Sample viewer

vx.netlux.org/Virus.DOS.Intruder.1322

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:20:27.575149855Z 47 PC: 12ff6 | Get disk transfer address
2018-12-17T22:20:27.576824078Z 26 PC: 1300a | Set disk transfer address
2018-12-17T22:20:27.579367446Z 71 PC: 12cbb | Get current directory
2018-12-17T22:20:27.582906126Z 26 PC: 12d3a | Set disk transfer address
2018-12-17T22:20:27.584501534Z 78 PC: 12d4e | Find first file
2018-12-17T22:20:27.592578799Z 61 PC: 12df4 | Open file (Filename = '\TEST.EXE')
2018-12-17T22:20:27.610120906Z 63 PC: 12e05 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:20:27.617698367Z 66 PC: 12e36 | Move file pointer
2018-12-17T22:20:27.620995344Z 63 PC: 12e44 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:20:27.626066819Z 79 PC: 12d69 | Find next file
2018-12-17T22:20:27.62804584Z 26 PC: 12d7b | Set disk transfer address
2018-12-17T22:20:27.630936991Z 78 PC: 12d85 | Find first file
2018-12-17T22:20:27.636952779Z 26 PC: 12d9e | Set disk transfer address
2018-12-17T22:20:27.638338815Z 79 PC: 12da2 | Find next file
2018-12-17T22:20:27.641544022Z 26 PC: 12d9e | Set disk transfer address
2018-12-17T22:20:27.64747631Z 79 PC: 12da2 | Find next file
2018-12-17T22:20:27.650792314Z 26 PC: 12d9e | Set disk transfer address
2018-12-17T22:20:27.65210474Z 79 PC: 12da2 | Find next file
2018-12-17T22:20:27.659753566Z 26 PC: 12d9e | Set disk transfer address
2018-12-17T22:20:27.661088954Z 79 PC: 12da2 | Find next file
2018-12-17T22:20:27.664700961Z 26 PC: 12d9e | Set disk transfer address
2018-12-17T22:20:27.667085461Z 79 PC: 12da2 | Find next file
2018-12-17T22:20:27.670154573Z 26 PC: 12d9e | Set disk transfer address
2018-12-17T22:20:27.671455437Z 79 PC: 12da2 | Find next file
2018-12-17T22:20:27.675381884Z 26 PC: 12d9e | Set disk transfer address
2018-12-17T22:20:27.678022048Z 79 PC: 12da2 | Find next file
2018-12-17T22:20:27.681179985Z 26 PC: 12d9e | Set disk transfer address
2018-12-17T22:20:27.683146412Z 79 PC: 12da2 | Find next file
2018-12-17T22:20:27.686134917Z 26 PC: 12d9e | Set disk transfer address
2018-12-17T22:20:27.687245631Z 79 PC: 12da2 | Find next file
2018-12-17T22:20:27.690706432Z 26 PC: 12d3a | Set disk transfer address
2018-12-17T22:20:27.692302874Z 78 PC: 12d4e | Find first file
2018-12-17T22:20:27.700654788Z 61 PC: 12df4 | Open file (Filename = '\TEST.EXE')
2018-12-17T22:20:27.709548025Z 63 PC: 12e05 | Read file or device (Read 28 bytes on handle 6)
2018-12-17T22:20:27.712739226Z 66 PC: 12e36 | Move file pointer
2018-12-17T22:20:27.714948918Z 63 PC: 12e44 | Read file or device (Read 2 bytes on handle 6)
2018-12-17T22:20:27.718643228Z 79 PC: 12d69 | Find next file
2018-12-17T22:20:27.732327621Z 26 PC: 12d7b | Set disk transfer address
2018-12-17T22:20:27.737004789Z 78 PC: 12d85 | Find first file
2018-12-17T22:20:27.743900331Z 26 PC: 12d9e | Set disk transfer address
2018-12-17T22:20:27.747852856Z 79 PC: 12da2 | Find next file
2018-12-17T22:20:27.75081523Z 26 PC: 12d9e | Set disk transfer address
2018-12-17T22:20:27.752026647Z 79 PC: 12da2 | Find next file
2018-12-17T22:20:27.7557929Z 26 PC: 12d9e | Set disk transfer address
2018-12-17T22:20:27.757099939Z 79 PC: 12da2 | Find next file
2018-12-17T22:20:27.761112176Z 26 PC: 12d9e | Set disk transfer address
2018-12-17T22:20:27.76338227Z 79 PC: 12da2 | Find next file
2018-12-17T22:20:27.766594672Z 26 PC: 12d9e | Set disk transfer address
2018-12-17T22:20:27.768373227Z 79 PC: 12da2 | Find next file
2018-12-17T22:20:27.772126311Z 26 PC: 12d9e | Set disk transfer address
2018-12-17T22:20:27.774887922Z 79 PC: 12da2 | Find next file
2018-12-17T22:20:27.778670189Z 26 PC: 12d9e | Set disk transfer address
2018-12-17T22:20:27.781060965Z 79 PC: 12da2 | Find next file
2018-12-17T22:20:27.784632975Z 26 PC: 12d9e | Set disk transfer address
2018-12-17T22:20:27.787180652Z 79 PC: 12da2 | Find next file
2018-12-17T22:20:27.793243559Z 26 PC: 12d9e | Set disk transfer address
2018-12-17T22:20:27.795079969Z 79 PC: 12da2 | Find next file
2018-12-17T22:20:27.798835016Z 26 PC: 13018 | Set disk transfer address
2018-12-17T22:20:27.80177947Z 65 PC: 12a58 | Delete file (Filename = ' ')
2018-12-17T22:20:27.809874132Z 76 PC: 12a5d | Terminate with return code (Return code = '0')