Sample viewer

vx.netlux.org/Virus.DOS.Mini.78.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:38:30.372816083Z 78 PC: 12a5b | Find first file
2018-12-17T22:38:30.380301849Z 61 PC: 12a66 | Open file (Filename = '')
2018-12-17T22:38:30.386944362Z 63 PC: 12a71 | Read file or device (Read 65530 bytes on handle 5)
2018-12-17T22:38:30.393662903Z 66 PC: 12a7e | Move file pointer
2018-12-17T22:38:30.39553733Z 64 PC: 12a85 | Write file or device (Write 485 bytes on handle 5)
2018-12-17T22:38:30.399321374Z 79 PC: 12a5b | Find next file
2018-12-17T22:38:30.402085313Z 61 PC: 12a66 | Open file (Filename = '')
2018-12-17T22:38:30.431706513Z 63 PC: 12a71 | Read file or device (Read 65530 bytes on handle 6)
2018-12-17T22:38:30.439519764Z 66 PC: 12a7e | Move file pointer
2018-12-17T22:38:30.440922045Z 64 PC: 12a85 | Write file or device (Write 105 bytes on handle 6)
2018-12-17T22:38:30.443410758Z 79 PC: 12a5b | Find next file
2018-12-17T22:38:30.446578143Z 61 PC: 12a66 | Open file (Filename = '')
2018-12-17T22:38:30.453045463Z 63 PC: 12a71 | Read file or device (Read 65530 bytes on handle 7)
2018-12-17T22:38:30.459672017Z 66 PC: 12a7e | Move file pointer
2018-12-17T22:38:30.461524259Z 64 PC: 12a85 | Write file or device (Write 170 bytes on handle 7)
2018-12-17T22:38:30.464262993Z 79 PC: 12a5b | Find next file
2018-12-17T22:38:30.467150103Z 61 PC: 12a66 | Open file (Filename = '')
2018-12-17T22:38:30.47433016Z 63 PC: 12a71 | Read file or device (Read 65530 bytes on handle 8)
2018-12-17T22:38:30.481142694Z 66 PC: 12a7e | Move file pointer
2018-12-17T22:38:30.482538066Z 64 PC: 12a85 | Write file or device (Write 107 bytes on handle 8)
2018-12-17T22:38:30.485601731Z 79 PC: 12a5b | Find next file
2018-12-17T22:38:30.488226805Z 61 PC: 12a66 | Open file (Filename = '')
2018-12-17T22:38:30.494602915Z 63 PC: 12a71 | Read file or device (Read 65530 bytes on handle 9)
2018-12-17T22:38:30.501437928Z 66 PC: 12a7e | Move file pointer
2018-12-17T22:38:30.502998611Z 64 PC: 12a85 | Write file or device (Write 107 bytes on handle 9)
2018-12-17T22:38:30.506152721Z 79 PC: 12a5b | Find next file
2018-12-17T22:38:30.509094585Z 61 PC: 12a66 | Open file (Filename = '')
2018-12-17T22:38:30.516185043Z 63 PC: 12a71 | Read file or device (Read 65530 bytes on handle 10)
2018-12-17T22:38:30.523066667Z 66 PC: 12a7e | Move file pointer
2018-12-17T22:38:30.524810908Z 64 PC: 12a85 | Write file or device (Write 579 bytes on handle 10)
2018-12-17T22:38:30.538919454Z 79 PC: 12a5b | Find next file
2018-12-17T22:38:30.541426868Z 61 PC: 12a66 | Open file (Filename = '')
2018-12-17T22:38:30.547918059Z 63 PC: 12a71 | Read file or device (Read 65530 bytes on handle 11)
2018-12-17T22:38:30.554974793Z 66 PC: 12a7e | Move file pointer
2018-12-17T22:38:30.556430273Z 64 PC: 12a85 | Write file or device (Write 107 bytes on handle 11)
2018-12-17T22:38:30.55903125Z 79 PC: 12a5b | Find next file
2018-12-17T22:38:30.562051582Z 61 PC: 12a66 | Open file (Filename = '')
2018-12-17T22:38:30.56880779Z 63 PC: 12a71 | Read file or device (Read 65530 bytes on handle 12)
2018-12-17T22:38:30.571795846Z 66 PC: 12a7e | Move file pointer
2018-12-17T22:38:30.57476818Z 64 PC: 12a85 | Write file or device (Write 157 bytes on handle 12)
2018-12-17T22:38:30.577815612Z 79 PC: 12a5b | Find next file
2018-12-17T22:38:30.586282522Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:38:30.588197434Z 72 PC: 12174 | Allocate memory
2018-12-17T22:38:30.589838713Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:38:30.591686644Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T22:38:30.596130742Z 2 PC: 1268d | Character output (Char = '4d')
2018-12-17T22:38:30.598366825Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:38:30.60034407Z 2 PC: 1268d | Character output (Char = '6d')
2018-12-17T22:38:30.602747683Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:38:30.605053533Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:38:30.607205574Z 2 PC: 1268d | Character output (Char = '79')
2018-12-17T22:38:30.61116558Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:38:30.613145036Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:38:30.615162888Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:38:30.617791694Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:38:30.621417227Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:38:30.623890398Z 2 PC: 1268d | Character output (Char = '63')
2018-12-17T22:38:30.626294393Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:38:30.629299967Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:38:30.631767477Z 2 PC: 1268d | Character output (Char = '69')
2018-12-17T22:38:30.634210791Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:38:30.641871231Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:38:30.643835042Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:38:30.645806064Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:38:30.652594925Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:38:30.655374103Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:38:30.657404623Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:38:30.660859607Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:38:30.662997274Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:38:30.664883558Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T22:38:30.669171971Z 2 PC: 1268d | Character output (Char = '43')
2018-12-17T22:38:30.67123789Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:38:30.673296653Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:38:30.681399142Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:38:30.683397989Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:38:30.685597998Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:38:30.688755532Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:38:30.69103614Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:38:30.700452241Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:38:30.703678584Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:38:30.705597845Z 2 PC: 1268d | Character output (Char = '64')
2018-12-17T22:38:30.707500669Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:38:30.710094633Z 2 PC: 1268d | Character output (Char = '43')
2018-12-17T22:38:30.712122914Z 2 PC: 1268d | Character output (Char = '4f')
2018-12-17T22:38:30.714222083Z 2 PC: 1268d | Character output (Char = '4d')
2018-12-17T22:38:30.716701543Z 2 PC: 1268d | Character output (Char = '4d')
2018-12-17T22:38:30.718180279Z 2 PC: 1268d | Character output (Char = '41')
2018-12-17T22:38:30.719550535Z 2 PC: 1268d | Character output (Char = '4e')
2018-12-17T22:38:30.721612843Z 2 PC: 1268d | Character output (Char = '44')
2018-12-17T22:38:30.72311735Z 2 PC: 1268d | Character output (Char = '2c')
2018-12-17T22:38:30.724626976Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:38:30.72681565Z 2 PC: 1268d | Character output (Char = '73')
2018-12-17T22:38:30.728344805Z 2 PC: 1268d | Character output (Char = '79')
2018-12-17T22:38:30.730530076Z 2 PC: 1268d | Character output (Char = '73')
2018-12-17T22:38:30.733095407Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:38:30.734515737Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:38:30.735869259Z 2 PC: 1268d | Character output (Char = '6d')
2018-12-17T22:38:30.74384134Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:38:30.745723724Z 2 PC: 1268d | Character output (Char = '68')
2018-12-17T22:38:30.747494567Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:38:30.750507162Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:38:30.752005992Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:38:30.753374337Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:38:30.755605436Z 2 PC: 1268d | Character output (Char = '64')
2018-12-17T22:38:30.757063786Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:38:30.758372671Z 2 PC: 1268d | Character output (Char = '0a')