Sample viewer

vx.netlux.org/Virus.DOS.Gotcha.627

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:13.832600499Z 218 PC: 12c70 | UNKNOWN!
2018-12-17T22:52:13.835215156Z 48 PC: 12c7a | Get DOS version
2018-12-17T22:52:13.837474939Z 37 PC: 12cbb | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:13.83916083Z 9 PC: 12c22 | Display string (Could not find end pointer)
2018-12-17T22:52:13.844144005Z 76 PC: 12c28 | Terminate with return code (Return code = '0')
2018-12-17T22:52:13.848495009Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:52:13.849815422Z 72 PC: 12174 | Allocate memory
2018-12-17T22:52:13.851765374Z 72 PC: 1218d | Allocate memory
2018-12-17T22:52:13.854579733Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:52:13.856129631Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:52:13.857419833Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:13.859685375Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:13.861699612Z 62 PC: 122ab | Close file
2018-12-17T22:52:13.864914127Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:13.86717202Z 62 PC: 122ab | Close file
2018-12-17T22:52:13.868857256Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:13.871108606Z 62 PC: 122ab | Close file
2018-12-17T22:52:13.875336058Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:13.877146184Z 62 PC: 122ab | Close file
2018-12-17T22:52:13.878793389Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:13.880800069Z 62 PC: 122ab | Close file
2018-12-17T22:52:13.882864134Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:13.884591782Z 62 PC: 122ab | Close file
2018-12-17T22:52:13.886293365Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:13.894086115Z 62 PC: 122ab | Close file
2018-12-17T22:52:13.896282562Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:13.89843415Z 62 PC: 122ab | Close file
2018-12-17T22:52:13.902421117Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:13.905355117Z 62 PC: 122ab | Close file
2018-12-17T22:52:13.907660556Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:13.912021927Z 62 PC: 122ab | Close file
2018-12-17T22:52:13.914232444Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:13.916412671Z 62 PC: 122ab | Close file
2018-12-17T22:52:13.919097423Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:13.921955199Z 62 PC: 122ab | Close file
2018-12-17T22:52:13.923747747Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:13.926032313Z 62 PC: 122ab | Close file
2018-12-17T22:52:13.928371819Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:13.930108649Z 62 PC: 122ab | Close file
2018-12-17T22:52:13.932481006Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:13.941819419Z 62 PC: 122ab | Close file
2018-12-17T22:52:13.945400682Z 99 PC: 9a247 | Get DBCS lead byte table pointer
2018-12-17T22:52:13.947439799Z 56 PC: 94a69 | Get or set country info
2018-12-17T22:52:13.950726976Z 64 PC: 9a4b8 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:52:13.956356161Z 25 PC: 94ad2 | Get default drive
2018-12-17T22:52:13.958655465Z 71 PC: 96d4d | Get current directory
2018-12-17T22:52:13.964128941Z 64 PC: 9a4b8 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:52:13.968136744Z 2 PC: 96d22 | Character output (Char = '3e')
2018-12-17T22:52:13.971002843Z 93 PC: 94b90 | File sharing functions
2018-12-17T22:52:13.97423052Z 93 PC: 94b97 | File sharing functions
2018-12-17T22:52:13.976631968Z 10 PC: 94ba9 | Buffered keyboard input
2018-12-17T22:52:28.80613308Z 0 PC: 0 | Program terminate
2018-12-17T22:52:30.159899979Z 0 PC: 0 | Program terminate
2018-12-17T22:52:30.262252995Z 64 PC: 9a4b8 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:52:30.266635429Z 41 PC: 94c1e | Parse filename
2018-12-17T22:52:30.268128568Z 41 PC: 94c9f | Parse filename
2018-12-17T22:52:30.26956219Z 41 PC: 94cbc | Parse filename
2018-12-17T22:52:30.271874635Z 26 PC: 98167 | Set disk transfer address
2018-12-17T22:52:30.273393921Z 71 PC: 98363 | Get current directory
2018-12-17T22:52:30.279902103Z 78 PC: 9836e | Find first file
2018-12-17T22:52:30.291493486Z 71 PC: 981dc | Get current directory
2018-12-17T22:52:30.295669101Z 73 PC: 97879 | Release memory
2018-12-17T22:52:30.298246579Z 61 PC: 9fa29 | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T22:52:30.305868967Z 98 PC: 9fa50 | Get current PSP
2018-12-17T22:52:30.306900636Z 51 PC: 9fa77 | Get or set Ctrl-Break
2018-12-17T22:52:30.318375758Z 51 PC: 9fa7d | Get or set Ctrl-Break
2018-12-17T22:52:30.319857926Z 53 PC: 9fa84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:30.321346748Z 37 PC: 9fa92 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:30.324354962Z 63 PC: 9fb06 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:52:30.33585757Z 63 PC: 9fb17 | Read file or device (Read 24 bytes on handle 5)
2018-12-17T22:52:30.33920279Z 62 PC: 9fa49 | Close file
2018-12-17T22:52:30.341605771Z 37 PC: 9fb9f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:30.342798883Z 51 PC: 9fba3 | Get or set Ctrl-Break
2018-12-17T22:52:30.344137808Z 75 PC: 11821 | Execute program
2018-12-17T22:52:30.355068594Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T22:52:30.360032472Z 76 PC: 12a4b | Terminate with return code (Return code = '36')
2018-12-17T22:52:30.365035759Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:52:30.366627878Z 72 PC: 12174 | Allocate memory
2018-12-17T22:52:30.368708919Z 72 PC: 1218d | Allocate memory
2018-12-17T22:52:30.37119007Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:52:30.372698315Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:52:30.374210281Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:30.376504049Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:30.378698525Z 62 PC: 122ab | Close file
2018-12-17T22:52:30.3808339Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:30.383300472Z 62 PC: 122ab | Close file
2018-12-17T22:52:30.385262743Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:30.38724612Z 62 PC: 122ab | Close file
2018-12-17T22:52:30.38935597Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:30.391783696Z 62 PC: 122ab | Close file
2018-12-17T22:52:30.393884882Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:30.396068431Z 62 PC: 122ab | Close file
2018-12-17T22:52:30.398938459Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:30.400702016Z 62 PC: 122ab | Close file
2018-12-17T22:52:30.402435687Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:30.410867216Z 62 PC: 122ab | Close file
2018-12-17T22:52:30.413023934Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:30.418140535Z 62 PC: 122ab | Close file
2018-12-17T22:52:30.423521783Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:30.425784756Z 62 PC: 122ab | Close file
2018-12-17T22:52:30.427966159Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:30.43097855Z 62 PC: 122ab | Close file
2018-12-17T22:52:30.43336458Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:30.435561565Z 62 PC: 122ab | Close file
2018-12-17T22:52:30.438387047Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:30.440432262Z 62 PC: 122ab | Close file
2018-12-17T22:52:30.442500623Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:30.44467983Z 62 PC: 122ab | Close file
2018-12-17T22:52:30.447856942Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:30.450057821Z 62 PC: 122ab | Close file
2018-12-17T22:52:30.452214939Z 69 PC: 9fa29 | Duplicate handle
2018-12-17T22:52:30.45525481Z 62 PC: 122ab | Close file
2018-12-17T22:52:30.459389878Z 99 PC: 9a247 | Get DBCS lead byte table pointer
2018-12-17T22:52:30.461430823Z 56 PC: 94a69 | Get or set country info
2018-12-17T22:52:30.464783329Z 64 PC: 9a4b8 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:52:30.470424585Z 25 PC: 94ad2 | Get default drive
2018-12-17T22:52:30.472491085Z 71 PC: 96d4d | Get current directory
2018-12-17T22:52:30.47725197Z 64 PC: 9a4b8 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:52:30.481657791Z 2 PC: 96d22 | Character output (Char = '3e')
2018-12-17T22:52:30.484508632Z 93 PC: 94b90 | File sharing functions
2018-12-17T22:52:30.486825283Z 93 PC: 94b97 | File sharing functions
2018-12-17T22:52:30.490865386Z 10 PC: 94ba9 | Buffered keyboard input