Sample viewer

vx.netlux.org/Virus.DOS.Triyanto.2234

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:45.110509275Z 53 PC: 168f2 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:55:45.112737646Z 53 PC: 168f2 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:55:45.115094057Z 53 PC: 168f2 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:55:45.117114496Z 53 PC: 168f2 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:45.119156717Z 53 PC: 168f2 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:45.1219659Z 53 PC: 168f2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:45.123914595Z 53 PC: 168f2 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:55:45.12590618Z 53 PC: 168f2 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:55:45.128935157Z 53 PC: 168f2 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:55:45.130948774Z 53 PC: 168f2 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:55:45.133003097Z 53 PC: 168f2 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:55:45.136111863Z 53 PC: 168f2 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:55:45.149902297Z 53 PC: 168f2 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:55:45.151404402Z 53 PC: 168f2 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:55:45.153973925Z 53 PC: 168f2 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:55:45.155862026Z 53 PC: 168f2 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:55:45.157769193Z 53 PC: 168f2 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:55:45.160025867Z 53 PC: 168f2 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:55:45.163659099Z 53 PC: 168f2 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:55:45.165702692Z 37 PC: 16907 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:55:45.176258554Z 37 PC: 1690f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:55:45.178557828Z 37 PC: 16917 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:45.179950266Z 37 PC: 1691f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:55:45.181573128Z 68 PC: 16ef2 | I/O control for devices (Set for = '\��J�+��A� �f:�#1�b1������')
2018-12-17T22:55:45.284136732Z 37 PC: 16315 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:55:45.444784929Z 60 PC: 16ed9 | Create or truncate file
2018-12-17T22:55:45.450747092Z 68 PC: 16ef2 | I/O control for devices (Set for = 'LPT1')
2018-12-17T22:55:45.453887768Z 68 PC: 1493a | I/O control for devices (Set for = '')
2018-12-17T22:55:45.456146126Z 68 PC: 14944 | I/O control for devices (Set for = '')
2018-12-17T22:55:45.458956841Z 53 PC: 1618a | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:55:45.466323575Z 37 PC: 161a6 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:55:45.467810451Z 25 PC: 161da | Get default drive
2018-12-17T22:55:45.469128911Z 71 PC: 161f9 | Get current directory
2018-12-17T22:55:45.473784467Z 61 PC: 17c4a | Open file (Filename = 'A:\README.TXT')