Sample viewer

vx.netlux.org/Virus.DOS.Karlik.1666

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:01:32.952544002Z 208 PC: 1935d | UNKNOWN!
2018-12-17T23:01:32.953798518Z 53 PC: 19413 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:32.954677363Z 53 PC: 9f66d | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:01:32.955441032Z 37 PC: 9f67d | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:01:32.957200963Z 42 PC: 9f697 | Get date 0x9f697: lds dx, ptr [0x5a]
0x9f69b: mov ax, 0x2501
0x9f69e: call 0x9f6ff
0x9f6a1: push cs
0x9f6a2: pop ds
0x9f6a3: cmp byte ptr cs:[0x5e], 1
0x9f6a9: jne 0x9f6c4
0x9f6ab: mov ax, word ptr cs:[0x69]
0x9f6af: mov bx, word ptr cs:[0x6b]
0x9f6b4: mov word ptr cs:[0x6d], ax
0x9f6b8: mov word ptr cs:[0x6f], bx
0x9f6bd: pushf
0x9f6be: pop ax
0x9f6bf: and ax, 0xfeff
0x9f6c2: push ax
0x9f6c3: popf
0x9f6c4: retf
0x9f6c5: ljmp ptr cs:[0x69]
0x9f6ca: push bp
0x9f6cb: mov bp, sp
2018-12-17T23:01:32.959789158Z 37 PC: 9f706 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:01:32.961301854Z 53 PC: 1942c | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:01:32.963470803Z 37 PC: 19440 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:32.964868764Z 37 PC: 1944c | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:01:32.966686728Z 74 PC: 12ce0 | Reallocate memory
2018-12-17T23:01:32.970088012Z 53 PC: 12cf5 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T23:01:32.971642763Z 37 PC: 12d0a | Set interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T23:01:32.973268831Z 68 PC: 13c38 | I/O control for devices (Set for = 'main')
2018-12-17T23:01:32.976587606Z 48 PC: 16407 | Get DOS version
2018-12-17T23:01:32.97910092Z 64 PC: 13540 | Write file or device (Write 4 bytes on handle 1)
2018-12-17T23:01:32.982309491Z 64 PC: 13540 | Write file or device (Write 33 bytes on handle 1)
2018-12-17T23:01:32.98675379Z 64 PC: 13540 | Write file or device (Write 4 bytes on handle 1)
2018-12-17T23:01:32.991073932Z 64 PC: 13540 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:01:32.995553538Z 64 PC: 13540 | Write file or device (Write 65 bytes on handle 1)
2018-12-17T23:01:33.002787727Z 64 PC: 13540 | Write file or device (Write 4 bytes on handle 1)
2018-12-17T23:01:33.009216336Z 64 PC: 13540 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T23:01:33.014570771Z 64 PC: 13540 | Write file or device (Write 4 bytes on handle 1)
2018-12-17T23:01:33.01939889Z 64 PC: 13540 | Write file or device (Write 34 bytes on handle 1)
2018-12-17T23:01:33.024251416Z 37 PC: 12d7b | Set interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T23:01:33.02548978Z 76 PC: 12d8c | Terminate with return code (Return code = '1')