Sample viewer

vx.netlux.org/Virus.DOS.Kolkris

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:59:59.506638721Z 255 PC: 12a53 | UNKNOWN!
2018-12-17T21:59:59.508610805Z 53 PC: 12aaa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:59:59.509852658Z 37 PC: 12abc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:59:59.511038155Z 74 PC: 12acd | Reallocate memory
2018-12-17T21:59:59.51304285Z 75 PC: 12b58 | Execute program
2018-12-17T21:59:59.53200549Z 53 PC: 12b58 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:59.533162315Z 37 PC: 12b58 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:59:59.535389385Z 67 PC: 12b58 | Get or set file attributes
2018-12-17T21:59:59.547695204Z 67 PC: 12b58 | Get or set file attributes
2018-12-17T22:00:01.056699474Z 61 PC: 12b58 | Open file (Filename = 'C:\DOS\KEYB.COM')
2018-12-17T22:00:01.063544633Z 87 PC: 12b58 | Get or set file date and time
2018-12-17T22:00:01.065513312Z 63 PC: 12b58 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:00:01.071366778Z 63 PC: 12b58 | Read file or device (Read 30 bytes on handle 5)
2018-12-17T22:00:01.073893302Z 66 PC: 12b58 | Move file pointer
2018-12-17T22:00:01.076254519Z 63 PC: 12b58 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:00:01.082704993Z 72 PC: 12b58 | Allocate memory
2018-12-17T22:00:01.084745581Z 64 PC: 12b58 | Write file or device (Write 1834 bytes on handle 5)
2018-12-17T22:00:01.096010449Z 73 PC: 12b58 | Release memory
2018-12-17T22:00:01.097702352Z 64 PC: 12b58 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:00:01.102590629Z 66 PC: 12b58 | Move file pointer
2018-12-17T22:00:01.105184294Z 64 PC: 12b58 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:00:01.108375199Z 87 PC: 12b58 | Get or set file date and time
2018-12-17T22:00:01.110002473Z 62 PC: 12b58 | Close file
2018-12-17T22:00:01.115900326Z 67 PC: 12b58 | Get or set file attributes
2018-12-17T22:00:01.122895039Z 37 PC: 12b58 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:00:01.124157848Z 75 PC: 12b02 | Execute program
2018-12-17T22:00:01.125798217Z 42 PC: 12b58 | Get date 0x12b58: ret
0x12b59: nop
0x12b5a: iret
0x12b5b: push bp
0x12b5c: add word ptr [bx + 0x11], dx
0x12b5f: push ax
0x12b60: push bx
0x12b61: push ds
0x12b62: push dx
0x12b63: push es
0x12b64: mov ax, 0x3524
0x12b67: call 0x22b52
0x12b6a: mov word ptr cs:[0x21b], bx
0x12b6f: mov word ptr cs:[0x21d], es
0x12b74: push cs
0x12b75: pop ds
0x12b76: mov dx, 0x219
0x12b79: mov ax, 0x2524
0x12b7c: call 0x22b52
0x12b7f: pop es
2018-12-17T22:00:01.128119021Z 77 PC: 12b28 | Get program return code
2018-12-17T22:00:01.129187816Z 49 PC: 12b37 | Terminate and stay resident (Return code = '0' | Memory size = '131')