Sample viewer

vx.netlux.org/Virus.DOS.Kaliostro.1520

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:29.544170232Z 153 PC: 15552 | UNKNOWN!
2018-12-17T22:54:29.546086805Z 74 PC: 15571 | Reallocate memory
2018-12-17T22:54:29.562857392Z 53 PC: 1559a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:54:29.564526496Z 88 PC: 155b6 | case 0xGet or set allocation strateg:
2018-12-17T22:54:29.566828338Z 88 PC: 155bc | case 0xGet or set allocation strateg:
2018-12-17T22:54:29.568278302Z 88 PC: 155c5 | case 0xGet or set allocation strateg:
2018-12-17T22:54:29.569637462Z 88 PC: 155d2 | case 0xGet or set allocation strateg:
2018-12-17T22:54:29.571469404Z 72 PC: 155da | Allocate memory
2018-12-17T22:54:29.57318955Z 88 PC: 155f1 | case 0xGet or set allocation strateg:
2018-12-17T22:54:29.574744272Z 88 PC: 155f9 | case 0xGet or set allocation strateg:
2018-12-17T22:54:29.576635477Z 37 PC: 15613 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:54:29.578260231Z 9 PC: 12a86 | Display string (Could not find end pointer)
2018-12-17T22:54:29.584443898Z 48 PC: 12a8f | Get DOS version
2018-12-17T22:54:29.58691821Z 44 PC: 9f1ce | Get time 0x9f1ce: xor ch, ch
0x9f1d0: add cl, 5
0x9f1d3: mov word ptr [0x4d0], cx
0x9f1d7: mov word ptr [0x4da], 0
0x9f1dd: mov ax, 0x4301
0x9f1e0: mov cx, 0x20
0x9f1e3: mov dx, 0x47c
0x9f1e6: pushf
0x9f1e7: lcall ptr [0x4e1]
0x9f1eb: mov ax, 0x3d02
0x9f1ee: pushf
0x9f1ef: lcall ptr [0x4e1]
0x9f1f3: jae 0x9f1f8
0x9f1f5: jmp 0x9f348
0x9f1f8: mov word ptr [0x4df], ax
0x9f1fb: mov ah, 0x3f
0x9f1fd: mov bx, word ptr [0x4df]
0x9f201: mov cx, 0x1c
0x9f204: mov dx, 3
0x9f207: pushf
2018-12-17T22:54:29.590315964Z 67 PC: 9f1eb | Get or set file attributes
2018-12-17T22:54:29.609007532Z 61 PC: 9f1f3 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:54:29.617675107Z 63 PC: 9f20c | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:54:29.621758583Z 62 PC: 9f348 | Close file
2018-12-17T22:54:29.623947955Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-17T22:54:29.628567309Z 93 PC: 12afe | File sharing functions
2018-12-17T22:54:29.630974183Z 9 PC: 12a86 | Display string (String= 'Size change=05FDh/01533d. ')
2018-12-17T22:54:29.634096385Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')