Sample viewer

vx.netlux.org/Virus.DOS.Dima.1024

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:44:42.676674615Z 53 PC: 13596 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:42.678998472Z 37 PC: 135ab | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:42.680436594Z 47 PC: 13571 | Get disk transfer address
2018-12-17T22:44:42.681969582Z 26 PC: 13278 | Set disk transfer address
2018-12-17T22:44:42.684303357Z 78 PC: 13284 | Find first file
2018-12-17T22:44:42.691447863Z 61 PC: 13291 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:44:42.698407503Z 63 PC: 132a7 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:44:42.705015643Z 66 PC: 132dd | Move file pointer
2018-12-17T22:44:42.707837135Z 64 PC: 132ef | Write file or device (Write 1024 bytes on handle 5)
2018-12-17T22:44:42.72264079Z 66 PC: 132fa | Move file pointer
2018-12-17T22:44:42.724249812Z 64 PC: 13306 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:44:42.732321263Z 64 PC: 13312 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:44:42.734917472Z 62 PC: 1331d | Close file
2018-12-17T22:44:42.7434154Z 79 PC: 13284 | Find next file
2018-12-17T22:44:42.747800027Z 61 PC: 13291 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:44:42.754607577Z 63 PC: 132a7 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:44:42.76119523Z 66 PC: 132dd | Move file pointer
2018-12-17T22:44:42.76379169Z 64 PC: 132ef | Write file or device (Write 1024 bytes on handle 5)
2018-12-17T22:44:42.772748585Z 66 PC: 132fa | Move file pointer
2018-12-17T22:44:42.77417164Z 64 PC: 13306 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:44:42.781795761Z 64 PC: 13312 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:44:42.784759996Z 62 PC: 1331d | Close file
2018-12-17T22:44:42.793497691Z 79 PC: 13284 | Find next file
2018-12-17T22:44:42.796393885Z 61 PC: 13291 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:44:42.80386947Z 63 PC: 132a7 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:44:42.810113276Z 66 PC: 132dd | Move file pointer
2018-12-17T22:44:42.811550643Z 64 PC: 132ef | Write file or device (Write 1024 bytes on handle 5)
2018-12-17T22:44:42.82055039Z 66 PC: 132fa | Move file pointer
2018-12-17T22:44:42.822161855Z 64 PC: 13306 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:44:42.828779392Z 64 PC: 13312 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:44:42.832658408Z 62 PC: 1331d | Close file
2018-12-17T22:44:42.840937897Z 79 PC: 13284 | Find next file
2018-12-17T22:44:42.843850508Z 61 PC: 13291 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:44:42.851312419Z 63 PC: 132a7 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:44:42.858844645Z 66 PC: 132dd | Move file pointer
2018-12-17T22:44:42.860587079Z 64 PC: 132ef | Write file or device (Write 1024 bytes on handle 5)
2018-12-17T22:44:42.881298118Z 66 PC: 132fa | Move file pointer
2018-12-17T22:44:42.883003298Z 64 PC: 13306 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:44:42.889704254Z 64 PC: 13312 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:44:42.893337975Z 62 PC: 1331d | Close file
2018-12-17T22:44:42.901899202Z 79 PC: 13284 | Find next file
2018-12-17T22:44:42.904750149Z 61 PC: 13291 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:44:42.911625432Z 63 PC: 132a7 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:44:42.918852941Z 66 PC: 132dd | Move file pointer
2018-12-17T22:44:42.920508437Z 64 PC: 132ef | Write file or device (Write 1024 bytes on handle 5)
2018-12-17T22:44:42.929149072Z 66 PC: 132fa | Move file pointer
2018-12-17T22:44:42.931760901Z 64 PC: 13306 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:44:42.938334782Z 64 PC: 13312 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:44:42.941141698Z 62 PC: 1331d | Close file
2018-12-17T22:44:42.950266304Z 79 PC: 13284 | Find next file
2018-12-17T22:44:42.953079056Z 61 PC: 13291 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:44:42.959696437Z 63 PC: 132a7 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:44:42.966995998Z 66 PC: 132dd | Move file pointer
2018-12-17T22:44:42.969018178Z 64 PC: 132ef | Write file or device (Write 1024 bytes on handle 5)
2018-12-17T22:44:42.977704888Z 66 PC: 132fa | Move file pointer
2018-12-17T22:44:42.980078675Z 64 PC: 13306 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:44:42.987435635Z 64 PC: 13312 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:44:42.990248759Z 62 PC: 1331d | Close file
2018-12-17T22:44:42.998792747Z 79 PC: 13284 | Find next file
2018-12-17T22:44:43.002424265Z 61 PC: 13291 | Open file (Filename = 'PAH.COM')
2018-12-17T22:44:43.009090954Z 63 PC: 132a7 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:44:43.015601218Z 66 PC: 132dd | Move file pointer
2018-12-17T22:44:43.01828655Z 64 PC: 132ef | Write file or device (Write 1024 bytes on handle 5)
2018-12-17T22:44:43.026815911Z 66 PC: 132fa | Move file pointer
2018-12-17T22:44:43.028440779Z 64 PC: 13306 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:44:43.036117133Z 64 PC: 13312 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:44:43.042961949Z 62 PC: 1331d | Close file
2018-12-17T22:44:43.051750484Z 79 PC: 13284 | Find next file
2018-12-17T22:44:43.055650776Z 61 PC: 13291 | Open file (Filename = 'TEST.COM')
2018-12-17T22:44:43.062290181Z 63 PC: 132a7 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:44:43.065093543Z 66 PC: 132bd | Move file pointer
2018-12-17T22:44:43.067557363Z 63 PC: 132c9 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:44:43.074750653Z 62 PC: 1331d | Close file
2018-12-17T22:44:43.076764972Z 79 PC: 13284 | Find next file
2018-12-17T22:44:43.094427699Z 26 PC: 1332b | Set disk transfer address
2018-12-17T22:44:43.095529619Z 78 PC: 13337 | Find first file
2018-12-17T22:44:43.101225144Z 26 PC: 1358e | Set disk transfer address
2018-12-17T22:44:43.103015392Z 37 PC: 135be | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:43.104206981Z 59 PC: 13236 | Change current directory
2018-12-17T22:44:43.106152377Z 9 PC: 12a61 | Display string (String= '������� ��� ������� ')