Sample viewer

vx.netlux.org/Virus.DOS.VCC.Empire.573

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:31:20.984062187Z 26 PC: 12a61 | Set disk transfer address
2018-12-17T22:31:20.985226282Z 37 PC: 12a6c | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:31:20.987347868Z 37 PC: 12a70 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:31:20.989818572Z 78 PC: 12ab7 | Find first file
2018-12-17T22:31:21.000631464Z 61 PC: 12c2e | Open file (Filename = 'As')
2018-12-17T22:31:21.010895665Z 79 PC: 12ab7 | Find next file
2018-12-17T22:31:21.013796284Z 61 PC: 12c2e | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:31:21.022038927Z 63 PC: 12c3d | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:21.031341794Z 66 PC: 12c4c | Move file pointer
2018-12-17T22:31:21.033911004Z 66 PC: 12c5b | Move file pointer
2018-12-17T22:31:21.036499184Z 64 PC: 12c67 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:31:21.040109043Z 66 PC: 12c73 | Move file pointer
2018-12-17T22:31:21.043317021Z 64 PC: 12c7e | Write file or device (Write 573 bytes on handle 5)
2018-12-17T22:31:21.060651626Z 62 PC: 12c82 | Close file
2018-12-17T22:31:21.070270878Z 79 PC: 12ab7 | Find next file
2018-12-17T22:31:21.075075973Z 61 PC: 12c2e | Open file (Filename = 'PRINT.S')
2018-12-17T22:31:21.084266813Z 63 PC: 12c3d | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:21.092970339Z 66 PC: 12c4c | Move file pointer
2018-12-17T22:31:21.105180362Z 66 PC: 12c5b | Move file pointer
2018-12-17T22:31:21.107397249Z 64 PC: 12c67 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:31:21.110673553Z 66 PC: 12c73 | Move file pointer
2018-12-17T22:31:21.112577781Z 64 PC: 12c7e | Write file or device (Write 573 bytes on handle 5)
2018-12-17T22:31:21.122349435Z 62 PC: 12c82 | Close file
2018-12-17T22:31:21.131543684Z 79 PC: 12ab7 | Find next file
2018-12-17T22:31:21.134844548Z 61 PC: 12c2e | Open file (Filename = 'Ap')
2018-12-17T22:31:21.145416103Z 79 PC: 12ab7 | Find next file
2018-12-17T22:31:21.148893029Z 61 PC: 12c2e | Open file (Filename = 'PRINT.COM')
2018-12-17T22:31:21.158386941Z 63 PC: 12c3d | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:21.166910903Z 66 PC: 12c4c | Move file pointer
2018-12-17T22:31:21.168918666Z 66 PC: 12c5b | Move file pointer
2018-12-17T22:31:21.170838633Z 64 PC: 12c67 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:31:21.174856194Z 66 PC: 12c73 | Move file pointer
2018-12-17T22:31:21.176459811Z 64 PC: 12c7e | Write file or device (Write 573 bytes on handle 5)
2018-12-17T22:31:21.18522409Z 62 PC: 12c82 | Close file
2018-12-17T22:31:21.195556388Z 79 PC: 12ab7 | Find next file
2018-12-17T22:31:21.19888952Z 61 PC: 12c2e | Open file (Filename = 'Ah')
2018-12-17T22:31:21.205800643Z 79 PC: 12ab7 | Find next file
2018-12-17T22:31:21.209932396Z 61 PC: 12c2e | Open file (Filename = 'HELLO.COM')
2018-12-17T22:31:21.217360591Z 63 PC: 12c3d | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:21.224452795Z 66 PC: 12c4c | Move file pointer
2018-12-17T22:31:21.226285585Z 66 PC: 12c5b | Move file pointer
2018-12-17T22:31:21.235763667Z 64 PC: 12c67 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:31:21.238535443Z 66 PC: 12c73 | Move file pointer
2018-12-17T22:31:21.239812453Z 64 PC: 12c7e | Write file or device (Write 573 bytes on handle 5)
2018-12-17T22:31:21.246865344Z 62 PC: 12c82 | Close file
2018-12-17T22:31:21.253721343Z 79 PC: 12ab7 | Find next file
2018-12-17T22:31:21.255612101Z 61 PC: 12c2e | Open file (Filename = 'Ap')
2018-12-17T22:31:21.260562587Z 79 PC: 12ab7 | Find next file
2018-12-17T22:31:21.262637658Z 61 PC: 12c2e | Open file (Filename = 'PHANG.COM')
2018-12-17T22:31:21.267128077Z 63 PC: 12c3d | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:21.272199106Z 66 PC: 12c4c | Move file pointer
2018-12-17T22:31:21.273538732Z 66 PC: 12c5b | Move file pointer
2018-12-17T22:31:21.274851341Z 64 PC: 12c67 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:31:21.278402384Z 66 PC: 12c73 | Move file pointer
2018-12-17T22:31:21.279919299Z 64 PC: 12c7e | Write file or device (Write 573 bytes on handle 5)
2018-12-17T22:31:21.286476302Z 62 PC: 12c82 | Close file
2018-12-17T22:31:21.293151105Z 79 PC: 12ab7 | Find next file
2018-12-17T22:31:21.295690594Z 61 PC: 12c2e | Open file (Filename = 'Bc')
2018-12-17T22:31:21.299874855Z 79 PC: 12ab7 | Find next file
2018-12-17T22:31:21.302347367Z 61 PC: 12c2e | Open file (Filename = 'p')
2018-12-17T22:31:21.30579987Z 79 PC: 12ab7 | Find next file
2018-12-17T22:31:21.307934918Z 61 PC: 12c2e | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:31:21.312377998Z 63 PC: 12c3d | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:21.31710573Z 66 PC: 12c4c | Move file pointer
2018-12-17T22:31:21.318358113Z 66 PC: 12c5b | Move file pointer
2018-12-17T22:31:21.319500453Z 64 PC: 12c67 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:31:21.321845468Z 66 PC: 12c73 | Move file pointer
2018-12-17T22:31:21.323001062Z 64 PC: 12c7e | Write file or device (Write 573 bytes on handle 5)
2018-12-17T22:31:21.328379466Z 62 PC: 12c82 | Close file
2018-12-17T22:31:21.334632567Z 79 PC: 12ab7 | Find next file
2018-12-17T22:31:21.33656016Z 61 PC: 12c2e | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:31:21.348868659Z 63 PC: 12c3d | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:21.356372032Z 66 PC: 12c4c | Move file pointer
2018-12-17T22:31:21.357514338Z 66 PC: 12c5b | Move file pointer
2018-12-17T22:31:21.358833287Z 64 PC: 12c67 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:31:21.362612417Z 66 PC: 12c73 | Move file pointer
2018-12-17T22:31:21.364252952Z 64 PC: 12c7e | Write file or device (Write 573 bytes on handle 5)
2018-12-17T22:31:21.373193241Z 62 PC: 12c82 | Close file
2018-12-17T22:31:21.382405619Z 79 PC: 12ab7 | Find next file
2018-12-17T22:31:21.385288636Z 61 PC: 12c2e | Open file (Filename = 'PAH.COM')
2018-12-17T22:31:21.393124323Z 63 PC: 12c3d | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:21.400265293Z 66 PC: 12c4c | Move file pointer
2018-12-17T22:31:21.401974556Z 66 PC: 12c5b | Move file pointer
2018-12-17T22:31:21.403340586Z 64 PC: 12c67 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:31:21.407328203Z 66 PC: 12c73 | Move file pointer
2018-12-17T22:31:21.409061031Z 64 PC: 12c7e | Write file or device (Write 573 bytes on handle 5)
2018-12-17T22:31:21.417910145Z 62 PC: 12c82 | Close file
2018-12-17T22:31:21.427478956Z 79 PC: 12ab7 | Find next file
2018-12-17T22:31:21.430840686Z 61 PC: 12c2e | Open file (Filename = 'TEST.COM')
2018-12-17T22:31:21.437911373Z 63 PC: 12c3d | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:21.444994988Z 62 PC: 12c82 | Close file
2018-12-17T22:31:21.447671126Z 79 PC: 12ab7 | Find next file
2018-12-17T22:31:21.450532778Z 59 PC: 12ac8 | Change current directory
2018-12-17T22:31:21.455200508Z 26 PC: 12ad1 | Set disk transfer address
2018-12-17T22:31:21.457125542Z 9 PC: 12ae3 | Display string (String= ' No, I think thats right. The idea is this will prick the boil. It may not. The history of this thing has to be though that you did not tuck this under the rug yesterday or today, and hope it would go away. ')