Sample viewer

vx.netlux.org/Virus.DOS.No25.1894

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:59:13.152677225Z 48 PC: 17556 | Get DOS version
2018-12-17T22:59:13.155967799Z 99 PC: 13726 | Get DBCS lead byte table pointer
2018-12-17T22:59:13.157983598Z 68 PC: 13740 | I/O control for devices (Set for = '')
2018-12-17T22:59:13.159754406Z 68 PC: 1374b | I/O control for devices (Set for = '')
2018-12-17T22:59:13.162785342Z 68 PC: 13756 | I/O control for devices (Set for = '')
2018-12-17T22:59:13.164976761Z 68 PC: 1375e | I/O control for devices (Set for = '��b���g�t�S3����[r�2��W�<t�<u�6�u����>��>W')
2018-12-17T22:59:13.167286642Z 48 PC: 13763 | Get DOS version
2018-12-17T22:59:13.169923528Z 37 PC: 1666f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:59:13.171953323Z 53 PC: 16678 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:13.173918967Z 37 PC: 1668f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:13.176295493Z 25 PC: 165ed | Get default drive
2018-12-17T22:59:13.17846475Z 71 PC: 165f7 | Get current directory
2018-12-17T22:59:13.183545149Z 64 PC: 139e5 | Write file or device (Write 30 bytes on handle 2)
2018-12-17T22:59:13.191171842Z 64 PC: 139e5 | Write file or device (Write 9 bytes on handle 1)
2018-12-17T22:59:13.195290092Z 64 PC: 139e5 | Write file or device (Write 17 bytes on handle 1)
2018-12-17T22:59:13.199038057Z 76 PC: 147f8 | Terminate with return code (Return code = '4')
2018-12-17T22:59:13.201765373Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:59:13.20492991Z 72 PC: 12174 | Allocate memory
2018-12-17T22:59:13.20748938Z 72 PC: 1218d | Allocate memory
2018-12-17T22:59:13.209258415Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:59:13.21128833Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:59:13.212950524Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:13.214860443Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:13.217600463Z 62 PC: 122ab | Close file
2018-12-17T22:59:13.219286812Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:13.221457832Z 62 PC: 122ab | Close file
2018-12-17T22:59:13.223523004Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:13.225218871Z 62 PC: 122ab | Close file
2018-12-17T22:59:13.226905732Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:13.22890002Z 62 PC: 122ab | Close file
2018-12-17T22:59:13.230938521Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:13.232733304Z 62 PC: 122ab | Close file
2018-12-17T22:59:13.234871001Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:13.236850181Z 62 PC: 122ab | Close file
2018-12-17T22:59:13.238655344Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:13.240226948Z 62 PC: 122ab | Close file
2018-12-17T22:59:13.248299619Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:13.250364891Z 62 PC: 122ab | Close file
2018-12-17T22:59:13.25256701Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:13.255457963Z 62 PC: 122ab | Close file
2018-12-17T22:59:13.257708062Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:13.259863513Z 62 PC: 122ab | Close file
2018-12-17T22:59:13.262899549Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:13.264774272Z 62 PC: 122ab | Close file
2018-12-17T22:59:13.266697277Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:13.269218796Z 62 PC: 122ab | Close file
2018-12-17T22:59:13.271337458Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:13.273148501Z 62 PC: 122ab | Close file
2018-12-17T22:59:13.276268455Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:13.278493136Z 62 PC: 122ab | Close file
2018-12-17T22:59:13.281680797Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:13.284112597Z 62 PC: 122ab | Close file
2018-12-17T22:59:13.287898232Z 99 PC: 99897 | Get DBCS lead byte table pointer
2018-12-17T22:59:13.28961553Z 56 PC: 940b9 | Get or set country info
2018-12-17T22:59:13.292495763Z 64 PC: 99b08 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:59:13.300936326Z 25 PC: 94122 | Get default drive
2018-12-17T22:59:13.302916678Z 71 PC: 9639d | Get current directory
2018-12-17T22:59:13.307752898Z 64 PC: 99b08 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:59:13.312510449Z 2 PC: 96372 | Character output (Char = '3e')
2018-12-17T22:59:13.315660369Z 93 PC: 941e0 | File sharing functions
2018-12-17T22:59:13.318148405Z 93 PC: 941e7 | File sharing functions
2018-12-17T22:59:13.321679902Z 10 PC: 941f9 | Buffered keyboard input
2018-12-17T22:59:28.138085247Z 0 PC: 0 | Program terminate
2018-12-17T22:59:29.492695756Z 0 PC: 0 | Program terminate
2018-12-17T22:59:29.596103276Z 64 PC: 99b08 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:59:29.603151633Z 41 PC: 9426e | Parse filename
2018-12-17T22:59:29.608597637Z 41 PC: 942ef | Parse filename
2018-12-17T22:59:29.610829962Z 41 PC: 9430c | Parse filename
2018-12-17T22:59:29.613713412Z 26 PC: 977b7 | Set disk transfer address
2018-12-17T22:59:29.616933353Z 71 PC: 979b3 | Get current directory
2018-12-17T22:59:29.626050157Z 78 PC: 9efe8 | Find first file
2018-12-17T22:59:29.637378608Z 47 PC: 9efe8 | Get disk transfer address
2018-12-17T22:59:29.642316237Z 71 PC: 9782c | Get current directory
2018-12-17T22:59:29.646682994Z 73 PC: 96ec9 | Release memory
2018-12-17T22:59:29.648557376Z 61 PC: 9efe8 | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T22:59:29.826184512Z 62 PC: 9efe8 | Close file
2018-12-17T22:59:29.829160485Z 75 PC: 11821 | Execute program
2018-12-17T22:59:29.844572239Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T22:59:29.849283273Z 76 PC: 12a4b | Terminate with return code (Return code = '36')
2018-12-17T22:59:29.85388945Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:59:29.856006609Z 72 PC: 12174 | Allocate memory
2018-12-17T22:59:29.858895378Z 72 PC: 1218d | Allocate memory
2018-12-17T22:59:29.862183067Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:59:29.864401546Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:59:29.866275999Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:29.868943081Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:29.871611366Z 62 PC: 122ab | Close file
2018-12-17T22:59:29.874639787Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:29.878000873Z 62 PC: 122ab | Close file
2018-12-17T22:59:29.880576023Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:29.883131165Z 62 PC: 122ab | Close file
2018-12-17T22:59:29.885840517Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:29.889017258Z 62 PC: 122ab | Close file
2018-12-17T22:59:29.892027525Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:29.894502917Z 62 PC: 122ab | Close file
2018-12-17T22:59:29.898179667Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:29.901678983Z 62 PC: 122ab | Close file
2018-12-17T22:59:29.903818384Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:29.906414013Z 62 PC: 122ab | Close file
2018-12-17T22:59:29.908330955Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:29.910315986Z 62 PC: 122ab | Close file
2018-12-17T22:59:29.913269737Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:29.91553809Z 62 PC: 122ab | Close file
2018-12-17T22:59:29.918388256Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:29.924314063Z 62 PC: 122ab | Close file
2018-12-17T22:59:29.927442513Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:29.934687458Z 62 PC: 122ab | Close file
2018-12-17T22:59:29.938278577Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:29.941092266Z 62 PC: 122ab | Close file
2018-12-17T22:59:29.94313274Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:29.945419247Z 62 PC: 122ab | Close file
2018-12-17T22:59:29.949600536Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:29.9517684Z 62 PC: 122ab | Close file
2018-12-17T22:59:29.953936474Z 69 PC: 9efe8 | Duplicate handle
2018-12-17T22:59:29.957375097Z 62 PC: 122ab | Close file
2018-12-17T22:59:29.96110674Z 99 PC: 99897 | Get DBCS lead byte table pointer
2018-12-17T22:59:29.96335747Z 56 PC: 940b9 | Get or set country info
2018-12-17T22:59:29.967983534Z 64 PC: 99b08 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:59:29.973530289Z 25 PC: 94122 | Get default drive
2018-12-17T22:59:29.976156745Z 71 PC: 9639d | Get current directory
2018-12-17T22:59:29.982570989Z 64 PC: 99b08 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:59:29.992764156Z 2 PC: 96372 | Character output (Char = '3e')
2018-12-17T22:59:29.996162873Z 93 PC: 941e0 | File sharing functions
2018-12-17T22:59:29.999733694Z 93 PC: 941e7 | File sharing functions
2018-12-17T22:59:30.003071727Z 10 PC: 941f9 | Buffered keyboard input