Sample viewer

vx.netlux.org/Virus.DOS.Ksenia.5000.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:00:05.996939921Z 24 PC: 12cb6 | Reserved
2018-12-17T22:00:05.999032453Z 53 PC: 13345 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:00:06.000568176Z 37 PC: 13358 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:00:06.003478134Z 53 PC: 1335d | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:00:06.005652884Z 37 PC: 1336d | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:00:06.00759158Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.013303489Z 74 PC: 12d48 | Reallocate memory
2018-12-17T22:00:06.015330477Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.017183603Z 113 PC: 1376c | UNKNOWN!
2018-12-17T22:00:06.018777923Z 67 PC: 1376c | Get or set file attributes
2018-12-17T22:00:06.026469294Z 113 PC: 1376c | UNKNOWN!
2018-12-17T22:00:06.027738517Z 108 PC: 1376c | Extended open/create file
2018-12-17T22:00:06.035314571Z 68 PC: 1376c | I/O control for devices (Set for = '')
2018-12-17T22:00:06.037116079Z 66 PC: 1376c | Move file pointer
2018-12-17T22:00:06.038925898Z 66 PC: 1376c | Move file pointer
2018-12-17T22:00:06.041442535Z 63 PC: 1376c | Read file or device (Read 32 bytes on handle 5)
2018-12-17T22:00:06.044584185Z 66 PC: 1376c | Move file pointer
2018-12-17T22:00:06.046437675Z 63 PC: 1376c | Read file or device (Read 32 bytes on handle 5)
2018-12-17T22:00:06.050197215Z 66 PC: 1376c | Move file pointer
2018-12-17T22:00:06.05222616Z 87 PC: 1376c | Get or set file date and time
2018-12-17T22:00:06.053749491Z 44 PC: 1376c | Get time 0x1376c: ret
0x1376d: push ax
0x1376e: push dx
0x1376f: mov ax, 0x4400
0x13772: call 0x23767
0x13775: jb 0x1377b
0x13777: sub dl, 0x80
0x1377a: cmc
0x1377b: pop dx
0x1377c: pop ax
0x1377d: ret
0x1377e: xchg ah, al
0x13780: call 0x13789
0x13783: xchg ah, al
0x13785: call 0x13789
0x13788: ret
0x13789: cmp al, 0x61
0x1378b: jb 0x13793
0x1378d: cmp al, 0x7a
0x1378f: ja 0x13793
2018-12-17T22:00:06.055926964Z 66 PC: 1376c | Move file pointer
2018-12-17T22:00:06.061585556Z 64 PC: 1376c | Write file or device (Write 5000 bytes on handle 5)
2018-12-17T22:00:06.077503889Z 66 PC: 1376c | Move file pointer
2018-12-17T22:00:06.079042119Z 64 PC: 1376c | Write file or device (Write 32 bytes on handle 5)
2018-12-17T22:00:06.083084453Z 87 PC: 1376c | Get or set file date and time
2018-12-17T22:00:06.085121692Z 87 PC: 1376c | Get or set file date and time
2018-12-17T22:00:06.087052382Z 66 PC: 1376c | Move file pointer
2018-12-17T22:00:06.089579549Z 66 PC: 1376c | Move file pointer
2018-12-17T22:00:06.091502311Z 63 PC: 1376c | Read file or device (Read 32 bytes on handle 5)
2018-12-17T22:00:06.094457491Z 66 PC: 1376c | Move file pointer
2018-12-17T22:00:06.100501609Z 87 PC: 1376c | Get or set file date and time
2018-12-17T22:00:06.102973008Z 62 PC: 1376c | Close file
2018-12-17T22:00:06.110965823Z 113 PC: 1376c | UNKNOWN!
2018-12-17T22:00:06.112510969Z 75 PC: 12d69 | Execute program
2018-12-17T22:00:06.130471121Z 48 PC: 16a17 | Get DOS version
2018-12-17T22:00:06.132779376Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.137866916Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.141578686Z 73 PC: 12d73 | Release memory
2018-12-17T22:00:06.143351285Z 77 PC: 12d97 | Get program return code
2018-12-17T22:00:06.146149514Z 76 PC: 12d9b | Terminate with return code (Return code = '0')
2018-12-17T22:00:06.149374454Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:00:06.150706237Z 72 PC: 12174 | Allocate memory
2018-12-17T22:00:06.153136226Z 72 PC: 1218d | Allocate memory
2018-12-17T22:00:06.155086533Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:00:06.156394986Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:00:06.158913617Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:00:06.161348693Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.16271734Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.165212093Z 62 PC: 1376c | Close file
2018-12-17T22:00:06.168038637Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.169969437Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.171283815Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.173662947Z 62 PC: 1376c | Close file
2018-12-17T22:00:06.175559033Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.177713633Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.179853972Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.181622971Z 62 PC: 1376c | Close file
2018-12-17T22:00:06.183218459Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.185709362Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.187295711Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.18925013Z 62 PC: 1376c | Close file
2018-12-17T22:00:06.192831034Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.194956826Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.196515827Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.199112459Z 62 PC: 1376c | Close file
2018-12-17T22:00:06.200909301Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.20284268Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.204855579Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.206804575Z 62 PC: 1376c | Close file
2018-12-17T22:00:06.208683653Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.211900747Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.21341305Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.215348442Z 62 PC: 1376c | Close file
2018-12-17T22:00:06.218339491Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.221260157Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.222751421Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.225732752Z 62 PC: 1376c | Close file
2018-12-17T22:00:06.22762718Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.229715871Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.232177208Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.234182585Z 62 PC: 1376c | Close file
2018-12-17T22:00:06.236030117Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.238867875Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.240578543Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.242499727Z 62 PC: 1376c | Close file
2018-12-17T22:00:06.244568689Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.247236991Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.248711525Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.250849236Z 62 PC: 1376c | Close file
2018-12-17T22:00:06.252996116Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.255122253Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.256878695Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.259029317Z 62 PC: 1376c | Close file
2018-12-17T22:00:06.260879621Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.263242462Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.264958786Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.266663518Z 62 PC: 1376c | Close file
2018-12-17T22:00:06.268561852Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.270976556Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.27253894Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.27469848Z 62 PC: 1376c | Close file
2018-12-17T22:00:06.277512411Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.279666031Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.281195155Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.284195878Z 62 PC: 1376c | Close file
2018-12-17T22:00:06.286110162Z 68 PC: 1376c | I/O control for devices (Set for = 'mfyW Wv WWj W WcW WW W5W')
2018-12-17T22:00:06.28961344Z 99 PC: 9a5d7 | Get DBCS lead byte table pointer
2018-12-17T22:00:06.292523567Z 56 PC: 94df9 | Get or set country info
2018-12-17T22:00:06.294930989Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.296455562Z 68 PC: 1376c | I/O control for devices (Set for = ' %1 mm-dd-yy')
2018-12-17T22:00:06.299301068Z 68 PC: 1376c | I/O control for devices (Set for = ' %1 mm-dd-yy')
2018-12-17T22:00:06.301034243Z 64 PC: 1376c | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:00:06.305636722Z 68 PC: 1376c | I/O control for devices (Set for = ' %1 mm-dd-yy')
2018-12-17T22:00:06.308866671Z 25 PC: 94e62 | Get default drive
2018-12-17T22:00:06.311846177Z 71 PC: 970dd | Get current directory
2018-12-17T22:00:06.31625715Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:06.318590634Z 68 PC: 1376c | I/O control for devices (Set for = 'A:\ win TEMP=C:\WINDOWS\TEMP$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$MS DOS Version 6 (C)Copyright 1981-1994 Microsoft Corp Licensed Material - Property of Microsoft All rights reserved ')
2018-12-17T22:00:06.320740578Z 68 PC: 1376c | I/O control for devices (Set for = 'A:\ win TEMP=C:\WINDOWS\TEMP$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$MS DOS Version 6 (C)Copyright 1981-1994 Microsoft Corp Licensed Material - Property of Microsoft All rights reserved ')
2018-12-17T22:00:06.322500124Z 64 PC: 1376c | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:00:06.326433271Z 68 PC: 1376c | I/O control for devices (Set for = 'A:\ win TEMP=C:\WINDOWS\TEMP$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$MS DOS Version 6 (C)Copyright 1981-1994 Microsoft Corp Licensed Material - Property of Microsoft All rights reserved ')
2018-12-17T22:00:06.329244384Z 2 PC: 970b2 | Character output (Char = '3e')
2018-12-17T22:00:06.331956568Z 93 PC: 94f20 | File sharing functions
2018-12-17T22:00:06.334969327Z 93 PC: 94f27 | File sharing functions
2018-12-17T22:00:06.33763227Z 10 PC: 94f39 | Buffered keyboard input
2018-12-17T22:00:06.923220105Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:07.91319533Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:08.902872191Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:09.891389351Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:10.881486632Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:11.871770933Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:12.861300962Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:13.849962939Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:14.840955983Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:15.83064684Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:16.820458358Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:17.810793896Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:18.799360242Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:19.789488896Z 98 PC: 1376c | Get current PSP
2018-12-17T22:00:20.779074586Z 98 PC: 1376c | Get current PSP