Sample viewer

vx.netlux.org/Virus.DOS.Small.666

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:14.575309369Z 254 PC: 157d2 | UNKNOWN!
2018-12-17T22:57:14.577341441Z 53 PC: 12a82 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:14.578515362Z 37 PC: 12a92 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:14.579693628Z 74 PC: 12a9c | Reallocate memory
2018-12-17T22:57:14.581437099Z 82 PC: 12aac | Get DOS internal pointers (SYSVARS)
2018-12-17T22:57:14.583202024Z 67 PC: 12b84 | Get or set file attributes
2018-12-17T22:57:14.58966164Z 53 PC: 12b96 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:14.591693363Z 67 PC: 12bb8 | Get or set file attributes
2018-12-17T22:57:14.606945577Z 61 PC: 12bc3 | Open file (Filename = '')
2018-12-17T22:57:14.614420326Z 63 PC: 12bd8 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:57:14.617317739Z 66 PC: 12be5 | Move file pointer
2018-12-17T22:57:14.619281473Z 63 PC: 12bfa | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:57:14.622658848Z 62 PC: 12c3c | Close file
2018-12-17T22:57:14.624741292Z 67 PC: 12c4e | Get or set file attributes
2018-12-17T22:57:14.63523392Z 53 PC: 12c82 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:14.637249732Z 75 PC: 12ad4 | Execute program
2018-12-17T22:57:14.654220501Z 53 PC: 13dad | Get interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:57:14.661779127Z 53 PC: 13c10 | Get interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:57:14.663484375Z 37 PC: 13c20 | Set interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:57:14.665096814Z 53 PC: 13c25 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:14.667324112Z 37 PC: 13c35 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:14.669203875Z 48 PC: 13c54 | Get DOS version
2018-12-17T22:57:14.670564359Z 73 PC: 13c60 | Release memory
2018-12-17T22:57:14.672584996Z 74 PC: 13c7b | Reallocate memory
2018-12-17T22:57:14.67586821Z 72 PC: 13c82 | Allocate memory
2018-12-17T22:57:14.677647318Z 73 PC: 13c88 | Release memory
2018-12-17T22:57:14.680598752Z 49 PC: 13cb8 | Terminate and stay resident (Return code = '0' | Memory size = '83')
2018-12-17T22:57:14.685971881Z 49 PC: 12aec | Terminate and stay resident (Return code = '0' | Memory size = '66')