Sample viewer

vx.netlux.org/Virus.DOS.V.416

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:25:34.438632648Z 47 PC: 12a8d | Get disk transfer address
2018-12-17T22:25:34.440644184Z 53 PC: 12a94 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:25:34.441995385Z 37 PC: 12a9e | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:25:34.443366923Z 26 PC: 12a51 | Set disk transfer address
2018-12-17T22:25:34.444694866Z 17 PC: 12ad2 | Find first file
2018-12-17T22:25:34.4523484Z 15 PC: 12af5 | Open file (Filename = 'SLEEP COM dLLL/3۸/A > U/ u &6&&&&&e!c!6  y/%s/!'+fP&ÕJ!X!Z!!+£`, t0')
2018-12-17T22:25:34.458979126Z 26 PC: 12a51 | Set disk transfer address
2018-12-17T22:25:34.460194882Z 39 PC: 12b18 | Random block read
2018-12-17T22:25:34.467679887Z 16 PC: 12b8e | Close file
2018-12-17T22:25:34.47007427Z 26 PC: 12a51 | Set disk transfer address
2018-12-17T22:25:34.471162679Z 18 PC: 12ad2 | Find next file
2018-12-17T22:25:34.485608981Z 15 PC: 12af5 | Open file (Filename = 'PRINT COM "M"M f8L!gfT$ !fô U/ u &6&&&&&e!c!6  y/%s/!'+fP&ÕJ!X!Z!!+£`, t0')
2018-12-17T22:25:34.492345274Z 26 PC: 12a51 | Set disk transfer address
2018-12-17T22:25:34.49332539Z 39 PC: 12b18 | Random block read
2018-12-17T22:25:34.50130303Z 16 PC: 12b8e | Close file
2018-12-17T22:25:34.504052591Z 26 PC: 12a51 | Set disk transfer address
2018-12-17T22:25:34.505085865Z 18 PC: 12ad2 | Find next file
2018-12-17T22:25:34.5087226Z 15 PC: 12af5 | Open file (Filename = 'HELLO COM dLLL \  !L!Hello, World! U/ u &6&&&&&e!c!6  y/%s/!'+fP&ÕJ!X!Z!!+£`, t0')
2018-12-17T22:25:34.515439817Z 26 PC: 12a51 | Set disk transfer address
2018-12-17T22:25:34.516447067Z 39 PC: 12b18 | Random block read
2018-12-17T22:25:34.523991065Z 16 PC: 12b8e | Close file
2018-12-17T22:25:34.527590149Z 26 PC: 12a51 | Set disk transfer address
2018-12-17T22:25:34.528825127Z 18 PC: 12ad2 | Find next file
2018-12-17T22:25:34.531928741Z 15 PC: 12af5 | Open file (Filename = 'PHANG COM rLLrL fL!f !! U/ u &6&&&&&e!c!6  y/%s/!'+fP&ÕJ!X!Z!!+£`, t0')
2018-12-17T22:25:34.538721126Z 26 PC: 12a51 | Set disk transfer address
2018-12-17T22:25:34.53995476Z 39 PC: 12b18 | Random block read
2018-12-17T22:25:34.547176749Z 16 PC: 12b8e | Close file
2018-12-17T22:25:34.549391385Z 26 PC: 12a51 | Set disk transfer address
2018-12-17T22:25:34.55115748Z 18 PC: 12ad2 | Find next file
2018-12-17T22:25:34.553545982Z 15 PC: 12af5 | Open file (Filename = 'PRINTA~1COM MM  !L!Hello, Worl U/ u &6&&&&&e!c!6  y/%s/!'+fP&ÕJ!X!Z!!+£`, t0')
2018-12-17T22:25:34.560081442Z 26 PC: 12a51 | Set disk transfer address
2018-12-17T22:25:34.569084999Z 39 PC: 12b18 | Random block read
2018-12-17T22:25:34.576269769Z 16 PC: 12b8e | Close file
2018-12-17T22:25:34.578520735Z 26 PC: 12a51 | Set disk transfer address
2018-12-17T22:25:34.580171533Z 18 PC: 12ad2 | Find next file
2018-12-17T22:25:34.582500483Z 15 PC: 12af5 | Open file (Filename = 'MANDEL COM (M(M  !L!Hello, Worl U/ u &6&&&&&e!c!6  y/%s/!'+fP&ÕJ!X!Z!!+£`, t0')
2018-12-17T22:25:34.58898768Z 26 PC: 12a51 | Set disk transfer address
2018-12-17T22:25:34.590561852Z 39 PC: 12b18 | Random block read
2018-12-17T22:25:34.597653584Z 16 PC: 12b8e | Close file
2018-12-17T22:25:34.599799872Z 26 PC: 12a51 | Set disk transfer address
2018-12-17T22:25:34.602094814Z 18 PC: 12ad2 | Find next file
2018-12-17T22:25:34.604540718Z 15 PC: 12af5 | Open file (Filename = 'PAH COM MOO U/ u &6&&&&&e!c!6  y/%s/!'+fP&ÕJ!X!Z!!+£`, t0')
2018-12-17T22:25:34.611130981Z 26 PC: 12a51 | Set disk transfer address
2018-12-17T22:25:34.612614798Z 39 PC: 12b18 | Random block read
2018-12-17T22:25:34.619843766Z 16 PC: 12b8e | Close file
2018-12-17T22:25:34.62210117Z 26 PC: 12a51 | Set disk transfer address
2018-12-17T22:25:34.62544377Z 18 PC: 12ad2 | Find next file
2018-12-17T22:25:34.627410408Z 15 PC: 12af5 | Open file (Filename = 'TEST COM 9M9M  !L!Hello, Worl U/ u &6&&&&&e!c!6  y/%s/!'+fP&ÕJ!X!Z!!+£`, t0')
2018-12-17T22:25:34.634476157Z 26 PC: 12a51 | Set disk transfer address
2018-12-17T22:25:34.637045084Z 39 PC: 12b18 | Random block read
2018-12-17T22:25:34.64111124Z 16 PC: 12b8e | Close file
2018-12-17T22:25:34.643740355Z 26 PC: 12a51 | Set disk transfer address
2018-12-17T22:25:34.645721465Z 18 PC: 12ad2 | Find next file
2018-12-17T22:25:34.648119861Z 37 PC: 12adb | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:25:34.649326716Z 26 PC: 12a51 | Set disk transfer address