Sample viewer

vx.netlux.org/Virus.DOS.Lhb.1989

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:14.9047471Z 53 PC: 12ebb | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:14.907091478Z 61 PC: 12b39 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:52:14.913112694Z 37 PC: 12b48 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:14.914328258Z 66 PC: 12b57 | Move file pointer
2018-12-17T22:52:14.915835149Z 63 PC: 12b65 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:52:14.919494967Z 62 PC: 12b69 | Close file
2018-12-17T22:52:14.921482649Z 37 PC: 12b78 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:14.922857883Z 61 PC: 12b90 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:52:14.930091928Z 63 PC: 12ba4 | Read file or device (Read 12 bytes on handle 5)
2018-12-17T22:52:14.932743159Z 66 PC: 12bad | Move file pointer
2018-12-17T22:52:14.934218267Z 64 PC: 12bd7 | Write file or device (Write 2000 bytes on handle 5)
2018-12-17T22:52:15.611197432Z 66 PC: 12be0 | Move file pointer
2018-12-17T22:52:15.612571018Z 64 PC: 12bee | Write file or device (Write 12 bytes on handle 5)
2018-12-17T22:52:15.61528939Z 62 PC: 12bf6 | Close file
2018-12-17T22:52:15.623209371Z 53 PC: 12cf5 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:52:15.624670097Z 53 PC: 12d04 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:15.626857728Z 76 PC: 12a44 | Terminate with return code (Return code = '0')