Sample viewer

vx.netlux.org/Virus.DOS.Beer.1835

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:43.395044774Z 48 PC: 16ee8 | Get DOS version
2018-12-17T22:51:43.396817802Z 53 PC: 16f67 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:43.398050044Z 37 PC: 16f9e | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:43.399136879Z 48 PC: 16fdc | Get DOS version
2018-12-17T22:51:43.401476063Z 53 PC: 16fe6 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:43.402721248Z 37 PC: 16ffb | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:43.403799667Z 47 PC: 17001 | Get disk transfer address
2018-12-17T22:51:43.405128795Z 26 PC: 17011 | Set disk transfer address
2018-12-17T22:51:43.40780208Z 78 PC: 1701b | Find first file
2018-12-17T22:51:43.414239982Z 53 PC: 9ee84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:43.415402318Z 37 PC: 9ee84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:43.417689796Z 67 PC: 9ee84 | Get or set file attributes
2018-12-17T22:51:43.422943051Z 37 PC: 9ee84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:43.424821093Z 61 PC: 17022 | Open file
2018-12-17T22:51:43.430667912Z 37 PC: 1704b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:43.431784126Z 26 PC: 17054 | Set disk transfer address
2018-12-17T22:51:43.432911129Z 9 PC: 12a4c | Display string (Could not find end pointer)
2018-12-17T22:51:43.614995584Z 76 PC: 12a51 | Terminate with return code (Return code = '0')