Sample viewer

vx.netlux.org/Virus.DOS.CeCe.2049.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:00:37.872701121Z 204 PC: 1466e | UNKNOWN!
2018-12-17T23:00:37.875372797Z 74 PC: 1468f | Reallocate memory
2018-12-17T23:00:37.877335837Z 74 PC: 1469c | Reallocate memory
2018-12-17T23:00:37.878840546Z 72 PC: 146a3 | Allocate memory
2018-12-17T23:00:37.880607755Z 53 PC: 9f554 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:37.882656897Z 53 PC: 9f561 | Get interrupt vector (Interrupt = '42' AKA 'Get date')
2018-12-17T23:00:37.883986519Z 37 PC: 9f571 | Set interrupt vector (Interrupt = '42' AKA 'Get date')
2018-12-17T23:00:37.885283566Z 48 PC: 9f575 | Get DOS version
2018-12-17T23:00:37.887659077Z 37 PC: 9f584 | Set interrupt vector (Interrupt = '42' AKA 'Get date')
2018-12-17T23:00:37.889289149Z 37 PC: 9f58e | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:00:37.890727372Z 48 PC: 9f5a0 | Get DOS version
2018-12-17T23:00:37.892833557Z 37 PC: 9f5aa | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:37.894401266Z 53 PC: 13452 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:37.895867755Z 53 PC: 13452 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:00:37.897684789Z 53 PC: 13452 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:37.899278298Z 53 PC: 13452 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:37.900746694Z 53 PC: 13452 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:37.902976974Z 53 PC: 13452 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:37.904332953Z 53 PC: 13452 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:37.905757814Z 53 PC: 13452 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:37.907369275Z 53 PC: 13452 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:37.909031045Z 53 PC: 13452 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:37.910494892Z 53 PC: 13452 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:37.911960108Z 53 PC: 13452 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:37.91367333Z 53 PC: 13452 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:37.91514603Z 53 PC: 13452 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:37.916544047Z 53 PC: 13452 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:37.918833212Z 53 PC: 13452 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:37.920964997Z 53 PC: 13452 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:00:37.923454288Z 53 PC: 13452 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:37.928809064Z 53 PC: 13452 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:00:37.930133659Z 37 PC: 13467 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:37.931398364Z 37 PC: 1346f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:37.933716321Z 37 PC: 13477 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:37.935288592Z 37 PC: 1347f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:37.937442895Z 68 PC: 137ef | I/O control for devices (Set for = '')
2018-12-17T23:00:37.996056701Z 37 PC: 12e75 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:38.001239592Z 58 PC: 142fa | Remove subdirectory
2018-12-17T23:00:38.012273743Z 25 PC: 14233 | Get default drive
2018-12-17T23:00:38.014859495Z 71 PC: 14246 | Get current directory
2018-12-17T23:00:38.018787911Z 59 PC: 142fa | Change current directory
2018-12-17T23:00:38.026163721Z 14 PC: 1428c | Set default drive (Drive = 'A')
2018-12-17T23:00:38.027969084Z 25 PC: 14290 | Get default drive
2018-12-17T23:00:38.030335831Z 59 PC: 142fa | Change current directory
2018-12-17T23:00:38.209125298Z 54 PC: 12d6a | Get free disk space
2018-12-17T23:00:38.216987647Z 67 PC: 12dca | Get or set file attributes
2018-12-17T23:00:38.221631659Z 60 PC: 1407a | Create or truncate file
2018-12-17T23:00:38.899463375Z 62 PC: 140ca | Close file
2018-12-17T23:00:38.902017693Z 65 PC: 141c3 | Delete file (Filename = 'C:\mempatch.exe')
2018-12-17T23:00:38.91475283Z 37 PC: 13566 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:00:38.916370223Z 37 PC: 13566 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T23:00:38.918127748Z 37 PC: 13566 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:00:38.920489484Z 37 PC: 13566 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:38.922448642Z 37 PC: 13566 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:38.924220091Z 37 PC: 13566 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:38.926212196Z 37 PC: 13566 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T23:00:38.928549269Z 37 PC: 13566 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T23:00:38.930429358Z 37 PC: 13566 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T23:00:38.932170232Z 37 PC: 13566 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T23:00:38.934578477Z 37 PC: 13566 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T23:00:38.936436605Z 37 PC: 13566 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T23:00:38.938158863Z 37 PC: 13566 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T23:00:38.94152872Z 37 PC: 13566 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T23:00:38.943423602Z 37 PC: 13566 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T23:00:38.945065225Z 37 PC: 13566 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T23:00:38.947380644Z 37 PC: 13566 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T23:00:38.949178733Z 37 PC: 13566 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T23:00:38.950937674Z 37 PC: 13566 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T23:00:38.953497373Z 76 PC: 135a5 | Terminate with return code (Return code = '0')