Sample viewer

vx.netlux.org/Virus.DOS.Shanghai.848

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:42.682437306Z 187 PC: 20b24 | UNKNOWN!
2018-12-17T22:56:42.683713672Z 53 PC: 20b61 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:56:42.68517528Z 37 PC: 20b77 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:56:42.686915819Z 48 PC: 1329b | Get DOS version
2018-12-17T22:56:42.698245688Z 88 PC: 132b5 | case 0xGet or set allocation strateg:
2018-12-17T22:56:42.700185343Z 88 PC: 132be | case 0xGet or set allocation strateg:
2018-12-17T22:56:42.701826302Z 88 PC: 132d3 | case 0xGet or set allocation strateg:
2018-12-17T22:56:42.703647929Z 88 PC: 132da | case 0xGet or set allocation strateg:
2018-12-17T22:56:42.705120548Z 72 PC: 132fd | Allocate memory
2018-12-17T22:56:42.707239625Z 73 PC: 13308 | Release memory
2018-12-17T22:56:42.709265837Z 88 PC: 13346 | case 0xGet or set allocation strateg:
2018-12-17T22:56:42.710916141Z 88 PC: 13350 | case 0xGet or set allocation strateg:
2018-12-17T22:56:42.713575714Z 74 PC: 135bb | Reallocate memory
2018-12-17T22:56:42.715670513Z 48 PC: 13142 | Get DOS version
2018-12-17T22:56:42.717215719Z 93 PC: 13155 | File sharing functions
2018-12-17T22:56:42.718726965Z 52 PC: 1317b | Get InDOS flag pointer
2018-12-17T22:56:42.720811417Z 61 PC: 12e1e | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:56:42.725258432Z 63 PC: 12e1e | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:56:42.726910203Z 62 PC: 12e1e | Close file
2018-12-17T22:56:42.728727101Z 9 PC: 14492 | Display string (String= 'ET.COM Version 3.52 For ET16V (ETen Floppy Chinese System #5) (C)Copyright ETen Information System Corp 1985, 1992 ')
2018-12-17T22:56:42.733313376Z 9 PC: 1442f | Display string (String= 'ET.COM Has Been Modified !')
2018-12-17T22:56:42.737585147Z 9 PC: 14486 | Display string (String= ' ')