Sample viewer

vx.netlux.org/Virus.DOS.Ghost_2.5000.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:58:17.438230663Z 84 PC: 12c58 | Get verify flag
2018-12-17T22:58:17.453406498Z 82 PC: 12c93 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:58:17.455043231Z 42 PC: 12cfc | Get date 0x12cfc: rol dl, 4
0x12cff: rol dh, 4
0x12d02: rol cl, 4
0x12d05: mov byte ptr [0x105], cl
0x12d09: mov byte ptr [0x106], dh
0x12d0d: mov byte ptr [0x107], dl
0x12d11: cmp dh, 8
0x12d14: jne 0x12e6f
0x12d18: call 0x22c2e
0x12d1b: mov ah, al
0x12d1d: call 0x22c2e
0x12d20: push cs
0x12d21: pop es
0x12d22: cld
0x12d23: xchg ax, bp
0x12d24: mov ah, 0
0x12d26: int 0x13
0x12d28: jb 0x12d30
0x12d2a: mov ah, 8
0x12d2c: mov dl, 0x80
2018-12-17T22:58:17.465111065Z 98 PC: 9d2d3 | Get current PSP
2018-12-17T22:58:17.466956417Z 61 PC: 9d2d3 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:58:17.474360566Z 68 PC: 9d2d3 | I/O control for devices (Set for = 'A:\TEST.COM')
2018-12-17T22:58:17.476262777Z 63 PC: 9d2d3 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:58:17.479266177Z 62 PC: 9d2d3 | Close file
2018-12-17T22:58:17.481629465Z 37 PC: 9d2d3 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:17.483134015Z 61 PC: 9d2d3 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:58:17.489908036Z 98 PC: 9d2d3 | Get current PSP
2018-12-17T22:58:17.491380588Z 66 PC: 9d2d3 | Move file pointer
2018-12-17T22:58:17.493505171Z 66 PC: 9d2d3 | Move file pointer
2018-12-17T22:58:17.495145789Z 66 PC: 9d2d3 | Move file pointer
2018-12-17T22:58:17.498025457Z 37 PC: 9d2d3 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:17.499493374Z 98 PC: 9d2d3 | Get current PSP
2018-12-17T22:58:17.500313211Z 37 PC: 9d2d3 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:17.502255465Z 63 PC: 9d090 | Read file or device (Read 32 bytes on handle 5)
2018-12-17T22:58:17.517757647Z 98 PC: 9d2d3 | Get current PSP
2018-12-17T22:58:17.518836353Z 37 PC: 9d2d3 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:17.520707405Z 66 PC: 9d090 | Move file pointer
2018-12-17T22:58:17.522890642Z 66 PC: 9d090 | Move file pointer
2018-12-17T22:58:17.524848984Z 98 PC: 9d2d3 | Get current PSP
2018-12-17T22:58:17.527442737Z 37 PC: 9d2d3 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:17.528648567Z 63 PC: 9d090 | Read file or device (Read 333 bytes on handle 5)
2018-12-17T22:58:17.532163064Z 98 PC: 9d2d3 | Get current PSP
2018-12-17T22:58:17.533470127Z 37 PC: 9d2d3 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:58:17.535168002Z 62 PC: 9d090 | Close file
2018-12-17T22:58:17.537652729Z 37 PC: 9d2d3 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')