Sample viewer

vx.netlux.org/Virus.DOS.Lcv.864

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:39.002971173Z 37 PC: 12cd0 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:55:39.00555816Z 37 PC: 12cd0 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:55:39.006731103Z 37 PC: 12cd0 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:39.007865901Z 37 PC: 12cd0 | Set interrupt vector (Interrupt = '25' AKA 'Get default drive')
2018-12-17T22:55:39.009864137Z 37 PC: 12cd0 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:55:39.014894548Z 53 PC: 12c53 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:39.016569718Z 37 PC: 12c63 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:39.018355171Z 48 PC: 12ced | Get DOS version
2018-12-17T22:55:39.020103073Z 78 PC: 12d42 | Find first file
2018-12-17T22:55:39.030456538Z 67 PC: 12bdc | Get or set file attributes
2018-12-17T22:55:39.045958271Z 61 PC: 12bf1 | Open file (Filename = '')
2018-12-17T22:55:39.053733079Z 63 PC: 12b86 | Read file or device (Read 18 bytes on handle 5)
2018-12-17T22:55:39.060391284Z 87 PC: 12c03 | Get or set file date and time
2018-12-17T22:55:39.061762802Z 63 PC: 12ba1 | Read file or device (Read 389 bytes on handle 5)
2018-12-17T22:55:39.064914642Z 66 PC: 12bc1 | Move file pointer
2018-12-17T22:55:39.066227589Z 64 PC: 12bd2 | Write file or device (Write 864 bytes on handle 5)
2018-12-17T22:55:39.080175097Z 64 PC: 12c98 | Write file or device (Write 407 bytes on handle 5)
2018-12-17T22:55:39.088397636Z 87 PC: 12b15 | Get or set file date and time
2018-12-17T22:55:39.090119329Z 62 PC: 12b1e | Close file
2018-12-17T22:55:39.097838684Z 67 PC: 12b02 | Get or set file attributes
2018-12-17T22:55:39.108292964Z 37 PC: 12c72 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:39.110111937Z 9 PC: 12a67 | Display string (String= 'This is a tiny COM program. ')