Sample viewer

vx.netlux.org/Virus.DOS.Favor.2576

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:14.112447778Z 148 PC: 12b46 | UNKNOWN!
2018-12-17T22:57:14.114122758Z 53 PC: 13255 | Get interrupt vector (Interrupt = '44' AKA 'Get time')
2018-12-17T22:57:14.115260628Z 53 PC: 1325c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:14.116402033Z 82 PC: 12b52 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:57:14.120548152Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.121873594Z 77 PC: 9f474 | Get program return code
2018-12-17T22:57:14.123656221Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.12469824Z 72 PC: 9f474 | Allocate memory
2018-12-17T22:57:14.127729958Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.128789924Z 72 PC: 9f474 | Allocate memory
2018-12-17T22:57:14.132284717Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.134127108Z 37 PC: 9f474 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:57:14.135728707Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.13661416Z 37 PC: 9f474 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:14.13905613Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.140131812Z 37 PC: 9f474 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:14.142394856Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.144485402Z 62 PC: 9f474 | Close file
2018-12-17T22:57:14.14680831Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.147695705Z 44 PC: 9f474 | Get time 0x9f474: call 0x9f4b5
0x9f477: pushf
0x9f478: push ds
0x9f479: push ax
0x9f47a: mov ax, word ptr cs:[0x114]
0x9f47e: mov ds, ax
0x9f480: mov ax, word ptr cs:[0x107]
0x9f484: mov word ptr [0xa], ax
0x9f487: mov ax, word ptr cs:[0x109]
0x9f48b: mov word ptr [0xc], ax
0x9f48e: pop ax
0x9f48f: pop ds
0x9f490: popf
0x9f491: ret
0x9f492: pushf
0x9f493: push cx
0x9f494: push es
0x9f495: push ds
0x9f496: push si
0x9f497: push di
2018-12-17T22:57:14.150882491Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.151728458Z 62 PC: 9f474 | Close file
2018-12-17T22:57:14.154084775Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.155824663Z 44 PC: 9f474 | Get time 0x9f474: call 0x9f4b5
0x9f477: pushf
0x9f478: push ds
0x9f479: push ax
0x9f47a: mov ax, word ptr cs:[0x114]
0x9f47e: mov ds, ax
0x9f480: mov ax, word ptr cs:[0x107]
0x9f484: mov word ptr [0xa], ax
0x9f487: mov ax, word ptr cs:[0x109]
0x9f48b: mov word ptr [0xc], ax
0x9f48e: pop ax
0x9f48f: pop ds
0x9f490: popf
0x9f491: ret
0x9f492: pushf
0x9f493: push cx
0x9f494: push es
0x9f495: push ds
0x9f496: push si
0x9f497: push di
2018-12-17T22:57:14.158739194Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.159794826Z 62 PC: 9f474 | Close file
2018-12-17T22:57:14.162360187Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.164309784Z 44 PC: 9f474 | Get time 0x9f474: call 0x9f4b5
0x9f477: pushf
0x9f478: push ds
0x9f479: push ax
0x9f47a: mov ax, word ptr cs:[0x114]
0x9f47e: mov ds, ax
0x9f480: mov ax, word ptr cs:[0x107]
0x9f484: mov word ptr [0xa], ax
0x9f487: mov ax, word ptr cs:[0x109]
0x9f48b: mov word ptr [0xc], ax
0x9f48e: pop ax
0x9f48f: pop ds
0x9f490: popf
0x9f491: ret
0x9f492: pushf
0x9f493: push cx
0x9f494: push es
0x9f495: push ds
0x9f496: push si
0x9f497: push di
2018-12-17T22:57:14.166889338Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.167927868Z 62 PC: 9f474 | Close file
2018-12-17T22:57:14.171117313Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.172339609Z 44 PC: 9f474 | Get time 0x9f474: call 0x9f4b5
0x9f477: pushf
0x9f478: push ds
0x9f479: push ax
0x9f47a: mov ax, word ptr cs:[0x114]
0x9f47e: mov ds, ax
0x9f480: mov ax, word ptr cs:[0x107]
0x9f484: mov word ptr [0xa], ax
0x9f487: mov ax, word ptr cs:[0x109]
0x9f48b: mov word ptr [0xc], ax
0x9f48e: pop ax
0x9f48f: pop ds
0x9f490: popf
0x9f491: ret
0x9f492: pushf
0x9f493: push cx
0x9f494: push es
0x9f495: push ds
0x9f496: push si
0x9f497: push di
2018-12-17T22:57:14.174985699Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.176421991Z 62 PC: 9f474 | Close file
2018-12-17T22:57:14.17813133Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.178964411Z 44 PC: 9f474 | Get time 0x9f474: call 0x9f4b5
0x9f477: pushf
0x9f478: push ds
0x9f479: push ax
0x9f47a: mov ax, word ptr cs:[0x114]
0x9f47e: mov ds, ax
0x9f480: mov ax, word ptr cs:[0x107]
0x9f484: mov word ptr [0xa], ax
0x9f487: mov ax, word ptr cs:[0x109]
0x9f48b: mov word ptr [0xc], ax
0x9f48e: pop ax
0x9f48f: pop ds
0x9f490: popf
0x9f491: ret
0x9f492: pushf
0x9f493: push cx
0x9f494: push es
0x9f495: push ds
0x9f496: push si
0x9f497: push di
2018-12-17T22:57:14.182327793Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.183121511Z 62 PC: 9f474 | Close file
2018-12-17T22:57:14.184946267Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.186849503Z 44 PC: 9f474 | Get time 0x9f474: call 0x9f4b5
0x9f477: pushf
0x9f478: push ds
0x9f479: push ax
0x9f47a: mov ax, word ptr cs:[0x114]
0x9f47e: mov ds, ax
0x9f480: mov ax, word ptr cs:[0x107]
0x9f484: mov word ptr [0xa], ax
0x9f487: mov ax, word ptr cs:[0x109]
0x9f48b: mov word ptr [0xc], ax
0x9f48e: pop ax
0x9f48f: pop ds
0x9f490: popf
0x9f491: ret
0x9f492: pushf
0x9f493: push cx
0x9f494: push es
0x9f495: push ds
0x9f496: push si
0x9f497: push di
2018-12-17T22:57:14.188476454Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.191072676Z 62 PC: 9f474 | Close file
2018-12-17T22:57:14.193403827Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.194308085Z 44 PC: 9f474 | Get time 0x9f474: call 0x9f4b5
0x9f477: pushf
0x9f478: push ds
0x9f479: push ax
0x9f47a: mov ax, word ptr cs:[0x114]
0x9f47e: mov ds, ax
0x9f480: mov ax, word ptr cs:[0x107]
0x9f484: mov word ptr [0xa], ax
0x9f487: mov ax, word ptr cs:[0x109]
0x9f48b: mov word ptr [0xc], ax
0x9f48e: pop ax
0x9f48f: pop ds
0x9f490: popf
0x9f491: ret
0x9f492: pushf
0x9f493: push cx
0x9f494: push es
0x9f495: push ds
0x9f496: push si
0x9f497: push di
2018-12-17T22:57:14.196914248Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.198279328Z 62 PC: 9f474 | Close file
2018-12-17T22:57:14.201868498Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.203009691Z 44 PC: 9f474 | Get time 0x9f474: call 0x9f4b5
0x9f477: pushf
0x9f478: push ds
0x9f479: push ax
0x9f47a: mov ax, word ptr cs:[0x114]
0x9f47e: mov ds, ax
0x9f480: mov ax, word ptr cs:[0x107]
0x9f484: mov word ptr [0xa], ax
0x9f487: mov ax, word ptr cs:[0x109]
0x9f48b: mov word ptr [0xc], ax
0x9f48e: pop ax
0x9f48f: pop ds
0x9f490: popf
0x9f491: ret
0x9f492: pushf
0x9f493: push cx
0x9f494: push es
0x9f495: push ds
0x9f496: push si
0x9f497: push di
2018-12-17T22:57:14.206309473Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.207445281Z 62 PC: 9f474 | Close file
2018-12-17T22:57:14.209987911Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.21133159Z 44 PC: 9f474 | Get time 0x9f474: call 0x9f4b5
0x9f477: pushf
0x9f478: push ds
0x9f479: push ax
0x9f47a: mov ax, word ptr cs:[0x114]
0x9f47e: mov ds, ax
0x9f480: mov ax, word ptr cs:[0x107]
0x9f484: mov word ptr [0xa], ax
0x9f487: mov ax, word ptr cs:[0x109]
0x9f48b: mov word ptr [0xc], ax
0x9f48e: pop ax
0x9f48f: pop ds
0x9f490: popf
0x9f491: ret
0x9f492: pushf
0x9f493: push cx
0x9f494: push es
0x9f495: push ds
0x9f496: push si
0x9f497: push di
2018-12-17T22:57:14.213748503Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.214456955Z 62 PC: 9f474 | Close file
2018-12-17T22:57:14.217301745Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.218346051Z 44 PC: 9f474 | Get time 0x9f474: call 0x9f4b5
0x9f477: pushf
0x9f478: push ds
0x9f479: push ax
0x9f47a: mov ax, word ptr cs:[0x114]
0x9f47e: mov ds, ax
0x9f480: mov ax, word ptr cs:[0x107]
0x9f484: mov word ptr [0xa], ax
0x9f487: mov ax, word ptr cs:[0x109]
0x9f48b: mov word ptr [0xc], ax
0x9f48e: pop ax
0x9f48f: pop ds
0x9f490: popf
0x9f491: ret
0x9f492: pushf
0x9f493: push cx
0x9f494: push es
0x9f495: push ds
0x9f496: push si
0x9f497: push di
2018-12-17T22:57:14.220646993Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.221488738Z 62 PC: 9f474 | Close file
2018-12-17T22:57:14.233773947Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.234533176Z 44 PC: 9f474 | Get time 0x9f474: call 0x9f4b5
0x9f477: pushf
0x9f478: push ds
0x9f479: push ax
0x9f47a: mov ax, word ptr cs:[0x114]
0x9f47e: mov ds, ax
0x9f480: mov ax, word ptr cs:[0x107]
0x9f484: mov word ptr [0xa], ax
0x9f487: mov ax, word ptr cs:[0x109]
0x9f48b: mov word ptr [0xc], ax
0x9f48e: pop ax
0x9f48f: pop ds
0x9f490: popf
0x9f491: ret
0x9f492: pushf
0x9f493: push cx
0x9f494: push es
0x9f495: push ds
0x9f496: push si
0x9f497: push di
2018-12-17T22:57:14.236754375Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.238330902Z 62 PC: 9f474 | Close file
2018-12-17T22:57:14.240832621Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.241867272Z 44 PC: 9f474 | Get time 0x9f474: call 0x9f4b5
0x9f477: pushf
0x9f478: push ds
0x9f479: push ax
0x9f47a: mov ax, word ptr cs:[0x114]
0x9f47e: mov ds, ax
0x9f480: mov ax, word ptr cs:[0x107]
0x9f484: mov word ptr [0xa], ax
0x9f487: mov ax, word ptr cs:[0x109]
0x9f48b: mov word ptr [0xc], ax
0x9f48e: pop ax
0x9f48f: pop ds
0x9f490: popf
0x9f491: ret
0x9f492: pushf
0x9f493: push cx
0x9f494: push es
0x9f495: push ds
0x9f496: push si
0x9f497: push di
2018-12-17T22:57:14.244779345Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.245536141Z 62 PC: 9f474 | Close file
2018-12-17T22:57:14.247597703Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.249370233Z 44 PC: 9f474 | Get time 0x9f474: call 0x9f4b5
0x9f477: pushf
0x9f478: push ds
0x9f479: push ax
0x9f47a: mov ax, word ptr cs:[0x114]
0x9f47e: mov ds, ax
0x9f480: mov ax, word ptr cs:[0x107]
0x9f484: mov word ptr [0xa], ax
0x9f487: mov ax, word ptr cs:[0x109]
0x9f48b: mov word ptr [0xc], ax
0x9f48e: pop ax
0x9f48f: pop ds
0x9f490: popf
0x9f491: ret
0x9f492: pushf
0x9f493: push cx
0x9f494: push es
0x9f495: push ds
0x9f496: push si
0x9f497: push di
2018-12-17T22:57:14.251679474Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.252415135Z 62 PC: 9f474 | Close file
2018-12-17T22:57:14.256589784Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.257509656Z 44 PC: 9f474 | Get time 0x9f474: call 0x9f4b5
0x9f477: pushf
0x9f478: push ds
0x9f479: push ax
0x9f47a: mov ax, word ptr cs:[0x114]
0x9f47e: mov ds, ax
0x9f480: mov ax, word ptr cs:[0x107]
0x9f484: mov word ptr [0xa], ax
0x9f487: mov ax, word ptr cs:[0x109]
0x9f48b: mov word ptr [0xc], ax
0x9f48e: pop ax
0x9f48f: pop ds
0x9f490: popf
0x9f491: ret
0x9f492: pushf
0x9f493: push cx
0x9f494: push es
0x9f495: push ds
0x9f496: push si
0x9f497: push di
2018-12-17T22:57:14.260273832Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.261963723Z 62 PC: 9f474 | Close file
2018-12-17T22:57:14.265834252Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.266804264Z 99 PC: 9f474 | Get DBCS lead byte table pointer
2018-12-17T22:57:14.271413341Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.272372542Z 56 PC: 9f474 | Get or set country info
2018-12-17T22:57:14.274598032Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.278001413Z 64 PC: 9f474 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:57:14.283676626Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.284808711Z 25 PC: 9f474 | Get default drive
2018-12-17T22:57:14.288852131Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.289897967Z 71 PC: 9f474 | Get current directory
2018-12-17T22:57:14.305312239Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.307230746Z 64 PC: 9f474 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:57:14.312349748Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.313099866Z 2 PC: 9f474 | Character output (Char = '3e')
2018-12-17T22:57:14.317401765Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.31823434Z 93 PC: 9f474 | File sharing functions
2018-12-17T22:57:14.321645269Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.323176885Z 93 PC: 9f474 | File sharing functions
2018-12-17T22:57:14.325438379Z 98 PC: 9f44b | Get current PSP
2018-12-17T22:57:14.326499345Z 10 PC: 9f474 | Buffered keyboard input