Sample viewer

vx.netlux.org/Virus.DOS.Dream.2012

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:37.868016686Z 99 PC: 137ec | Get DBCS lead byte table pointer
2018-12-17T22:54:37.870542147Z 48 PC: 137f6 | Get DOS version
2018-12-17T22:54:37.873159811Z 53 PC: 137ff | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:54:37.875393503Z 53 PC: 1380b | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:54:37.877917081Z 37 PC: 1384f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:54:37.880577686Z 37 PC: 13856 | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:54:37.882144574Z 9 PC: 12a86 | Display string (String= 'Goat file (COM/....). Size=00000834h/0000002100d bytes. ')
2018-12-17T22:54:37.893484658Z 48 PC: 12a8f | Get DOS version
2018-12-17T22:54:37.89721221Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-17T22:54:37.907898564Z 93 PC: 12afe | File sharing functions
2018-12-17T22:54:37.912534105Z 9 PC: 12a86 | Display string (String= 'Size change=0832h/02098d. ')
2018-12-17T22:54:37.917620134Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')