Sample viewer

vx.netlux.org/Virus.DOS.DKiller.Clouds.657

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:29:31.591782356Z 26 PC: 12aa3 | Set disk transfer address
2018-12-17T22:29:31.593240553Z 53 PC: 12aa8 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:31.594287063Z 37 PC: 12abd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:31.595218377Z 78 PC: 12ac8 | Find first file
2018-12-17T22:29:31.602536115Z 61 PC: 12ad9 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:29:31.60878844Z 63 PC: 12aeb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:29:31.614792269Z 66 PC: 12b08 | Move file pointer
2018-12-17T22:29:31.616212502Z 64 PC: 12b21 | Write file or device (Write 657 bytes on handle 5)
2018-12-17T22:29:31.644681671Z 66 PC: 12b2f | Move file pointer
2018-12-17T22:29:31.645861893Z 64 PC: 12b3f | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:29:31.65246615Z 62 PC: 12b48 | Close file
2018-12-17T22:29:31.660475938Z 79 PC: 12b4c | Find next file
2018-12-17T22:29:31.663164028Z 61 PC: 12ad9 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:29:31.669961625Z 63 PC: 12aeb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:29:31.685470918Z 66 PC: 12b08 | Move file pointer
2018-12-17T22:29:31.687237542Z 64 PC: 12b21 | Write file or device (Write 657 bytes on handle 5)
2018-12-17T22:29:31.696122717Z 66 PC: 12b2f | Move file pointer
2018-12-17T22:29:31.6984517Z 64 PC: 12b3f | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:29:31.704708345Z 62 PC: 12b48 | Close file
2018-12-17T22:29:31.712523791Z 79 PC: 12b4c | Find next file
2018-12-17T22:29:31.715480968Z 61 PC: 12ad9 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:29:31.722310275Z 63 PC: 12aeb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:29:31.728570774Z 66 PC: 12b08 | Move file pointer
2018-12-17T22:29:31.730753181Z 64 PC: 12b21 | Write file or device (Write 657 bytes on handle 5)
2018-12-17T22:29:31.738502756Z 66 PC: 12b2f | Move file pointer
2018-12-17T22:29:31.740267916Z 64 PC: 12b3f | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:29:31.74789154Z 62 PC: 12b48 | Close file
2018-12-17T22:29:31.756108042Z 79 PC: 12b4c | Find next file
2018-12-17T22:29:31.75898086Z 61 PC: 12ad9 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:29:31.766839436Z 63 PC: 12aeb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:29:31.773372386Z 66 PC: 12b08 | Move file pointer
2018-12-17T22:29:31.775366928Z 64 PC: 12b21 | Write file or device (Write 657 bytes on handle 5)
2018-12-17T22:29:31.783501506Z 66 PC: 12b2f | Move file pointer
2018-12-17T22:29:31.785627609Z 64 PC: 12b3f | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:29:31.79269063Z 62 PC: 12b48 | Close file
2018-12-17T22:29:31.800824392Z 79 PC: 12b4c | Find next file
2018-12-17T22:29:31.804459124Z 61 PC: 12ad9 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:29:31.811142747Z 63 PC: 12aeb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:29:31.817908365Z 66 PC: 12b08 | Move file pointer
2018-12-17T22:29:31.820744262Z 64 PC: 12b21 | Write file or device (Write 657 bytes on handle 5)
2018-12-17T22:29:31.828920153Z 66 PC: 12b2f | Move file pointer
2018-12-17T22:29:31.83027848Z 64 PC: 12b3f | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:29:31.837646177Z 62 PC: 12b48 | Close file
2018-12-17T22:29:31.846071326Z 79 PC: 12b4c | Find next file
2018-12-17T22:29:31.849139697Z 61 PC: 12ad9 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:29:31.856418596Z 63 PC: 12aeb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:29:31.865788507Z 66 PC: 12b08 | Move file pointer
2018-12-17T22:29:31.867539805Z 64 PC: 12b21 | Write file or device (Write 657 bytes on handle 5)
2018-12-17T22:29:31.876499833Z 66 PC: 12b2f | Move file pointer
2018-12-17T22:29:31.878460589Z 64 PC: 12b3f | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:29:31.8849462Z 62 PC: 12b48 | Close file
2018-12-17T22:29:31.893376345Z 79 PC: 12b4c | Find next file
2018-12-17T22:29:31.896502319Z 61 PC: 12ad9 | Open file (Filename = 'PAH.COM')
2018-12-17T22:29:31.90376375Z 63 PC: 12aeb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:29:31.910818209Z 66 PC: 12b08 | Move file pointer
2018-12-17T22:29:31.913203203Z 64 PC: 12b21 | Write file or device (Write 657 bytes on handle 5)
2018-12-17T22:29:31.921390038Z 66 PC: 12b2f | Move file pointer
2018-12-17T22:29:31.923278302Z 64 PC: 12b3f | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:29:31.931159904Z 62 PC: 12b48 | Close file
2018-12-17T22:29:31.93914839Z 79 PC: 12b4c | Find next file
2018-12-17T22:29:31.942024642Z 61 PC: 12ad9 | Open file (Filename = 'TEST.COM')
2018-12-17T22:29:31.949352402Z 63 PC: 12aeb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:29:31.951940941Z 62 PC: 12b48 | Close file
2018-12-17T22:29:31.953678669Z 79 PC: 12b4c | Find next file
2018-12-17T22:29:31.957116208Z 26 PC: 12b5b | Set disk transfer address
2018-12-17T22:29:31.95849088Z 37 PC: 12b6c | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:31.959663206Z 9 PC: 12a47 | Display string (String= 'This is Virus, Written By Dark Killer. ')