Sample viewer

vx.netlux.org/Virus.DOS.Rajaat.443

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:25.419834291Z 48 PC: 12a4a | Get DOS version
2018-12-17T22:52:25.422702921Z 53 PC: 12a55 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:25.42384767Z 53 PC: 12a62 | Get interrupt vector (Interrupt = '40' AKA 'Random block write')
2018-12-17T22:52:25.42496201Z 37 PC: 12a72 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:25.427386899Z 37 PC: 12a7a | Set interrupt vector (Interrupt = '40' AKA 'Random block write')
2018-12-17T22:52:25.42867482Z 74 PC: 12a90 | Reallocate memory
2018-12-17T22:52:25.43008186Z 73 PC: 12a98 | Release memory
2018-12-17T22:52:25.431552576Z 61 PC: 12b80 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:52:25.438234721Z 62 PC: 12b80 | Close file
2018-12-17T22:52:25.439887659Z 75 PC: 12acf | Execute program
2018-12-17T22:52:25.448461082Z 49 PC: 12adc | Terminate and stay resident (Return code = '0' | Memory size = '58')