Sample viewer

vx.netlux.org/Virus.DOS.Wormsign.1572

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:28:01.801855314Z 47 PC: 12da6 | Get disk transfer address
2018-12-17T22:28:01.80352965Z 26 PC: 12db7 | Set disk transfer address
2018-12-17T22:28:01.804693224Z 9 PC: 12dc0 | Display string (String= 'Wormsign ! ')
2018-12-17T22:28:01.808507908Z 25 PC: 12df0 | Get default drive
2018-12-17T22:28:01.810407885Z 78 PC: 12e05 | Find first file
2018-12-17T22:28:01.816927305Z 79 PC: 13026 | Find next file
2018-12-17T22:28:01.820024916Z 79 PC: 13026 | Find next file
2018-12-17T22:28:01.823125129Z 79 PC: 13026 | Find next file
2018-12-17T22:28:01.825850143Z 79 PC: 13026 | Find next file
2018-12-17T22:28:01.828995437Z 79 PC: 13026 | Find next file
2018-12-17T22:28:01.832348503Z 79 PC: 13026 | Find next file
2018-12-17T22:28:01.835019843Z 79 PC: 13026 | Find next file
2018-12-17T22:28:01.838658666Z 67 PC: 12e2c | Get or set file attributes
2018-12-17T22:28:01.844351063Z 67 PC: 12e37 | Get or set file attributes
2018-12-17T22:28:01.861591142Z 61 PC: 12e41 | Open file (Filename = 'TEST.COM')
2018-12-17T22:28:01.869908723Z 82 PC: 12e4e | Get DOS internal pointers (SYSVARS)
2018-12-17T22:28:01.871049957Z 63 PC: 12e6a | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:28:01.873576852Z 62 PC: 1300a | Close file
2018-12-17T22:28:01.877051488Z 67 PC: 13018 | Get or set file attributes
2018-12-17T22:28:01.887141373Z 79 PC: 13026 | Find next file
2018-12-17T22:28:01.889674949Z 14 PC: 1304c | Set default drive (Drive = 'A')
2018-12-17T22:28:01.891274742Z 26 PC: 1305b | Set disk transfer address