Sample viewer

vx.netlux.org/Virus.DOS.PS-MPC.349

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:50.870589678Z 26 PC: 12a70 | Set disk transfer address
2018-12-17T22:51:50.872774773Z 53 PC: 12a75 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:50.880885429Z 37 PC: 12a85 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:50.882142781Z 78 PC: 12a92 | Find first file
2018-12-17T22:51:50.889045368Z 61 PC: 12b91 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:51:50.897617471Z 63 PC: 12aa4 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:51:50.906388408Z 62 PC: 12aa8 | Close file
2018-12-17T22:51:50.908841065Z 67 PC: 12b9c | Get or set file attributes
2018-12-17T22:51:51.00038762Z 61 PC: 12b91 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:51:51.007794584Z 64 PC: 12b2b | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:51:51.011142714Z 66 PC: 12b33 | Move file pointer
2018-12-17T22:51:51.014231216Z 64 PC: 12b3e | Write file or device (Write 349 bytes on handle 5)
2018-12-17T22:51:51.023503033Z 87 PC: 12b4b | Get or set file date and time
2018-12-17T22:51:51.026490265Z 62 PC: 12b4f | Close file
2018-12-17T22:51:51.035330241Z 67 PC: 12b9c | Get or set file attributes
2018-12-17T22:51:51.046992479Z 37 PC: 12ae8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:51.048652828Z 26 PC: 12af1 | Set disk transfer address