Sample viewer

vx.netlux.org/Virus.DOS.PCBB.3072.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:47:45.065798614Z 62 PC: 12a71 | Close file
2018-12-17T22:47:45.069671187Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.070734998Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.07177402Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:47:45.073434656Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.074506915Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.075513213Z 72 PC: 12174 | Allocate memory
2018-12-17T22:47:45.077620086Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.078781316Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.079855947Z 72 PC: 1218d | Allocate memory
2018-12-17T22:47:45.082465482Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.08359377Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.084626991Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:47:45.086098506Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.087350277Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.088347711Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:47:45.0894173Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.090577768Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.091561323Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.092646508Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.094434145Z 69 PC: 9e609 | Duplicate handle
2018-12-17T22:47:45.09595733Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.097037797Z 62 PC: 122ab | Close file
2018-12-17T22:47:45.099234296Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.100277456Z 69 PC: 9e609 | Duplicate handle
2018-12-17T22:47:45.101998728Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.103586968Z 62 PC: 122ab | Close file
2018-12-17T22:47:45.105237351Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.106872766Z 69 PC: 9e609 | Duplicate handle
2018-12-17T22:47:45.112123548Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.114069811Z 62 PC: 122ab | Close file
2018-12-17T22:47:45.116149104Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.118480844Z 69 PC: 9e609 | Duplicate handle
2018-12-17T22:47:45.120419818Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.121980555Z 62 PC: 122ab | Close file
2018-12-17T22:47:45.124459102Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.125842237Z 69 PC: 9e609 | Duplicate handle
2018-12-17T22:47:45.12749626Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.130053672Z 62 PC: 122ab | Close file
2018-12-17T22:47:45.131856359Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.134163708Z 69 PC: 9e609 | Duplicate handle
2018-12-17T22:47:45.136617676Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.138464347Z 62 PC: 122ab | Close file
2018-12-17T22:47:45.140262889Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.141917011Z 69 PC: 9e609 | Duplicate handle
2018-12-17T22:47:45.143779949Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.145277355Z 62 PC: 122ab | Close file
2018-12-17T22:47:45.147087181Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.148702207Z 69 PC: 9e609 | Duplicate handle
2018-12-17T22:47:45.150275438Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.151389184Z 62 PC: 122ab | Close file
2018-12-17T22:47:45.153609134Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.15505722Z 69 PC: 9e609 | Duplicate handle
2018-12-17T22:47:45.156713541Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.158278605Z 62 PC: 122ab | Close file
2018-12-17T22:47:45.159534544Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.160510049Z 69 PC: 9e609 | Duplicate handle
2018-12-17T22:47:45.16226063Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.163163521Z 62 PC: 122ab | Close file
2018-12-17T22:47:45.164355325Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.165796517Z 69 PC: 9e609 | Duplicate handle
2018-12-17T22:47:45.167046993Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.168029502Z 62 PC: 122ab | Close file
2018-12-17T22:47:45.16980905Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.170742441Z 69 PC: 9e609 | Duplicate handle
2018-12-17T22:47:45.172018236Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.173850647Z 62 PC: 122ab | Close file
2018-12-17T22:47:45.17552804Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.17636687Z 69 PC: 9e609 | Duplicate handle
2018-12-17T22:47:45.178462197Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.179524507Z 62 PC: 122ab | Close file
2018-12-17T22:47:45.180838449Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.182359204Z 69 PC: 9e609 | Duplicate handle
2018-12-17T22:47:45.183634968Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.184451407Z 62 PC: 122ab | Close file
2018-12-17T22:47:45.186347785Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.187384717Z 69 PC: 9e609 | Duplicate handle
2018-12-17T22:47:45.188763527Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.190413271Z 62 PC: 122ab | Close file
2018-12-17T22:47:45.192480304Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.193639621Z 61 PC: 9e609 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:47:45.200616253Z 63 PC: 9e609 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:47:45.203569601Z 62 PC: 9e609 | Close file
2018-12-17T22:47:45.205657661Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.207478771Z 61 PC: 12354 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:47:45.213542508Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.21463873Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.216131206Z 66 PC: 12372 | Move file pointer
2018-12-17T22:47:45.217774207Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.218895217Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.22073543Z 63 PC: 12383 | Read file or device (Read 44693 bytes on handle 5)
2018-12-17T22:47:45.233664466Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.234852059Z 69 PC: 9e609 | Duplicate handle
2018-12-17T22:47:45.244168334Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.24552804Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.246796811Z 87 PC: 9e79d | Get or set file date and time
2018-12-17T22:47:45.249850947Z 87 PC: 9e609 | Get or set file date and time
2018-12-17T22:47:45.252230643Z 62 PC: 9e609 | Close file
2018-12-17T22:47:45.578792437Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.580770384Z 62 PC: 1238a | Close file
2018-12-17T22:47:45.584195448Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.585442059Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.587425411Z 99 PC: 98db7 | Get DBCS lead byte table pointer
2018-12-17T22:47:45.588564596Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.589681443Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.5912681Z 56 PC: 935d9 | Get or set country info
2018-12-17T22:47:45.592816878Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.593899337Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.595473681Z 64 PC: 99028 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:47:45.59847961Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.599511154Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.601092717Z 25 PC: 93642 | Get default drive
2018-12-17T22:47:45.60241463Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.603374036Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.605069593Z 71 PC: 958bd | Get current directory
2018-12-17T22:47:45.617458746Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.618487533Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.619982705Z 64 PC: 99028 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:47:45.623507317Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.624719765Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.626343015Z 2 PC: 95892 | Character output (Char = '3e')
2018-12-17T22:47:45.628511526Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.629846271Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.631700172Z 93 PC: 93700 | File sharing functions
2018-12-17T22:47:45.633523385Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.634584914Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.636309289Z 93 PC: 93707 | File sharing functions
2018-12-17T22:47:45.638042514Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.639175271Z 37 PC: 9e609 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:45.64144561Z 10 PC: 93719 | Buffered keyboard input