Sample viewer

vx.netlux.org/Virus.DOS.Zorm.1120

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:19:19.154931962Z 61 PC: 12b1e | Open file (Filename = 'Í ÀŸ')
2018-12-17T22:19:19.160491875Z 105 PC: 12b4b | Get or set media id
2018-12-17T22:19:19.161979871Z 74 PC: 12b5b | Reallocate memory
2018-12-17T22:19:19.163629319Z 74 PC: 12b63 | Reallocate memory
2018-12-17T22:19:19.16598142Z 72 PC: 12b6a | Allocate memory
2018-12-17T22:19:19.167823882Z 37 PC: 12bb3 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:19:19.171556144Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.172757982Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:19:19.181310137Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.182402572Z 72 PC: 12174 | Allocate memory
2018-12-17T22:19:19.18406538Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.19116572Z 72 PC: 1218d | Allocate memory
2018-12-17T22:19:19.193327731Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.19440181Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:19:19.196065038Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.197288887Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:19:19.198471367Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.200145378Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.201348605Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.20248576Z 62 PC: 122ab | Close file
2018-12-17T22:19:19.20438279Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.205402778Z 62 PC: 122ab | Close file
2018-12-17T22:19:19.20672404Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.208271066Z 62 PC: 122ab | Close file
2018-12-17T22:19:19.209700288Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.210688818Z 62 PC: 122ab | Close file
2018-12-17T22:19:19.21249381Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.213512778Z 62 PC: 122ab | Close file
2018-12-17T22:19:19.214807961Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.216581965Z 62 PC: 122ab | Close file
2018-12-17T22:19:19.217682273Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.218464417Z 62 PC: 122ab | Close file
2018-12-17T22:19:19.219873737Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.220898692Z 62 PC: 122ab | Close file
2018-12-17T22:19:19.222022092Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.223568408Z 62 PC: 122ab | Close file
2018-12-17T22:19:19.225014992Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.226027095Z 62 PC: 122ab | Close file
2018-12-17T22:19:19.227245277Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.229003596Z 62 PC: 122ab | Close file
2018-12-17T22:19:19.230620081Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.231543677Z 62 PC: 122ab | Close file
2018-12-17T22:19:19.234278112Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.234967358Z 62 PC: 122ab | Close file
2018-12-17T22:19:19.235853765Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.237479413Z 62 PC: 122ab | Close file
2018-12-17T22:19:19.23897034Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.240014077Z 62 PC: 122ab | Close file
2018-12-17T22:19:19.244460829Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.245599475Z 99 PC: 99c07 | Get DBCS lead byte table pointer
2018-12-17T22:19:19.246771801Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.248158855Z 56 PC: 94429 | Get or set country info
2018-12-17T22:19:19.249968603Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.250986187Z 64 PC: 99e78 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:19:19.256129327Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.257095573Z 25 PC: 94492 | Get default drive
2018-12-17T22:19:19.258284765Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.259885361Z 71 PC: 9670d | Get current directory
2018-12-17T22:19:19.262720645Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.263652182Z 64 PC: 99e78 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:19:19.26634468Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.267200171Z 2 PC: 966e2 | Character output (Char = '3e')
2018-12-17T22:19:19.268588449Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.26999356Z 93 PC: 94550 | File sharing functions
2018-12-17T22:19:19.271243881Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.272184051Z 93 PC: 94557 | File sharing functions
2018-12-17T22:19:19.274311311Z 37 PC: 9f3a8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:19.2754184Z 10 PC: 94569 | Buffered keyboard input