Sample viewer

vx.netlux.org/Virus.DOS.Mini.88.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:33.829074361Z 78 PC: 12a65 | Find first file
2018-12-17T22:45:33.83686929Z 61 PC: 12a70 | Open file (Filename = '')
2018-12-17T22:45:33.844600491Z 63 PC: 12a7b | Read file or device (Read 65530 bytes on handle 5)
2018-12-17T22:45:33.852085689Z 66 PC: 12a87 | Move file pointer
2018-12-17T22:45:33.854158633Z 64 PC: 12a8e | Write file or device (Write 495 bytes on handle 5)
2018-12-17T22:45:33.85811326Z 79 PC: 12a65 | Find next file
2018-12-17T22:45:33.861245031Z 61 PC: 12a70 | Open file (Filename = '')
2018-12-17T22:45:33.868585208Z 63 PC: 12a7b | Read file or device (Read 65530 bytes on handle 6)
2018-12-17T22:45:33.876632572Z 66 PC: 12a87 | Move file pointer
2018-12-17T22:45:33.878494038Z 64 PC: 12a8e | Write file or device (Write 115 bytes on handle 6)
2018-12-17T22:45:33.881840793Z 79 PC: 12a65 | Find next file
2018-12-17T22:45:33.88597092Z 61 PC: 12a70 | Open file (Filename = '')
2018-12-17T22:45:33.894719511Z 63 PC: 12a7b | Read file or device (Read 65530 bytes on handle 7)
2018-12-17T22:45:33.902021005Z 66 PC: 12a87 | Move file pointer
2018-12-17T22:45:33.905839537Z 64 PC: 12a8e | Write file or device (Write 180 bytes on handle 7)
2018-12-17T22:45:33.910492646Z 79 PC: 12a65 | Find next file
2018-12-17T22:45:33.913773037Z 61 PC: 12a70 | Open file (Filename = '')
2018-12-17T22:45:33.921486534Z 63 PC: 12a7b | Read file or device (Read 65530 bytes on handle 8)
2018-12-17T22:45:33.936719323Z 66 PC: 12a87 | Move file pointer
2018-12-17T22:45:33.941952332Z 64 PC: 12a8e | Write file or device (Write 117 bytes on handle 8)
2018-12-17T22:45:33.948983728Z 79 PC: 12a65 | Find next file
2018-12-17T22:45:33.952043815Z 61 PC: 12a70 | Open file (Filename = '')
2018-12-17T22:45:33.958915952Z 63 PC: 12a7b | Read file or device (Read 65530 bytes on handle 9)
2018-12-17T22:45:33.965062837Z 66 PC: 12a87 | Move file pointer
2018-12-17T22:45:33.969122882Z 64 PC: 12a8e | Write file or device (Write 117 bytes on handle 9)
2018-12-17T22:45:33.972112116Z 79 PC: 12a65 | Find next file
2018-12-17T22:45:33.975030317Z 61 PC: 12a70 | Open file (Filename = '')
2018-12-17T22:45:33.982578543Z 63 PC: 12a7b | Read file or device (Read 65530 bytes on handle 10)
2018-12-17T22:45:33.98866752Z 66 PC: 12a87 | Move file pointer
2018-12-17T22:45:33.990582496Z 64 PC: 12a8e | Write file or device (Write 589 bytes on handle 10)
2018-12-17T22:45:34.007363513Z 79 PC: 12a65 | Find next file
2018-12-17T22:45:34.010416417Z 61 PC: 12a70 | Open file (Filename = '')
2018-12-17T22:45:34.017661975Z 63 PC: 12a7b | Read file or device (Read 65530 bytes on handle 11)
2018-12-17T22:45:34.025617627Z 66 PC: 12a87 | Move file pointer
2018-12-17T22:45:34.027824582Z 64 PC: 12a8e | Write file or device (Write 117 bytes on handle 11)
2018-12-17T22:45:34.031253202Z 79 PC: 12a65 | Find next file
2018-12-17T22:45:34.035646543Z 61 PC: 12a70 | Open file (Filename = '')
2018-12-17T22:45:34.043896307Z 63 PC: 12a7b | Read file or device (Read 65530 bytes on handle 12)
2018-12-17T22:45:34.047021196Z 66 PC: 12a87 | Move file pointer
2018-12-17T22:45:34.04890816Z 64 PC: 12a8e | Write file or device (Write 177 bytes on handle 12)
2018-12-17T22:45:34.052326751Z 79 PC: 12a65 | Find next file
2018-12-17T22:45:34.061833846Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:45:34.06324141Z 72 PC: 12174 | Allocate memory
2018-12-17T22:45:34.066190439Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:45:34.06832067Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T22:45:34.071987006Z 2 PC: 1268d | Character output (Char = '4d')
2018-12-17T22:45:34.075245626Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:45:34.077712208Z 2 PC: 1268d | Character output (Char = '6d')
2018-12-17T22:45:34.079946064Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:45:34.082772963Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:45:34.084945564Z 2 PC: 1268d | Character output (Char = '79')
2018-12-17T22:45:34.087471868Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:45:34.098658408Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:45:34.101013441Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:45:34.10334994Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:45:34.105866617Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:45:34.108506474Z 2 PC: 1268d | Character output (Char = '63')
2018-12-17T22:45:34.110785264Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:45:34.113086937Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:45:34.115941328Z 2 PC: 1268d | Character output (Char = '69')
2018-12-17T22:45:34.118577099Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:45:34.121286167Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:45:34.125969172Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:45:34.128362818Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:45:34.130707682Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:45:34.133983574Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:45:34.137230101Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:45:34.140550167Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:45:34.143737353Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:45:34.151693486Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T22:45:34.155690623Z 2 PC: 1268d | Character output (Char = '43')
2018-12-17T22:45:34.159007272Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:45:34.161851704Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:45:34.164333927Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:45:34.167378284Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:45:34.170567624Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:45:34.173236767Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:45:34.175884099Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:45:34.179379695Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:45:34.181817303Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:45:34.184244812Z 2 PC: 1268d | Character output (Char = '64')
2018-12-17T22:45:34.187187378Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:45:34.189729844Z 2 PC: 1268d | Character output (Char = '43')
2018-12-17T22:45:34.192360805Z 2 PC: 1268d | Character output (Char = '4f')
2018-12-17T22:45:34.19588858Z 2 PC: 1268d | Character output (Char = '4d')
2018-12-17T22:45:34.198691845Z 2 PC: 1268d | Character output (Char = '4d')
2018-12-17T22:45:34.201417926Z 2 PC: 1268d | Character output (Char = '41')
2018-12-17T22:45:34.204819144Z 2 PC: 1268d | Character output (Char = '4e')
2018-12-17T22:45:34.207367169Z 2 PC: 1268d | Character output (Char = '44')
2018-12-17T22:45:34.210129387Z 2 PC: 1268d | Character output (Char = '2c')
2018-12-17T22:45:34.213292789Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:45:34.215698146Z 2 PC: 1268d | Character output (Char = '73')
2018-12-17T22:45:34.218983476Z 2 PC: 1268d | Character output (Char = '79')
2018-12-17T22:45:34.222852372Z 2 PC: 1268d | Character output (Char = '73')
2018-12-17T22:45:34.225242873Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:45:34.22747795Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:45:34.229727385Z 2 PC: 1268d | Character output (Char = '6d')
2018-12-17T22:45:34.232770891Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:45:34.235094214Z 2 PC: 1268d | Character output (Char = '68')
2018-12-17T22:45:34.237262197Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:45:34.242112516Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:45:34.244582976Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:45:34.247108249Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:45:34.250379232Z 2 PC: 1268d | Character output (Char = '64')
2018-12-17T22:45:34.25310934Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:45:34.255377199Z 2 PC: 1268d | Character output (Char = '0a')