Sample viewer

vx.netlux.org/Virus.DOS.Intruder.654

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:45.796177051Z 47 PC: 1416c | Get disk transfer address
2018-12-17T22:51:45.798577681Z 26 PC: 14175 | Set disk transfer address
2018-12-17T22:51:45.800144439Z 78 PC: 14251 | Find first file
2018-12-17T22:51:45.806443326Z 61 PC: 14267 | Open file (Filename = 'ÿÿÿÿÿÿÿÿÿÿÿÿÿÿ~h')
2018-12-17T22:51:45.814011201Z 63 PC: 14275 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:51:45.816802514Z 62 PC: 1429f | Close file
2018-12-17T22:51:45.818881602Z 79 PC: 1425c | Find next file
2018-12-17T22:51:45.823270852Z 26 PC: 1418e | Set disk transfer address
2018-12-17T22:51:45.824718524Z 48 PC: 12a6d | Get DOS version
2018-12-17T22:51:45.826029092Z 9 PC: 12a84 | Display string (Could not find end pointer)
2018-12-17T22:51:45.837061028Z 61 PC: 12cc4 | Open file (Filename = '')
2018-12-17T22:51:45.844654432Z 9 PC: 12a92 | Display string (Could not find end pointer)
2018-12-17T22:51:45.847395446Z 93 PC: 12b31 | File sharing functions
2018-12-17T22:51:45.849941936Z 9 PC: 12b10 | Display string (String= 'Size change=+029Bh/00667d. Virus might be activ? ')
2018-12-17T22:51:45.855790337Z 76 PC: 12b16 | Terminate with return code (Return code = '1')