Sample viewer

vx.netlux.org/Virus.DOS.WilliWonka.1088

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:25:32.056859781Z 53 PC: 14154 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:25:32.058792312Z 37 PC: 14154 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:25:32.0600182Z 37 PC: 9f8d8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:25:32.061016602Z 67 PC: 9faf4 | Get or set file attributes
2018-12-17T22:25:32.065253604Z 67 PC: 9faf4 | Get or set file attributes
2018-12-17T22:25:32.078177Z 61 PC: 9faf4 | Open file (Filename = '&8uv�')
2018-12-17T22:25:32.088516466Z 87 PC: 9faf4 | Get or set file date and time
2018-12-17T22:25:32.092700818Z 66 PC: 9faf4 | Move file pointer
2018-12-17T22:25:32.094708972Z 63 PC: 9faf4 | Read file or device (Read 24 bytes on handle 5)
2018-12-17T22:25:32.097684302Z 66 PC: 9faf4 | Move file pointer
2018-12-17T22:25:32.099631813Z 64 PC: 9faf4 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:25:32.10297951Z 66 PC: 9faf4 | Move file pointer
2018-12-17T22:25:32.108347456Z 64 PC: 9faf4 | Write file or device (Write 10 bytes on handle 5)
2018-12-17T22:25:32.111569388Z 66 PC: 9faf4 | Move file pointer
2018-12-17T22:25:32.113840052Z 64 PC: 9faf4 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:25:32.122635057Z 87 PC: 9faf4 | Get or set file date and time
2018-12-17T22:25:32.12590677Z 62 PC: 9faf4 | Close file
2018-12-17T22:25:32.14957061Z 67 PC: 9faf4 | Get or set file attributes
2018-12-17T22:25:32.159720986Z 53 PC: 13292 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:32.160946268Z 53 PC: 13292 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:25:32.163374176Z 53 PC: 13292 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:25:32.164641431Z 53 PC: 13292 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:25:32.165836297Z 53 PC: 13292 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:25:32.170004876Z 53 PC: 13292 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:25:32.171148855Z 53 PC: 13292 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:25:32.172306919Z 53 PC: 13292 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:25:32.174385538Z 53 PC: 13292 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:25:32.17576127Z 53 PC: 13292 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:25:32.177162701Z 53 PC: 13292 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:25:32.18205043Z 53 PC: 13292 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:25:32.18432513Z 53 PC: 13292 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:25:32.186422017Z 53 PC: 13292 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:25:32.189113213Z 53 PC: 13292 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:25:32.190287923Z 53 PC: 13292 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:25:32.191421056Z 53 PC: 13292 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:25:32.192739441Z 53 PC: 13292 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:25:32.194432124Z 53 PC: 13292 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:25:32.195654138Z 37 PC: 132a7 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:32.196794056Z 37 PC: 132af | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:25:32.198455231Z 37 PC: 132b7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:25:32.199526265Z 37 PC: 132bf | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:25:32.201001592Z 68 PC: 1362f | I/O control for devices (Set for = '')
2018-12-17T22:25:32.267380371Z 37 PC: 12cb5 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:25:32.26924667Z 25 PC: 13cc6 | Get default drive
2018-12-17T22:25:32.270526403Z 71 PC: 13cd9 | Get current directory
2018-12-17T22:25:32.27497346Z 59 PC: 13d8d | Change current directory
2018-12-17T22:25:32.280934188Z 14 PC: 13d1f | Set default drive (Drive = 'A')
2018-12-17T22:25:32.28224574Z 25 PC: 13d23 | Get default drive
2018-12-17T22:25:32.284652562Z 59 PC: 13d8d | Change current directory
2018-12-17T22:25:32.45115695Z 37 PC: 133a6 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:25:32.453073861Z 37 PC: 133a6 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:25:32.456617831Z 37 PC: 133a6 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:25:32.458112647Z 37 PC: 133a6 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:25:32.459174189Z 37 PC: 133a6 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:25:32.460853254Z 37 PC: 133a6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:25:32.461981355Z 37 PC: 133a6 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:25:32.463058495Z 37 PC: 133a6 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:25:32.465152867Z 37 PC: 133a6 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:25:32.466446392Z 37 PC: 133a6 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:25:32.467407394Z 37 PC: 133a6 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:25:32.469379344Z 37 PC: 133a6 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:25:32.470529564Z 37 PC: 133a6 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:25:32.471644823Z 37 PC: 133a6 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:25:32.473395959Z 37 PC: 133a6 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:25:32.474535286Z 37 PC: 133a6 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:25:32.475535284Z 37 PC: 133a6 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:25:32.487315766Z 37 PC: 133a6 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:25:32.488516745Z 37 PC: 133a6 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:25:32.489552058Z 76 PC: 133e5 | Terminate with return code (Return code = '0')
2018-12-17T22:25:32.491839279Z 37 PC: 9f8d8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:25:32.493288483Z 67 PC: 9faf4 | Get or set file attributes
2018-12-17T22:25:32.497143869Z 67 PC: 9faf4 | Get or set file attributes
2018-12-17T22:25:32.504346316Z 61 PC: 9faf4 | Open file (Filename = '')
2018-12-17T22:25:32.509418027Z 87 PC: 9faf4 | Get or set file date and time
2018-12-17T22:25:32.510654637Z 66 PC: 9faf4 | Move file pointer
2018-12-17T22:25:32.511926065Z 63 PC: 9faf4 | Read file or device (Read 24 bytes on handle 5)
2018-12-17T22:25:32.514904873Z 66 PC: 9faf4 | Move file pointer
2018-12-17T22:25:32.516109904Z 63 PC: 9faf4 | Read file or device (Read 10 bytes on handle 5)
2018-12-17T22:25:32.517955537Z 66 PC: 9faf4 | Move file pointer
2018-12-17T22:25:32.519869898Z 66 PC: 9faf4 | Move file pointer
2018-12-17T22:25:32.521322283Z 64 PC: 9faf4 | Write file or device (Write 24 bytes on handle 5)
2018-12-17T22:25:32.523324017Z 66 PC: 9faf4 | Move file pointer
2018-12-17T22:25:32.525353364Z 64 PC: 9faf4 | Write file or device (Write 1088 bytes on handle 5)
2018-12-17T22:25:32.532623173Z 87 PC: 9faf4 | Get or set file date and time
2018-12-17T22:25:32.533949314Z 62 PC: 9faf4 | Close file
2018-12-17T22:25:32.553694067Z 67 PC: 9faf4 | Get or set file attributes