Sample viewer

vx.netlux.org/Virus.DOS.Wormsign.1547

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:03.461851823Z 47 PC: 12da2 | Get disk transfer address
2018-12-17T22:45:03.463310622Z 26 PC: 12db3 | Set disk transfer address
2018-12-17T22:45:03.465768418Z 9 PC: 12dbc | Display string (String= 'Wormsign ! ')
2018-12-17T22:45:03.469846859Z 25 PC: 12e74 | Get default drive
2018-12-17T22:45:03.471067501Z 78 PC: 12e89 | Find first file
2018-12-17T22:45:03.479325621Z 79 PC: 1309a | Find next file
2018-12-17T22:45:03.482457824Z 79 PC: 1309a | Find next file
2018-12-17T22:45:03.485295964Z 79 PC: 1309a | Find next file
2018-12-17T22:45:03.489198214Z 79 PC: 1309a | Find next file
2018-12-17T22:45:03.491951435Z 79 PC: 1309a | Find next file
2018-12-17T22:45:03.494503067Z 79 PC: 1309a | Find next file
2018-12-17T22:45:03.498188759Z 79 PC: 1309a | Find next file
2018-12-17T22:45:03.501293501Z 67 PC: 12eb0 | Get or set file attributes
2018-12-17T22:45:03.507631494Z 67 PC: 12ebb | Get or set file attributes
2018-12-17T22:45:03.527256613Z 61 PC: 12ec5 | Open file (Filename = '')
2018-12-17T22:45:03.536111373Z 63 PC: 12ede | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:45:03.538908807Z 62 PC: 1307e | Close file
2018-12-17T22:45:03.540812382Z 67 PC: 1308c | Get or set file attributes
2018-12-17T22:45:03.555307867Z 79 PC: 1309a | Find next file
2018-12-17T22:45:03.558362956Z 14 PC: 130c0 | Set default drive (Drive = 'A')
2018-12-17T22:45:03.560240512Z 26 PC: 130cf | Set disk transfer address