Sample viewer

vx.netlux.org/Virus.DOS.Gotcha.666

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:59:16.500040165Z 219 PC: 12b8b | UNKNOWN!
2018-12-17T22:59:16.502178398Z 48 PC: 12b95 | Get DOS version
2018-12-17T22:59:16.503499424Z 37 PC: 12bd7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:59:16.506431925Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:59:16.508125216Z 72 PC: 12174 | Allocate memory
2018-12-17T22:59:16.509900096Z 72 PC: 1218d | Allocate memory
2018-12-17T22:59:16.512329012Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:59:16.519049014Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:59:16.520255476Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:16.521505421Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:16.523639955Z 62 PC: 122ab | Close file
2018-12-17T22:59:16.525124061Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:16.529393124Z 62 PC: 122ab | Close file
2018-12-17T22:59:16.531938247Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:16.534184429Z 62 PC: 122ab | Close file
2018-12-17T22:59:16.53557523Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:16.536995391Z 62 PC: 122ab | Close file
2018-12-17T22:59:16.539120844Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:16.540957469Z 62 PC: 122ab | Close file
2018-12-17T22:59:16.542848715Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:16.545295741Z 62 PC: 122ab | Close file
2018-12-17T22:59:16.547200095Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:16.549137896Z 62 PC: 122ab | Close file
2018-12-17T22:59:16.56138298Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:16.563137448Z 62 PC: 122ab | Close file
2018-12-17T22:59:16.564747706Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:16.566957881Z 62 PC: 122ab | Close file
2018-12-17T22:59:16.568622344Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:16.570264043Z 62 PC: 122ab | Close file
2018-12-17T22:59:16.572228867Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:16.573758138Z 62 PC: 122ab | Close file
2018-12-17T22:59:16.575111832Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:16.577330265Z 62 PC: 122ab | Close file
2018-12-17T22:59:16.57951756Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:16.581615587Z 62 PC: 122ab | Close file
2018-12-17T22:59:16.584574569Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:16.586174623Z 62 PC: 122ab | Close file
2018-12-17T22:59:16.58775302Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:16.591817571Z 62 PC: 122ab | Close file
2018-12-17T22:59:16.596286806Z 99 PC: 9a227 | Get DBCS lead byte table pointer
2018-12-17T22:59:16.597923817Z 56 PC: 94a49 | Get or set country info
2018-12-17T22:59:16.600278182Z 64 PC: 9a498 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:59:16.60564814Z 25 PC: 94ab2 | Get default drive
2018-12-17T22:59:16.607275755Z 71 PC: 96d2d | Get current directory
2018-12-17T22:59:16.611419395Z 64 PC: 9a498 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:59:16.615916884Z 2 PC: 96d02 | Character output (Char = '3e')
2018-12-17T22:59:16.618081891Z 93 PC: 94b70 | File sharing functions
2018-12-17T22:59:16.619921754Z 93 PC: 94b77 | File sharing functions
2018-12-17T22:59:16.623394898Z 10 PC: 94b89 | Buffered keyboard input
2018-12-17T22:59:31.487571047Z 0 PC: 0 | Program terminate
2018-12-17T22:59:32.841856242Z 0 PC: 0 | Program terminate
2018-12-17T22:59:32.943972948Z 64 PC: 9a498 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:59:32.949679921Z 41 PC: 94bfe | Parse filename
2018-12-17T22:59:32.951703459Z 41 PC: 94c7f | Parse filename
2018-12-17T22:59:32.95308102Z 41 PC: 94c9c | Parse filename
2018-12-17T22:59:32.956364674Z 26 PC: 98147 | Set disk transfer address
2018-12-17T22:59:32.958632997Z 71 PC: 98343 | Get current directory
2018-12-17T22:59:32.971382975Z 78 PC: 9834e | Find first file
2018-12-17T22:59:32.981013974Z 71 PC: 981bc | Get current directory
2018-12-17T22:59:32.984406926Z 73 PC: 97859 | Release memory
2018-12-17T22:59:32.985807505Z 61 PC: 9fa0a | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T22:59:32.992726235Z 98 PC: 9fa31 | Get current PSP
2018-12-17T22:59:32.994212646Z 51 PC: 9fa58 | Get or set Ctrl-Break
2018-12-17T22:59:32.995165459Z 51 PC: 9fa5e | Get or set Ctrl-Break
2018-12-17T22:59:32.996306652Z 53 PC: 9fa65 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:32.997684002Z 37 PC: 9fa73 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:32.999398608Z 63 PC: 9fae7 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:59:33.006908497Z 63 PC: 9faf8 | Read file or device (Read 24 bytes on handle 5)
2018-12-17T22:59:33.009783716Z 62 PC: 9fa2a | Close file
2018-12-17T22:59:33.011551182Z 37 PC: 9fb80 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:33.012691162Z 51 PC: 9fb84 | Get or set Ctrl-Break
2018-12-17T22:59:33.014049865Z 75 PC: 11821 | Execute program
2018-12-17T22:59:33.024377148Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T22:59:33.028195915Z 76 PC: 12a4b | Terminate with return code (Return code = '36')
2018-12-17T22:59:33.031503493Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:59:33.032848562Z 72 PC: 12174 | Allocate memory
2018-12-17T22:59:33.034543152Z 72 PC: 1218d | Allocate memory
2018-12-17T22:59:33.036456441Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:59:33.037851132Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:59:33.039395637Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:33.042009841Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:33.043912936Z 62 PC: 122ab | Close file
2018-12-17T22:59:33.04579422Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:33.048673032Z 62 PC: 122ab | Close file
2018-12-17T22:59:33.050527741Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:33.052217105Z 62 PC: 122ab | Close file
2018-12-17T22:59:33.054351519Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:33.055832121Z 62 PC: 122ab | Close file
2018-12-17T22:59:33.057788756Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:33.060577847Z 62 PC: 122ab | Close file
2018-12-17T22:59:33.062480678Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:33.064354996Z 62 PC: 122ab | Close file
2018-12-17T22:59:33.066960123Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:33.06852189Z 62 PC: 122ab | Close file
2018-12-17T22:59:33.07015388Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:33.072567203Z 62 PC: 122ab | Close file
2018-12-17T22:59:33.074226161Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:33.075975381Z 62 PC: 122ab | Close file
2018-12-17T22:59:33.078209853Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:33.079928882Z 62 PC: 122ab | Close file
2018-12-17T22:59:33.081694916Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:33.083996067Z 62 PC: 122ab | Close file
2018-12-17T22:59:33.085625047Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:33.08725477Z 62 PC: 122ab | Close file
2018-12-17T22:59:33.089285854Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:33.093836541Z 62 PC: 122ab | Close file
2018-12-17T22:59:33.095332595Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:33.09775185Z 62 PC: 122ab | Close file
2018-12-17T22:59:33.099181411Z 69 PC: 9fa0a | Duplicate handle
2018-12-17T22:59:33.100595433Z 62 PC: 122ab | Close file
2018-12-17T22:59:33.104046655Z 99 PC: 9a227 | Get DBCS lead byte table pointer
2018-12-17T22:59:33.105406902Z 56 PC: 94a49 | Get or set country info
2018-12-17T22:59:33.107201427Z 64 PC: 9a498 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:59:33.111936149Z 25 PC: 94ab2 | Get default drive
2018-12-17T22:59:33.113552143Z 71 PC: 96d2d | Get current directory
2018-12-17T22:59:33.117728553Z 64 PC: 9a498 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:59:33.12166318Z 2 PC: 96d02 | Character output (Char = '3e')
2018-12-17T22:59:33.123798214Z 93 PC: 94b70 | File sharing functions
2018-12-17T22:59:33.125632466Z 93 PC: 94b77 | File sharing functions
2018-12-17T22:59:33.128035004Z 10 PC: 94b89 | Buffered keyboard input