Sample viewer

vx.netlux.org/Virus.DOS.A_morph.370

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:58.812875139Z 37 PC: 12a90 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:43:58.814569091Z 37 PC: 12a98 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:43:58.815917353Z 37 PC: 12a90 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:58.817388468Z 78 PC: 12a90 | Find first file
2018-12-17T22:43:58.824830889Z 37 PC: 12a90 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:58.826227284Z 61 PC: 12a90 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:43:58.832992122Z 53 PC: 12a90 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:58.834325794Z 37 PC: 12b71 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:58.841019173Z 64 PC: 12b81 | Write file or device (Write 370 bytes on handle 5)
2018-12-17T22:43:58.847744924Z 62 PC: 12a90 | Close file
2018-12-17T22:43:58.86332343Z 79 PC: 12a90 | Find next file
2018-12-17T22:43:58.865915871Z 37 PC: 12a90 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:58.867164948Z 61 PC: 12a90 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:43:58.871425842Z 53 PC: 12a90 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:58.872847857Z 37 PC: 12b71 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:58.874138322Z 64 PC: 12b81 | Write file or device (Write 370 bytes on handle 5)
2018-12-17T22:43:58.878750732Z 62 PC: 12a90 | Close file
2018-12-17T22:43:58.884480275Z 79 PC: 12a90 | Find next file
2018-12-17T22:43:58.8864003Z 37 PC: 12a90 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:58.887471336Z 61 PC: 12a90 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:43:58.892302247Z 53 PC: 12a90 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:58.893239047Z 37 PC: 12b71 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:58.894095729Z 64 PC: 12b81 | Write file or device (Write 370 bytes on handle 5)
2018-12-17T22:43:58.899085734Z 62 PC: 12a90 | Close file
2018-12-17T22:43:58.904609181Z 79 PC: 12a90 | Find next file
2018-12-17T22:43:58.906384561Z 37 PC: 12a90 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:58.907639561Z 61 PC: 12a90 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:43:58.912061522Z 53 PC: 12a90 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:58.913244536Z 37 PC: 12b71 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:58.914637416Z 64 PC: 12b81 | Write file or device (Write 370 bytes on handle 5)
2018-12-17T22:43:58.92149335Z 62 PC: 12a90 | Close file
2018-12-17T22:43:58.929247399Z 79 PC: 12a90 | Find next file
2018-12-17T22:43:58.931962274Z 37 PC: 12a90 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:58.933595392Z 61 PC: 12a90 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:43:58.941457215Z 53 PC: 12a90 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:58.942600757Z 37 PC: 12b71 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:58.944893874Z 64 PC: 12b81 | Write file or device (Write 370 bytes on handle 5)
2018-12-17T22:43:58.951272382Z 62 PC: 12a90 | Close file
2018-12-17T22:43:58.958605369Z 79 PC: 12a90 | Find next file
2018-12-17T22:43:58.963939674Z 37 PC: 12a90 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:58.965604311Z 61 PC: 12a90 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:43:58.972529166Z 53 PC: 12a90 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:58.974676947Z 37 PC: 12b71 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:58.97578951Z 64 PC: 12b81 | Write file or device (Write 370 bytes on handle 5)
2018-12-17T22:43:58.982236492Z 62 PC: 12a90 | Close file
2018-12-17T22:43:58.990493405Z 79 PC: 12a90 | Find next file
2018-12-17T22:43:58.99314676Z 37 PC: 12a90 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:58.994332562Z 61 PC: 12a90 | Open file (Filename = 'PAH.COM')
2018-12-17T22:43:59.001195443Z 53 PC: 12a90 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:59.002411505Z 37 PC: 12b71 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:59.003509812Z 64 PC: 12b81 | Write file or device (Write 370 bytes on handle 5)
2018-12-17T22:43:59.010728027Z 62 PC: 12a90 | Close file
2018-12-17T22:43:59.018488956Z 79 PC: 12a90 | Find next file
2018-12-17T22:43:59.021314809Z 37 PC: 12a90 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:59.023291218Z 61 PC: 12a90 | Open file (Filename = 'TEST.COM')
2018-12-17T22:43:59.030919853Z 53 PC: 12a90 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:59.032598424Z 37 PC: 12b71 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:43:59.035056286Z 64 PC: 12b81 | Write file or device (Write 370 bytes on handle 5)
2018-12-17T22:43:59.042018589Z 62 PC: 12a90 | Close file
2018-12-17T22:43:59.049570156Z 79 PC: 12a90 | Find next file
2018-12-17T22:43:59.053190281Z 37 PC: 12a90 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')