Sample viewer

vx.netlux.org/Virus.DOS.SillyC.184.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:40:30.074444301Z 26 PC: 1ffcf | Set disk transfer address
2018-12-17T22:40:30.075955079Z 78 PC: 1ffda | Find first file
2018-12-17T22:40:30.082068426Z 61 PC: 1ffe6 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:40:30.089100171Z 63 PC: 1fff5 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:40:30.096331514Z 66 PC: 20008 | Move file pointer
2018-12-17T22:40:30.097533576Z 64 PC: 2001a | Write file or device (Write 184 bytes on handle 5)
2018-12-17T22:40:30.112127996Z 66 PC: 20028 | Move file pointer
2018-12-17T22:40:30.1136091Z 64 PC: 20033 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:40:30.119740016Z 62 PC: 20042 | Close file
2018-12-17T22:40:30.132668736Z 26 PC: 20049 | Set disk transfer address
2018-12-17T22:40:30.134690681Z 80 PC: 13fb9 | Set current PSP
2018-12-17T22:40:30.135522505Z 48 PC: 13fbe | Get DOS version
2018-12-17T22:40:30.137093351Z 101 PC: 14044 | Get extended country info
2018-12-17T22:40:30.139539956Z 99 PC: 1404a | Get DBCS lead byte table pointer
2018-12-17T22:40:30.140645855Z 74 PC: 140ac | Reallocate memory
2018-12-17T22:40:30.141851517Z 25 PC: 140e3 | Get default drive
2018-12-17T22:40:30.14326766Z 37 PC: 13ba3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:40:30.144210249Z 37 PC: 13baa | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:40:30.145159561Z 37 PC: 13bb1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:40:30.156680465Z 2 PC: 13e6c | Character output (Char = '0d')
2018-12-17T22:40:30.162945828Z 2 PC: 13e6c | Character output (Char = '0a')
2018-12-17T22:40:30.174621152Z 2 PC: 13e6c | Character output (Char = '0d')
2018-12-17T22:40:30.181620961Z 2 PC: 13e6c | Character output (Char = '0a')
2018-12-17T22:40:30.185064074Z 2 PC: 13e6c | Character output (Char = '4d')
2018-12-17T22:40:30.186820171Z 2 PC: 13e6c | Character output (Char = '69')
2018-12-17T22:40:30.189446643Z 2 PC: 13e6c | Character output (Char = '63')
2018-12-17T22:40:30.193864863Z 2 PC: 13e6c | Character output (Char = '72')
2018-12-17T22:40:30.19620173Z 2 PC: 13e6c | Character output (Char = '6f')
2018-12-17T22:40:30.19934087Z 2 PC: 13e6c | Character output (Char = '73')
2018-12-17T22:40:30.201755344Z 2 PC: 13e6c | Character output (Char = '6f')
2018-12-17T22:40:30.204071594Z 2 PC: 13e6c | Character output (Char = '66')
2018-12-17T22:40:30.207448662Z 2 PC: 13e6c | Character output (Char = '74')
2018-12-17T22:40:30.209786332Z 2 PC: 13e6c | Character output (Char = '28')
2018-12-17T22:40:30.212099357Z 2 PC: 13e6c | Character output (Char = '52')
2018-12-17T22:40:30.221489283Z 2 PC: 13e6c | Character output (Char = '29')
2018-12-17T22:40:30.226917548Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T22:40:30.234959981Z 2 PC: 13e6c | Character output (Char = '4d')
2018-12-17T22:40:30.23932378Z 2 PC: 13e6c | Character output (Char = '53')
2018-12-17T22:40:30.24187787Z 2 PC: 13e6c | Character output (Char = '2d')
2018-12-17T22:40:30.245622059Z 2 PC: 13e6c | Character output (Char = '44')
2018-12-17T22:40:30.25644789Z 2 PC: 13e6c | Character output (Char = '4f')
2018-12-17T22:40:30.260611899Z 2 PC: 13e6c | Character output (Char = '53')
2018-12-17T22:40:30.263031642Z 2 PC: 13e6c | Character output (Char = '28')
2018-12-17T22:40:30.266201768Z 2 PC: 13e6c | Character output (Char = '52')
2018-12-17T22:40:30.268916978Z 2 PC: 13e6c | Character output (Char = '29')
2018-12-17T22:40:30.2712731Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T22:40:30.274479448Z 2 PC: 13e6c | Character output (Char = '56')
2018-12-17T22:40:30.282857631Z 2 PC: 13e6c | Character output (Char = '65')
2018-12-17T22:40:30.284962818Z 2 PC: 13e6c | Character output (Char = '72')
2018-12-17T22:40:30.287192876Z 2 PC: 13e6c | Character output (Char = '73')
2018-12-17T22:40:30.289545407Z 2 PC: 13e6c | Character output (Char = '69')
2018-12-17T22:40:30.291703684Z 2 PC: 13e6c | Character output (Char = '6f')
2018-12-17T22:40:30.294075078Z 2 PC: 13e6c | Character output (Char = '6e')
2018-12-17T22:40:30.314432489Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T22:40:30.319072614Z 2 PC: 13e6c | Character output (Char = '36')
2018-12-17T22:40:30.324287536Z 2 PC: 13e6c | Character output (Char = '2e')
2018-12-17T22:40:30.331628095Z 2 PC: 13e6c | Character output (Char = '32')
2018-12-17T22:40:30.333813531Z 2 PC: 13e6c | Character output (Char = '32')
2018-12-17T22:40:30.336029885Z 2 PC: 13e6c | Character output (Char = '0d')
2018-12-17T22:40:30.340018165Z 2 PC: 13e6c | Character output (Char = '0a')
2018-12-17T22:40:30.344044124Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T22:40:30.346034074Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T22:40:30.348750525Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T22:40:30.351001281Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T22:40:30.353391139Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T22:40:30.356481173Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T22:40:30.358903403Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T22:40:30.3612643Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T22:40:30.36506389Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T22:40:30.367554259Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T22:40:30.370713406Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T22:40:30.377514341Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T22:40:30.379746741Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T22:40:30.381911166Z 2 PC: 13e6c | Character output (Char = '28')
2018-12-17T22:40:30.38499785Z 2 PC: 13e6c | Character output (Char = '43')
2018-12-17T22:40:30.387096081Z 2 PC: 13e6c | Character output (Char = '29')
2018-12-17T22:40:30.391025911Z 2 PC: 13e6c | Character output (Char = '43')
2018-12-17T22:40:30.393676371Z 2 PC: 13e6c | Character output (Char = '6f')
2018-12-17T22:40:30.395807336Z 2 PC: 13e6c | Character output (Char = '70')
2018-12-17T22:40:30.39780742Z 2 PC: 13e6c | Character output (Char = '79')
2018-12-17T22:40:30.400423937Z 2 PC: 13e6c | Character output (Char = '72')
2018-12-17T22:40:30.402545688Z 2 PC: 13e6c | Character output (Char = '69')
2018-12-17T22:40:30.404647162Z 2 PC: 13e6c | Character output (Char = '67')
2018-12-17T22:40:30.408051579Z 2 PC: 13e6c | Character output (Char = '68')
2018-12-17T22:40:30.410056559Z 2 PC: 13e6c | Character output (Char = '74')
2018-12-17T22:40:30.412011376Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T22:40:30.416806111Z 2 PC: 13e6c | Character output (Char = '4d')
2018-12-17T22:40:30.419003008Z 2 PC: 13e6c | Character output (Char = '69')
2018-12-17T22:40:30.421120251Z 2 PC: 13e6c | Character output (Char = '63')
2018-12-17T22:40:30.424253243Z 2 PC: 13e6c | Character output (Char = '72')
2018-12-17T22:40:30.426476319Z 2 PC: 13e6c | Character output (Char = '6f')
2018-12-17T22:40:30.428706539Z 2 PC: 13e6c | Character output (Char = '73')
2018-12-17T22:40:30.431504434Z 2 PC: 13e6c | Character output (Char = '6f')
2018-12-17T22:40:30.435083373Z 2 PC: 13e6c | Character output (Char = '66')
2018-12-17T22:40:30.442381233Z 2 PC: 13e6c | Character output (Char = '74')
2018-12-17T22:40:30.446102622Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T22:40:30.448417363Z 2 PC: 13e6c | Character output (Char = '43')
2018-12-17T22:40:30.450692485Z 2 PC: 13e6c | Character output (Char = '6f')
2018-12-17T22:40:30.453840039Z 2 PC: 13e6c | Character output (Char = '72')
2018-12-17T22:40:30.456102563Z 2 PC: 13e6c | Character output (Char = '70')
2018-12-17T22:40:30.458375069Z 2 PC: 13e6c | Character output (Char = '20')
2018-12-17T22:40:30.464635632Z 2 PC: 13e6c | Character output (Char = '31')
2018-12-17T22:40:30.467865374Z 2 PC: 13e6c | Character output (Char = '39')
2018-12-17T22:40:30.470125834Z 2 PC: 13e6c | Character output (Char = '38')
2018-12-17T22:40:30.47307322Z 2 PC: 13e6c | Character output (Char = '31')
2018-12-17T22:40:30.475600858Z 2 PC: 13e6c | Character output (Char = '2d')
2018-12-17T22:40:30.477841604Z 2 PC: 13e6c | Character output (Char = '31')
2018-12-17T22:40:30.480753466Z 2 PC: 13e6c | Character output (Char = '39')
2018-12-17T22:40:30.483819142Z 2 PC: 13e6c | Character output (Char = '39')
2018-12-17T22:40:30.48608387Z 2 PC: 13e6c | Character output (Char = '34')
2018-12-17T22:40:30.488979321Z 2 PC: 13e6c | Character output (Char = '2e')
2018-12-17T22:40:30.493627624Z 2 PC: 13e6c | Character output (Char = '0d')
2018-12-17T22:40:30.495746458Z 2 PC: 13e6c | Character output (Char = '0a')
2018-12-17T22:40:30.500039361Z 74 PC: 12d4c | Reallocate memory
2018-12-17T22:40:30.502421886Z 72 PC: 12d8d | Allocate memory
2018-12-17T22:40:30.504158956Z 72 PC: 12dc5 | Allocate memory
2018-12-17T22:40:30.506029053Z 72 PC: 12dcd | Allocate memory