)
2018-12-17T21:52:40.051159579Z 62 PC: 12ab2 | Close file
2018-12-17T21:52:40.05898536Z 79 PC: 12a61 | Find next file
2018-12-17T21:52:40.061379384Z 61 PC: 12a6c | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T21:52:40.068097103Z 63 PC: 12a7a | Read file or device (Read 4 bytes on handle 5)
2018-12-17T21:52:40.074135404Z 66 PC: 12a89 | Move file pointer
2018-12-17T21:52:40.075347522Z 64 PC: 12a9b | Write file or device (Write 144 bytes on handle 5)
2018-12-17T21:52:40.078340767Z 66 PC: 12aa3 | Move file pointer
2018-12-17T21:52:40.07957995Z 64 PC: 12aae | Write file or device (Write 4 bytes on handle 5)
2018-12-17T21:52:40.081959966Z 62 PC: 12ab2 | Close file
2018-12-17T21:52:40.089814965Z 79 PC: 12a61 | Find next file
2018-12-17T21:52:40.092254175Z 61 PC: 12a6c | Open file (Filename = 'MANDEL.COM')
2018-12-17T21:52:40.09847665Z 63 PC: 12a7a | Read file or device (Read 4 bytes on handle 5)
2018-12-17T21:52:40.10593188Z 66 PC: 12a89 | Move file pointer
2018-12-17T21:52:40.107197294Z 64 PC: 12a9b | Write file or device (Write 144 bytes on handle 5)
2018-12-17T21:52:40.114801121Z 66 PC: 12aa3 | Move file pointer
2018-12-17T21:52:40.116918412Z 64 PC: 12aae | Write file or device (Write 4 bytes on handle 5)
2018-12-17T21:52:40.123125202Z 62 PC: 12ab2 | Close file
2018-12-17T21:52:40.130919389Z 79 PC: 12a61 | Find next file
2018-12-17T21:52:40.133500671Z 61 PC: 12a6c | Open file (Filename = 'PAH.COM')
2018-12-17T21:52:40.140000377Z 63 PC: 12a7a | Read file or device (Read 4 bytes on handle 5)
2018-12-17T21:52:40.146135838Z 66 PC: 12a89 | Move file pointer
2018-12-17T21:52:40.147321445Z 64 PC: 12a9b | Write file or device (Write 144 bytes on handle 5)
2018-12-17T21:52:40.150068506Z 66 PC: 12aa3 | Move file pointer
2018-12-17T21:52:40.151275655Z 64 PC: 12aae | Write file or device (Write 4 bytes on handle 5)
2018-12-17T21:52:40.153630333Z 62 PC: 12ab2 | Close file
2018-12-17T21:52:40.161068783Z 79 PC: 12a61 | Find next file
2018-12-17T21:52:40.164142601Z 61 PC: 12a6c | Open file (Filename = 'TEST.COM')
2018-12-17T21:52:40.170241003Z 63 PC: 12a7a | Read file or device (Read 4 bytes on handle 5)
2018-12-17T21:52:40.172651832Z 66 PC: 12a89 | Move file pointer
2018-12-17T21:52:40.17388737Z 64 PC: 12a9b | Write file or device (Write 144 bytes on handle 5)
2018-12-17T21:52:40.176335522Z 66 PC: 12aa3 | Move file pointer
2018-12-17T21:52:40.177764983Z 64 PC: 12aae | Write file or device (Write 4 bytes on handle 5)
2018-12-17T21:52:40.180291229Z 62 PC: 12ab2 | Close file
2018-12-17T21:52:40.187645904Z 79 PC: 12a61 | Find next file
2018-12-17T21:52:40.189881035Z 26 PC: 12abd | Set disk transfer address