Sample viewer

vx.netlux.org/Virus.DOS.Crow.1475

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:01:29.338699609Z 255 PC: 1b153 | UNKNOWN!
2018-12-17T22:01:29.340204765Z 74 PC: 1b163 | Reallocate memory
2018-12-17T22:01:29.341824802Z 74 PC: 1b16a | Reallocate memory
2018-12-17T22:01:29.343594588Z 72 PC: 1b171 | Allocate memory
2018-12-17T22:01:29.345764576Z 53 PC: 1b188 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:01:29.34704555Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:01:29.348150662Z 53 PC: 12b82 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:29.350129532Z 53 PC: 12b8f | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:01:29.351613865Z 53 PC: 12b9c | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:01:29.353269724Z 53 PC: 12ba9 | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:01:29.355745228Z 37 PC: 12bbd | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:29.357691343Z 74 PC: 12ad6 | Reallocate memory
2018-12-17T22:01:29.36086651Z 68 PC: 1896e | I/O control for devices (Set for = '��V')
2018-12-17T22:01:29.364803619Z 74 PC: 1905c | Reallocate memory
2018-12-17T22:01:29.367294453Z 74 PC: 1905c | Reallocate memory
2018-12-17T22:01:29.369346849Z 68 PC: 1896e | I/O control for devices (Set for = 'Turbo C++ - Copyright 1990 Borland Intl.')
2018-12-17T22:01:29.374867764Z 68 PC: 15e01 | I/O control for devices (Set for = '')
2018-12-17T22:01:29.37646163Z 68 PC: 15e0a | I/O control for devices (Set for = 'd page size value ignored')
2018-12-17T22:01:29.378225563Z 68 PC: 15e12 | I/O control for devices (Set for = 'd page size value ignored')
2018-12-17T22:01:29.380465945Z 68 PC: 15e1b | I/O control for devices (Set for = 'd page size value ignored')
2018-12-17T22:01:29.382552309Z 51 PC: 15e22 | Get or set Ctrl-Break
2018-12-17T22:01:29.38416409Z 64 PC: 197c3 | Write file or device (Write 52 bytes on handle 2)
2018-12-17T22:01:29.390873686Z 64 PC: 197c3 | Write file or device (Write 128 bytes on handle 1)
2018-12-17T22:01:29.398991245Z 64 PC: 197c3 | Write file or device (Write 128 bytes on handle 1)
2018-12-17T22:01:29.407525971Z 64 PC: 197c3 | Write file or device (Write 128 bytes on handle 1)
2018-12-17T22:01:29.416312919Z 64 PC: 197c3 | Write file or device (Write 128 bytes on handle 1)
2018-12-17T22:01:29.424187108Z 64 PC: 197c3 | Write file or device (Write 128 bytes on handle 1)
2018-12-17T22:01:29.437718849Z 64 PC: 197c3 | Write file or device (Write 87 bytes on handle 1)
2018-12-17T22:01:29.445155706Z 64 PC: 197c3 | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:01:29.449974753Z 64 PC: 197c3 | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:01:29.455728403Z 37 PC: 12bc9 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:29.457794805Z 37 PC: 12bd4 | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:01:29.460201724Z 37 PC: 12bdf | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:01:29.462895591Z 37 PC: 12bea | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:01:29.46528513Z 76 PC: 12b73 | Terminate with return code (Return code = '1')