Sample viewer

vx.netlux.org/Virus.DOS.Mini.75.d

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:30:09.302244181Z 78 PC: 12a5a | Find first file
2018-12-17T22:30:09.308760099Z 61 PC: 12a65 | Open file (Filename = '')
2018-12-17T22:30:09.334166831Z 63 PC: 12a6f | Read file or device (Read 65530 bytes on handle 5)
2018-12-17T22:30:09.341436879Z 66 PC: 12a7b | Move file pointer
2018-12-17T22:30:09.343238475Z 64 PC: 12a82 | Write file or device (Write 482 bytes on handle 5)
2018-12-17T22:30:09.354144786Z 79 PC: 12a5a | Find next file
2018-12-17T22:30:09.372876456Z 61 PC: 12a65 | Open file (Filename = '')
2018-12-17T22:30:09.380491733Z 63 PC: 12a6f | Read file or device (Read 65530 bytes on handle 6)
2018-12-17T22:30:09.389026019Z 66 PC: 12a7b | Move file pointer
2018-12-17T22:30:09.390978156Z 64 PC: 12a82 | Write file or device (Write 102 bytes on handle 6)
2018-12-17T22:30:09.394338177Z 79 PC: 12a5a | Find next file
2018-12-17T22:30:09.398521709Z 61 PC: 12a65 | Open file (Filename = '')
2018-12-17T22:30:09.407227358Z 63 PC: 12a6f | Read file or device (Read 65530 bytes on handle 7)
2018-12-17T22:30:09.425168894Z 66 PC: 12a7b | Move file pointer
2018-12-17T22:30:09.426805976Z 64 PC: 12a82 | Write file or device (Write 167 bytes on handle 7)
2018-12-17T22:30:09.430135781Z 79 PC: 12a5a | Find next file
2018-12-17T22:30:09.432990178Z 61 PC: 12a65 | Open file (Filename = '')
2018-12-17T22:30:09.440210524Z 63 PC: 12a6f | Read file or device (Read 65530 bytes on handle 8)
2018-12-17T22:30:09.447730088Z 66 PC: 12a7b | Move file pointer
2018-12-17T22:30:09.44929493Z 64 PC: 12a82 | Write file or device (Write 104 bytes on handle 8)
2018-12-17T22:30:09.452561748Z 79 PC: 12a5a | Find next file
2018-12-17T22:30:09.456175015Z 61 PC: 12a65 | Open file (Filename = '')
2018-12-17T22:30:09.464364145Z 63 PC: 12a6f | Read file or device (Read 65530 bytes on handle 9)
2018-12-17T22:30:09.471950853Z 66 PC: 12a7b | Move file pointer
2018-12-17T22:30:09.475029756Z 64 PC: 12a82 | Write file or device (Write 104 bytes on handle 9)
2018-12-17T22:30:09.478123168Z 79 PC: 12a5a | Find next file
2018-12-17T22:30:09.481757676Z 61 PC: 12a65 | Open file (Filename = '')
2018-12-17T22:30:09.489871592Z 63 PC: 12a6f | Read file or device (Read 65530 bytes on handle 10)
2018-12-17T22:30:09.497767849Z 66 PC: 12a7b | Move file pointer
2018-12-17T22:30:09.499392235Z 64 PC: 12a82 | Write file or device (Write 576 bytes on handle 10)
2018-12-17T22:30:09.514844288Z 79 PC: 12a5a | Find next file
2018-12-17T22:30:09.518949871Z 61 PC: 12a65 | Open file (Filename = '')
2018-12-17T22:30:09.526996041Z 63 PC: 12a6f | Read file or device (Read 65530 bytes on handle 11)
2018-12-17T22:30:09.535750112Z 66 PC: 12a7b | Move file pointer
2018-12-17T22:30:09.538557075Z 64 PC: 12a82 | Write file or device (Write 104 bytes on handle 11)
2018-12-17T22:30:09.542256633Z 79 PC: 12a5a | Find next file
2018-12-17T22:30:09.545711533Z 61 PC: 12a65 | Open file (Filename = '')
2018-12-17T22:30:09.554209562Z 63 PC: 12a6f | Read file or device (Read 65530 bytes on handle 12)
2018-12-17T22:30:09.557794927Z 66 PC: 12a7b | Move file pointer
2018-12-17T22:30:09.559729365Z 64 PC: 12a82 | Write file or device (Write 151 bytes on handle 12)
2018-12-17T22:30:09.563662557Z 79 PC: 12a5a | Find next file
2018-12-17T22:30:09.574357167Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:30:09.576129618Z 72 PC: 12174 | Allocate memory
2018-12-17T22:30:09.579279381Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:30:09.58226701Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T22:30:09.586834688Z 2 PC: 1268d | Character output (Char = '4d')
2018-12-17T22:30:09.589615226Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:30:09.593074905Z 2 PC: 1268d | Character output (Char = '6d')
2018-12-17T22:30:09.595622332Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:30:09.598107158Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:30:09.601144475Z 2 PC: 1268d | Character output (Char = '79')
2018-12-17T22:30:09.6036696Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:30:09.607047839Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:30:09.610781372Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:30:09.613296648Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:30:09.616200905Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:30:09.61913973Z 2 PC: 1268d | Character output (Char = '63')
2018-12-17T22:30:09.621496388Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:30:09.623804748Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:30:09.626786022Z 2 PC: 1268d | Character output (Char = '69')
2018-12-17T22:30:09.629588653Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:30:09.632547602Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:30:09.638277418Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:30:09.640459768Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:30:09.642852853Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:30:09.645561625Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:30:09.648454717Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:30:09.650317559Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:30:09.652487272Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:30:09.655111601Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T22:30:09.657919811Z 2 PC: 1268d | Character output (Char = '43')
2018-12-17T22:30:09.65977092Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:30:09.66230903Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:30:09.664363913Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:30:09.667631324Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:30:09.670036443Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:30:09.671858848Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:30:09.674171772Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:30:09.676397056Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:30:09.678243841Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:30:09.680262419Z 2 PC: 1268d | Character output (Char = '64')
2018-12-17T22:30:09.684479429Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:30:09.686049128Z 2 PC: 1268d | Character output (Char = '43')
2018-12-17T22:30:09.688413797Z 2 PC: 1268d | Character output (Char = '4f')
2018-12-17T22:30:09.690779575Z 2 PC: 1268d | Character output (Char = '4d')
2018-12-17T22:30:09.693440999Z 2 PC: 1268d | Character output (Char = '4d')
2018-12-17T22:30:09.695270545Z 2 PC: 1268d | Character output (Char = '41')
2018-12-17T22:30:09.698314275Z 2 PC: 1268d | Character output (Char = '4e')
2018-12-17T22:30:09.701710685Z 2 PC: 1268d | Character output (Char = '44')
2018-12-17T22:30:09.704882982Z 2 PC: 1268d | Character output (Char = '2c')
2018-12-17T22:30:09.708013384Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:30:09.711406379Z 2 PC: 1268d | Character output (Char = '73')
2018-12-17T22:30:09.714264937Z 2 PC: 1268d | Character output (Char = '79')
2018-12-17T22:30:09.717191585Z 2 PC: 1268d | Character output (Char = '73')
2018-12-17T22:30:09.720414335Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:30:09.723675865Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:30:09.726562361Z 2 PC: 1268d | Character output (Char = '6d')
2018-12-17T22:30:09.729764656Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:30:09.732283361Z 2 PC: 1268d | Character output (Char = '68')
2018-12-17T22:30:09.735107086Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:30:09.739938421Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:30:09.743075524Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:30:09.745962417Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:30:09.749640911Z 2 PC: 1268d | Character output (Char = '64')
2018-12-17T22:30:09.752100268Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:30:09.754851443Z 2 PC: 1268d | Character output (Char = '0a')