Sample viewer

vx.netlux.org/Virus.DOS.Trivial.77.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:42:43.583297655Z 78 PC: 12a5b | Find first file
2018-12-17T22:42:43.58993356Z 61 PC: 12a66 | Open file (Filename = '')
2018-12-17T22:42:43.59951955Z 63 PC: 12a70 | Read file or device (Read 65530 bytes on handle 5)
2018-12-17T22:42:43.606430271Z 66 PC: 12a7c | Move file pointer
2018-12-17T22:42:43.607938313Z 64 PC: 12a83 | Write file or device (Write 484 bytes on handle 5)
2018-12-17T22:42:43.6112229Z 79 PC: 12a5b | Find next file
2018-12-17T22:42:43.614125083Z 61 PC: 12a66 | Open file (Filename = '')
2018-12-17T22:42:43.621305232Z 63 PC: 12a70 | Read file or device (Read 65530 bytes on handle 6)
2018-12-17T22:42:43.62856316Z 66 PC: 12a7c | Move file pointer
2018-12-17T22:42:43.630111467Z 64 PC: 12a83 | Write file or device (Write 104 bytes on handle 6)
2018-12-17T22:42:43.632974774Z 79 PC: 12a5b | Find next file
2018-12-17T22:42:43.636345341Z 61 PC: 12a66 | Open file (Filename = '')
2018-12-17T22:42:43.643586233Z 63 PC: 12a70 | Read file or device (Read 65530 bytes on handle 7)
2018-12-17T22:42:43.650510637Z 66 PC: 12a7c | Move file pointer
2018-12-17T22:42:43.652551507Z 64 PC: 12a83 | Write file or device (Write 169 bytes on handle 7)
2018-12-17T22:42:43.655531385Z 79 PC: 12a5b | Find next file
2018-12-17T22:42:43.658324546Z 61 PC: 12a66 | Open file (Filename = '')
2018-12-17T22:42:43.666166143Z 63 PC: 12a70 | Read file or device (Read 65530 bytes on handle 8)
2018-12-17T22:42:43.6734785Z 66 PC: 12a7c | Move file pointer
2018-12-17T22:42:43.675265193Z 64 PC: 12a83 | Write file or device (Write 106 bytes on handle 8)
2018-12-17T22:42:43.678599285Z 79 PC: 12a5b | Find next file
2018-12-17T22:42:43.682644273Z 61 PC: 12a66 | Open file (Filename = '')
2018-12-17T22:42:43.689911593Z 63 PC: 12a70 | Read file or device (Read 65530 bytes on handle 9)
2018-12-17T22:42:43.6969912Z 66 PC: 12a7c | Move file pointer
2018-12-17T22:42:43.698996067Z 64 PC: 12a83 | Write file or device (Write 106 bytes on handle 9)
2018-12-17T22:42:43.701945126Z 79 PC: 12a5b | Find next file
2018-12-17T22:42:43.704707481Z 61 PC: 12a66 | Open file (Filename = '')
2018-12-17T22:42:43.712509187Z 63 PC: 12a70 | Read file or device (Read 65530 bytes on handle 10)
2018-12-17T22:42:43.719653488Z 66 PC: 12a7c | Move file pointer
2018-12-17T22:42:43.72108623Z 64 PC: 12a83 | Write file or device (Write 578 bytes on handle 10)
2018-12-17T22:42:43.73739425Z 79 PC: 12a5b | Find next file
2018-12-17T22:42:43.740889615Z 61 PC: 12a66 | Open file (Filename = '')
2018-12-17T22:42:43.748618398Z 63 PC: 12a70 | Read file or device (Read 65530 bytes on handle 11)
2018-12-17T22:42:43.759830378Z 66 PC: 12a7c | Move file pointer
2018-12-17T22:42:43.761957486Z 64 PC: 12a83 | Write file or device (Write 106 bytes on handle 11)
2018-12-17T22:42:43.765899428Z 79 PC: 12a5b | Find next file
2018-12-17T22:42:43.77000627Z 61 PC: 12a66 | Open file (Filename = '')
2018-12-17T22:42:43.777293162Z 63 PC: 12a70 | Read file or device (Read 65530 bytes on handle 12)
2018-12-17T22:42:43.780112017Z 66 PC: 12a7c | Move file pointer
2018-12-17T22:42:43.781801705Z 64 PC: 12a83 | Write file or device (Write 155 bytes on handle 12)
2018-12-17T22:42:43.785346833Z 79 PC: 12a5b | Find next file
2018-12-17T22:42:43.794921892Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:42:43.796225605Z 72 PC: 12174 | Allocate memory
2018-12-17T22:42:43.798488567Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:42:43.801599261Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T22:42:43.805640537Z 2 PC: 1268d | Character output (Char = '4d')
2018-12-17T22:42:43.816480237Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:42:43.819769714Z 2 PC: 1268d | Character output (Char = '6d')
2018-12-17T22:42:43.822402065Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:42:43.831476248Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:42:43.833914838Z 2 PC: 1268d | Character output (Char = '79')
2018-12-17T22:42:43.836278816Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:42:43.845458758Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:42:43.84820249Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:42:43.851081546Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:42:43.854576422Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:42:43.857460934Z 2 PC: 1268d | Character output (Char = '63')
2018-12-17T22:42:43.860337575Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:42:43.863594715Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:42:43.865957952Z 2 PC: 1268d | Character output (Char = '69')
2018-12-17T22:42:43.868188082Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:42:43.870627402Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:42:43.873333298Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:42:43.875662121Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:42:43.87794502Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:42:43.880473568Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:42:43.883063386Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:42:43.885320976Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:42:43.888404991Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:42:43.891370485Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T22:42:43.897061561Z 2 PC: 1268d | Character output (Char = '43')
2018-12-17T22:42:43.906238561Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:42:43.908601532Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:42:43.91101417Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:42:43.916961427Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:42:43.919441212Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:42:43.926515732Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:42:43.929519717Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:42:43.933077919Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:42:43.936146677Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:42:43.940263097Z 2 PC: 1268d | Character output (Char = '64')
2018-12-17T22:42:43.943702335Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:42:43.946438996Z 2 PC: 1268d | Character output (Char = '43')
2018-12-17T22:42:43.950067679Z 2 PC: 1268d | Character output (Char = '4f')
2018-12-17T22:42:43.952577004Z 2 PC: 1268d | Character output (Char = '4d')
2018-12-17T22:42:43.955102688Z 2 PC: 1268d | Character output (Char = '4d')
2018-12-17T22:42:43.958419468Z 2 PC: 1268d | Character output (Char = '41')
2018-12-17T22:42:43.960786193Z 2 PC: 1268d | Character output (Char = '4e')
2018-12-17T22:42:43.963222809Z 2 PC: 1268d | Character output (Char = '44')
2018-12-17T22:42:43.965545297Z 2 PC: 1268d | Character output (Char = '2c')
2018-12-17T22:42:43.968622585Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:42:43.97107563Z 2 PC: 1268d | Character output (Char = '73')
2018-12-17T22:42:43.973474121Z 2 PC: 1268d | Character output (Char = '79')
2018-12-17T22:42:43.97659471Z 2 PC: 1268d | Character output (Char = '73')
2018-12-17T22:42:43.979854044Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:42:43.983634249Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:42:43.986982117Z 2 PC: 1268d | Character output (Char = '6d')
2018-12-17T22:42:43.989354913Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:42:43.991594795Z 2 PC: 1268d | Character output (Char = '68')
2018-12-17T22:42:43.994304671Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:42:43.999498937Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:42:44.002452987Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:42:44.006806547Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:42:44.009345803Z 2 PC: 1268d | Character output (Char = '64')
2018-12-17T22:42:44.011727783Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:42:44.01475989Z 2 PC: 1268d | Character output (Char = '0a')