Sample viewer

vx.netlux.org/Virus.DOS.Wormsign.1709

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:20:17.445796831Z 47 PC: 12da0 | Get disk transfer address
2018-12-17T22:20:17.449258619Z 26 PC: 12db1 | Set disk transfer address
2018-12-17T22:20:17.450708352Z 9 PC: 12dba | Display string (String= 'Wormsign ! ')
2018-12-17T22:20:17.454838147Z 25 PC: 12dea | Get default drive
2018-12-17T22:20:17.456215182Z 78 PC: 12dff | Find first file
2018-12-17T22:20:17.46352744Z 79 PC: 13010 | Find next file
2018-12-17T22:20:17.466438307Z 79 PC: 13010 | Find next file
2018-12-17T22:20:17.469195425Z 79 PC: 13010 | Find next file
2018-12-17T22:20:17.47357915Z 79 PC: 13010 | Find next file
2018-12-17T22:20:17.477269296Z 79 PC: 13010 | Find next file
2018-12-17T22:20:17.480397245Z 79 PC: 13010 | Find next file
2018-12-17T22:20:17.485290913Z 79 PC: 13010 | Find next file
2018-12-17T22:20:17.488169959Z 67 PC: 12e26 | Get or set file attributes
2018-12-17T22:20:17.494853154Z 67 PC: 12e31 | Get or set file attributes
2018-12-17T22:20:17.51355036Z 61 PC: 12e3b | Open file (Filename = 'TEST.COM')
2018-12-17T22:20:17.529845212Z 63 PC: 12e54 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:20:17.535961464Z 62 PC: 12ff4 | Close file
2018-12-17T22:20:17.538476975Z 67 PC: 13002 | Get or set file attributes
2018-12-17T22:20:17.568352306Z 79 PC: 13010 | Find next file
2018-12-17T22:20:17.570069829Z 14 PC: 13036 | Set default drive (Drive = 'A')
2018-12-17T22:20:17.571278142Z 26 PC: 13045 | Set disk transfer address