Sample viewer

vx.netlux.org/Virus.DOS.Beer.1933

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:00:25.202285466Z 48 PC: 14950 | Get DOS version
2018-12-17T23:00:25.204211195Z 37 PC: 149db | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:25.206483215Z 48 PC: 141c3 | Get DOS version
2018-12-17T23:00:25.208333702Z 48 PC: 12a63 | Get DOS version
2018-12-17T23:00:25.218180175Z 53 PC: 9ef09 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:25.220699409Z 37 PC: 9ef09 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:25.222761585Z 67 PC: 9ef09 | Get or set file attributes
2018-12-17T23:00:25.229593624Z 67 PC: 9ef09 | Get or set file attributes
2018-12-17T23:00:25.249146096Z 61 PC: 9ef09 | Open file (Filename = '4 Microsoft Corp Licensed Material - Property of Microsoft All rights reserved ')
2018-12-17T23:00:25.256913293Z 87 PC: 9ef09 | Get or set file date and time
2018-12-17T23:00:25.258939831Z 66 PC: 9ef09 | Move file pointer
2018-12-17T23:00:25.261478711Z 66 PC: 9ef09 | Move file pointer
2018-12-17T23:00:25.264184696Z 63 PC: 9ef09 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:00:25.272157809Z 66 PC: 9ef09 | Move file pointer
2018-12-17T23:00:25.274702471Z 63 PC: 9ef09 | Read file or device (Read 16 bytes on handle 5)
2018-12-17T23:00:25.282651349Z 66 PC: 9ef09 | Move file pointer
2018-12-17T23:00:25.284848999Z 64 PC: 9ef09 | Write file or device (Write 1933 bytes on handle 5)
2018-12-17T23:00:25.29640774Z 66 PC: 9ef09 | Move file pointer
2018-12-17T23:00:25.298779277Z 64 PC: 9ef09 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:00:25.302553118Z 87 PC: 9ef09 | Get or set file date and time
2018-12-17T23:00:25.305010426Z 62 PC: 9ef09 | Close file
2018-12-17T23:00:25.313934606Z 37 PC: 9ef09 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:25.316003003Z 61 PC: 12cb5 | Open file (Filename = '')
2018-12-17T23:00:25.323480715Z 9 PC: 12a87 | Display string (String= 'Self test: ')
2018-12-17T23:00:25.327466084Z 93 PC: 12b22 | File sharing functions
2018-12-17T23:00:25.333125679Z 76 PC: 12b07 | Terminate with return code (Return code = '1')