Sample viewer

vx.netlux.org/Virus.DOS.Dikshev.Yj.427

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:59:43.827191028Z 98 PC: 12a44 | Get current PSP
2018-12-17T22:59:43.82910106Z 60 PC: 12a83 | Create or truncate file
2018-12-17T22:59:43.969112653Z 64 PC: 12a8f | Write file or device (Write 62 bytes on handle 5)
2018-12-17T22:59:43.973605144Z 62 PC: 12a93 | Close file
2018-12-17T22:59:43.983148064Z 60 PC: 12a9c | Create or truncate file
2018-12-17T22:59:43.99751683Z 64 PC: 12aa9 | Write file or device (Write 427 bytes on handle 5)
2018-12-17T22:59:44.002198534Z 62 PC: 12aad | Close file
2018-12-17T22:59:44.011687141Z 78 PC: 12ab7 | Find first file
2018-12-17T22:59:44.019858897Z 74 PC: 12b0a | Reallocate memory
2018-12-17T22:59:44.02223835Z 75 PC: 12b30 | Execute program
2018-12-17T22:59:44.049175054Z 80 PC: 18029 | Set current PSP
2018-12-17T22:59:44.051468947Z 48 PC: 1802e | Get DOS version
2018-12-17T22:59:44.053561007Z 99 PC: 1e810 | Get DBCS lead byte table pointer
2018-12-17T22:59:44.05756684Z 101 PC: 180b4 | Get extended country info
2018-12-17T22:59:44.059271087Z 99 PC: 180ba | Get DBCS lead byte table pointer
2018-12-17T22:59:44.060996231Z 74 PC: 1811c | Reallocate memory
2018-12-17T22:59:44.062588815Z 25 PC: 18153 | Get default drive
2018-12-17T22:59:44.064203206Z 37 PC: 17c13 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:59:44.068344276Z 37 PC: 17c1a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:59:44.071624279Z 37 PC: 17c21 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:59:44.075640614Z 74 PC: 16dbc | Reallocate memory
2018-12-17T22:59:44.08214465Z 72 PC: 16dfd | Allocate memory
2018-12-17T22:59:44.084299495Z 72 PC: 16e35 | Allocate memory
2018-12-17T22:59:44.086566599Z 72 PC: 16e3d | Allocate memory