Sample viewer

vx.netlux.org/Virus.DOS.Enculator.1833

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:14.653090266Z 53 PC: 13c5f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:14.65541086Z 88 PC: 13e79 | case 0xGet or set allocation strateg:
2018-12-17T22:55:14.65733893Z 47 PC: 13fb6 | Get disk transfer address
2018-12-17T22:55:14.658730288Z 26 PC: 13bf7 | Set disk transfer address
2018-12-17T22:55:14.660622462Z 71 PC: 13fd1 | Get current directory
2018-12-17T22:55:14.663722286Z 53 PC: 13c5f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:14.665235449Z 37 PC: 13c64 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:14.66758537Z 67 PC: 13c77 | Get or set file attributes
2018-12-17T22:55:15.35984589Z 61 PC: 13c6f | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:55:15.377738791Z 63 PC: 13c45 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:55:15.381501444Z 66 PC: 13c22 | Move file pointer
2018-12-17T22:55:15.383889946Z 63 PC: 13c45 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:55:15.387071638Z 66 PC: 13c31 | Move file pointer
2018-12-17T22:55:15.389533291Z 66 PC: 13c5a | Move file pointer
2018-12-17T22:55:15.391268939Z 63 PC: 13c45 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:55:15.397555357Z 66 PC: 13c31 | Move file pointer
2018-12-17T22:55:15.400273955Z 64 PC: 13c13 | Write file or device (Write 1828 bytes on handle 5)
2018-12-17T22:55:15.411728164Z 64 PC: 13c3b | Write file or device (Write 5 bytes on handle 5)
2018-12-17T22:55:15.41454412Z 66 PC: 13c22 | Move file pointer
2018-12-17T22:55:15.41691088Z 64 PC: 13c3b | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:55:15.420267727Z 78 PC: 13bdb | Find first file
2018-12-17T22:55:15.426761643Z 78 PC: 13bdb | Find first file
2018-12-17T22:55:15.433944423Z 62 PC: 13c4f | Close file
2018-12-17T22:55:15.441595915Z 59 PC: 13c69 | Change current directory
2018-12-17T22:55:15.445699808Z 59 PC: 13c69 | Change current directory
2018-12-17T22:55:15.449525113Z 37 PC: 13c64 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:15.450955466Z 26 PC: 13bf7 | Set disk transfer address