Sample viewer

vx.netlux.org/Virus.DOS.V.752

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:47:37.877845274Z 53 PC: 13e8a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:37.879906927Z 53 PC: 13e8a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:47:37.880934492Z 53 PC: 13e8a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:47:37.881911647Z 53 PC: 13e8a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:37.883068913Z 53 PC: 13e8a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:47:37.885040278Z 53 PC: 13e8a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:37.886539723Z 53 PC: 13e8a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:47:37.887951831Z 53 PC: 13e8a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:47:37.889890697Z 53 PC: 13e8a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:47:37.891057063Z 53 PC: 13e8a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:47:37.892244228Z 53 PC: 13e8a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:47:37.894043514Z 53 PC: 13e8a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:47:37.895512691Z 53 PC: 13e8a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:47:37.89669059Z 53 PC: 13e8a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:47:37.898449925Z 53 PC: 13e8a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:47:37.899924496Z 53 PC: 13e8a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:47:37.901049325Z 53 PC: 13e8a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:47:37.902499433Z 53 PC: 13e8a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:47:37.904283765Z 53 PC: 13e8a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:47:37.905491582Z 37 PC: 13e9f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:37.906989301Z 37 PC: 13ea7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:47:37.9090419Z 37 PC: 13eaf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:37.910461244Z 37 PC: 13eb7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:47:37.912437595Z 68 PC: 14b5c | I/O control for devices (Set for = 't`<;uF��< t4�`t������<;t��u�< t< t�< t�%��%�')
2018-12-17T22:47:37.914875716Z 44 PC: 14c93 | Get time 0x14c93: mov word ptr [0x8a], cx
0x14c97: mov word ptr [0x8c], dx
0x14c9b: retf
0x14c9c: call 0x14ce3
0x14c9f: jb 0x14cb0
0x14ca1: mov cx, word ptr es:[di + 4]
0x14ca5: cmp cx, 1
0x14ca8: je 0x14cb0
0x14caa: xor bx, bx
0x14cac: push cs
0x14cad: call 0x24824
0x14cb0: retf 4
0x14cb3: call 0x14ce3
0x14cb6: jb 0x14ccb
0x14cb8: mov ax, cx
0x14cba: mov dx, bx
0x14cbc: mov cx, word ptr es:[di + 4]
0x14cc0: cmp cx, 1
0x14cc3: je 0x14ccb
0x14cc5: xor bx, bx
2018-12-17T22:47:37.917265987Z 48 PC: 14772 | Get DOS version
2018-12-17T22:47:37.918907028Z 67 PC: 13c5f | Get or set file attributes
2018-12-17T22:47:37.925723411Z 67 PC: 13c86 | Get or set file attributes
2018-12-17T22:47:37.940706985Z 61 PC: 145b0 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:47:37.9454609Z 63 PC: 14683 | Read file or device (Read 8 bytes on handle 5)
2018-12-17T22:47:37.959862974Z 66 PC: 146e2 | Move file pointer
2018-12-17T22:47:37.961404128Z 63 PC: 14683 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:47:37.963061067Z 63 PC: 14683 | Read file or device (Read 6810 bytes on handle 5)
2018-12-17T22:47:37.966468465Z 60 PC: 145b0 | Create or truncate file
2018-12-17T22:47:37.978697248Z 63 PC: 14683 | Read file or device (Read 10000 bytes on handle 5)
2018-12-17T22:47:37.98063808Z 66 PC: 14cfd | Move file pointer
2018-12-17T22:47:37.982492843Z 66 PC: 14d0b | Move file pointer
2018-12-17T22:47:37.983819963Z 66 PC: 14d19 | Move file pointer
2018-12-17T22:47:37.985167071Z 62 PC: 14600 | Close file
2018-12-17T22:47:37.987803994Z 67 PC: 13c86 | Get or set file attributes
2018-12-17T22:47:37.99752593Z 62 PC: 14600 | Close file
2018-12-17T22:47:37.999633771Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:38.00132691Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:38.002407769Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:47:38.003569895Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:47:38.005369345Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:47:38.006901404Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:47:38.007989027Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:38.009297205Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:38.010655438Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:47:38.011719434Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:47:38.01323591Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:38.014278597Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:38.01539149Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:47:38.01675936Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:47:38.018099221Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:47:38.019143754Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:47:38.020332226Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:47:38.021617566Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:47:38.022637314Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:47:38.023963827Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:47:38.0254864Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:47:38.026805386Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:47:38.027996097Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:47:38.029432834Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:47:38.030468126Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:47:38.031677877Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:47:38.032843856Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:47:38.033764171Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:47:38.034903787Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:47:38.036556524Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:47:38.037817964Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:47:38.039253377Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:47:38.053833585Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:47:38.055075854Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:47:38.056297948Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:47:38.058044197Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:47:38.05942426Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:47:38.06101326Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:47:38.062925118Z 41 PC: 13db5 | Parse filename
2018-12-17T22:47:38.064333889Z 41 PC: 13dc3 | Parse filename
2018-12-17T22:47:38.065714126Z 75 PC: 13dce | Execute program
2018-12-17T22:47:38.075655116Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:38.076761513Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:38.07787839Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:47:38.080049207Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:47:38.081380058Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:47:38.082565859Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:47:38.084495002Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:38.085897104Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:38.087212844Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:47:38.089176803Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:47:38.090335579Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:38.091548285Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:38.093326639Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:47:38.094557343Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:47:38.095741662Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:47:38.097471435Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:47:38.09847049Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:47:38.099469248Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:47:38.101072244Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:47:38.102614817Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:47:38.103889426Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:47:38.105850904Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:47:38.107189157Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:47:38.108260273Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:47:38.109707796Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:47:38.11111542Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:47:38.112523707Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:47:38.114514092Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:47:38.115611018Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:47:38.11698699Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:47:38.119337911Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:47:38.120868916Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:47:38.122349055Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:47:38.124875233Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:47:38.126377381Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:47:38.127561123Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:47:38.129746263Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:47:38.133066853Z 37 PC: 13e07 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:47:38.135491571Z 65 PC: 146f9 | Delete file (Filename = 'Victim.Exe')
2018-12-17T22:47:38.153743213Z 26 PC: 13cfd | Set disk transfer address
2018-12-17T22:47:38.154923781Z 78 PC: 13d09 | Find first file
2018-12-17T22:47:38.161705693Z 86 PC: 1473d | Rename file
2018-12-17T22:47:38.174298494Z 60 PC: 145b0 | Create or truncate file
2018-12-17T22:47:38.185592063Z 67 PC: 13c5f | Get or set file attributes
2018-12-17T22:47:38.191489745Z 67 PC: 13c86 | Get or set file attributes
2018-12-17T22:47:38.202446352Z 61 PC: 145b0 | Open file (Filename = 'Victim.Exe')
2018-12-17T22:47:38.209722025Z 64 PC: 14683 | Write file or device (Write 4844 bytes on handle 5)
2018-12-17T22:47:38.218127175Z 64 PC: 14683 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:47:38.221704596Z 64 PC: 14683 | Write file or device (Write 6810 bytes on handle 5)
2018-12-17T22:47:38.232148208Z 63 PC: 14683 | Read file or device (Read 10000 bytes on handle 6)
2018-12-17T22:47:38.240601128Z 64 PC: 14683 | Write file or device (Write 9616 bytes on handle 5)
2018-12-17T22:47:38.250037525Z 66 PC: 14cfd | Move file pointer
2018-12-17T22:47:38.251488974Z 66 PC: 14d0b | Move file pointer
2018-12-17T22:47:38.253069288Z 66 PC: 14d19 | Move file pointer
2018-12-17T22:47:38.255316189Z 87 PC: 13ccd | Get or set file date and time
2018-12-17T22:47:38.257123475Z 62 PC: 14600 | Close file
2018-12-17T22:47:38.259128543Z 67 PC: 13c86 | Get or set file attributes
2018-12-17T22:47:38.27116876Z 62 PC: 14600 | Close file
2018-12-17T22:47:38.278055433Z 65 PC: 146f9 | Delete file (Filename = 'Victim.Exe')
2018-12-17T22:47:38.289476663Z 26 PC: 13d21 | Set disk transfer address
2018-12-17T22:47:38.291321637Z 79 PC: 13d26 | Find next file
2018-12-17T22:47:38.294497918Z 26 PC: 13d21 | Set disk transfer address
2018-12-17T22:47:38.295867526Z 79 PC: 13d26 | Find next file
2018-12-17T22:47:38.299886071Z 64 PC: 1450b | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:47:38.302138559Z 37 PC: 13fe1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:47:38.303488692Z 37 PC: 13fe1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:47:38.305548264Z 37 PC: 13fe1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:47:38.307231898Z 37 PC: 13fe1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:38.309000737Z 37 PC: 13fe1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:47:38.310553111Z 37 PC: 13fe1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:38.31232672Z 37 PC: 13fe1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:47:38.313472609Z 37 PC: 13fe1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:47:38.314579291Z 37 PC: 13fe1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:47:38.316655777Z 37 PC: 13fe1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:47:38.317853216Z 37 PC: 13fe1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:47:38.318983422Z 37 PC: 13fe1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:47:38.321064668Z 37 PC: 13fe1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:47:38.322143013Z 37 PC: 13fe1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:47:38.323192295Z 37 PC: 13fe1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:47:38.325085176Z 37 PC: 13fe1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:47:38.326603321Z 37 PC: 13fe1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:47:38.32770534Z 37 PC: 13fe1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:47:38.329616744Z 37 PC: 13fe1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:47:38.330935477Z 76 PC: 14020 | Terminate with return code (Return code = '0')