Sample viewer

vx.netlux.org/Virus.DOS.Intruder.1353

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:32:02.384983443Z 47 PC: 138b5 | Get disk transfer address
2018-12-17T22:32:02.386973919Z 26 PC: 138c9 | Set disk transfer address
2018-12-17T22:32:02.388929539Z 71 PC: 1357f | Get current directory
2018-12-17T22:32:02.392040989Z 26 PC: 135fe | Set disk transfer address
2018-12-17T22:32:02.393707683Z 78 PC: 13612 | Find first file
2018-12-17T22:32:02.401295694Z 61 PC: 136b8 | Open file (Filename = '\TEST.EXE')
2018-12-17T22:32:02.408784844Z 63 PC: 136c9 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:32:02.411799001Z 66 PC: 136fa | Move file pointer
2018-12-17T22:32:02.413816028Z 63 PC: 13708 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:32:02.421456138Z 79 PC: 1362d | Find next file
2018-12-17T22:32:02.424533803Z 26 PC: 1363f | Set disk transfer address
2018-12-17T22:32:02.427004193Z 78 PC: 13649 | Find first file
2018-12-17T22:32:02.434278091Z 26 PC: 13662 | Set disk transfer address
2018-12-17T22:32:02.435743082Z 79 PC: 13666 | Find next file
2018-12-17T22:32:02.439842486Z 26 PC: 13662 | Set disk transfer address
2018-12-17T22:32:02.441357056Z 79 PC: 13666 | Find next file
2018-12-17T22:32:02.444546394Z 26 PC: 13662 | Set disk transfer address
2018-12-17T22:32:02.446616504Z 79 PC: 13666 | Find next file
2018-12-17T22:32:02.449481135Z 26 PC: 13662 | Set disk transfer address
2018-12-17T22:32:02.450776332Z 79 PC: 13666 | Find next file
2018-12-17T22:32:02.45389232Z 26 PC: 13662 | Set disk transfer address
2018-12-17T22:32:02.45578285Z 79 PC: 13666 | Find next file
2018-12-17T22:32:02.458805845Z 26 PC: 13662 | Set disk transfer address
2018-12-17T22:32:02.460187848Z 79 PC: 13666 | Find next file
2018-12-17T22:32:02.463568601Z 26 PC: 13662 | Set disk transfer address
2018-12-17T22:32:02.464670197Z 79 PC: 13666 | Find next file
2018-12-17T22:32:02.466708057Z 26 PC: 13662 | Set disk transfer address
2018-12-17T22:32:02.468639002Z 79 PC: 13666 | Find next file
2018-12-17T22:32:02.471134932Z 26 PC: 13662 | Set disk transfer address
2018-12-17T22:32:02.472556754Z 79 PC: 13666 | Find next file
2018-12-17T22:32:02.478027496Z 26 PC: 135fe | Set disk transfer address
2018-12-17T22:32:02.480484858Z 78 PC: 13612 | Find first file
2018-12-17T22:32:02.486239136Z 61 PC: 136b8 | Open file (Filename = '\TEST.EXE')
2018-12-17T22:32:02.492001518Z 63 PC: 136c9 | Read file or device (Read 28 bytes on handle 6)
2018-12-17T22:32:02.494947031Z 66 PC: 136fa | Move file pointer
2018-12-17T22:32:02.49634855Z 63 PC: 13708 | Read file or device (Read 2 bytes on handle 6)
2018-12-17T22:32:02.500066624Z 79 PC: 1362d | Find next file
2018-12-17T22:32:02.502793693Z 26 PC: 1363f | Set disk transfer address
2018-12-17T22:32:02.503873535Z 78 PC: 13649 | Find first file
2018-12-17T22:32:02.510568549Z 26 PC: 13662 | Set disk transfer address
2018-12-17T22:32:02.51194519Z 79 PC: 13666 | Find next file
2018-12-17T22:32:02.515357475Z 26 PC: 13662 | Set disk transfer address
2018-12-17T22:32:02.516701136Z 79 PC: 13666 | Find next file
2018-12-17T22:32:02.519790036Z 26 PC: 13662 | Set disk transfer address
2018-12-17T22:32:02.520985092Z 79 PC: 13666 | Find next file
2018-12-17T22:32:02.523885577Z 26 PC: 13662 | Set disk transfer address
2018-12-17T22:32:02.525874188Z 79 PC: 13666 | Find next file
2018-12-17T22:32:02.546449798Z 26 PC: 13662 | Set disk transfer address
2018-12-17T22:32:02.548019427Z 79 PC: 13666 | Find next file
2018-12-17T22:32:02.552934185Z 26 PC: 13662 | Set disk transfer address
2018-12-17T22:32:02.554703846Z 79 PC: 13666 | Find next file
2018-12-17T22:32:02.557996548Z 26 PC: 13662 | Set disk transfer address
2018-12-17T22:32:02.560302323Z 79 PC: 13666 | Find next file
2018-12-17T22:32:02.563646592Z 26 PC: 13662 | Set disk transfer address
2018-12-17T22:32:02.565036239Z 79 PC: 13666 | Find next file
2018-12-17T22:32:02.573145264Z 26 PC: 13662 | Set disk transfer address
2018-12-17T22:32:02.574583701Z 79 PC: 13666 | Find next file
2018-12-17T22:32:02.577422491Z 26 PC: 138d7 | Set disk transfer address