Sample viewer

vx.netlux.org/Virus.DOS.Hooters.546

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:07.318650237Z 26 PC: 1412d | Set disk transfer address
2018-12-17T22:51:07.320771438Z 53 PC: 14135 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:07.322392893Z 37 PC: 14145 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:07.323585842Z 78 PC: 14154 | Find first file
2018-12-17T22:51:07.330907506Z 67 PC: 142fe | Get or set file attributes
2018-12-17T22:51:07.343800169Z 61 PC: 14163 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:51:07.350463979Z 63 PC: 14171 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:51:07.353480362Z 66 PC: 1417b | Move file pointer
2018-12-17T22:51:07.354905834Z 87 PC: 14192 | Get or set file date and time
2018-12-17T22:51:07.356224163Z 62 PC: 14196 | Close file
2018-12-17T22:51:07.361682966Z 67 PC: 142fe | Get or set file attributes
2018-12-17T22:51:07.376278068Z 79 PC: 14154 | Find next file
2018-12-17T22:51:07.378534827Z 37 PC: 141ba | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:07.380928651Z 26 PC: 141c6 | Set disk transfer address
2018-12-17T22:51:07.383374138Z 48 PC: 12a6d | Get DOS version
2018-12-17T22:51:07.386084595Z 9 PC: 12a84 | Display string (Could not find end pointer)
2018-12-17T22:51:07.400694256Z 61 PC: 12cc4 | Open file (Filename = '')
2018-12-17T22:51:07.409203522Z 9 PC: 12a92 | Display string (Could not find end pointer)
2018-12-17T22:51:07.41499967Z 93 PC: 12b31 | File sharing functions
2018-12-17T22:51:07.417605173Z 9 PC: 12b10 | Display string (String= 'Size change=+0223h/00547d. Virus might be activ? ')
2018-12-17T22:51:07.425086095Z 76 PC: 12b16 | Terminate with return code (Return code = '1')