Sample viewer

vx.netlux.org/Virus.DOS.Albania.575.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:03:16.376427712Z 53 PC: 12e71 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:16.378230198Z 37 PC: 1304e | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:16.380643751Z 26 PC: 12e87 | Set disk transfer address
2018-12-17T23:03:16.382442123Z 25 PC: 12e8b | Get default drive
2018-12-17T23:03:16.383960218Z 71 PC: 12ea1 | Get current directory
2018-12-17T23:03:16.388852307Z 59 PC: 12f6b | Change current directory
2018-12-17T23:03:16.395133519Z 78 PC: 12f74 | Find first file
2018-12-17T23:03:16.401312272Z 67 PC: 12fa9 | Get or set file attributes
2018-12-17T23:03:16.754721114Z 61 PC: 12fae | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T23:03:16.762681031Z 66 PC: 12fbd | Move file pointer
2018-12-17T23:03:16.765107315Z 63 PC: 12fc8 | Read file or device (Read 7 bytes on handle 5)
2018-12-17T23:03:16.769736575Z 66 PC: 13042 | Move file pointer
2018-12-17T23:03:16.771434984Z 63 PC: 12fe5 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:03:16.774484855Z 66 PC: 13042 | Move file pointer
2018-12-17T23:03:16.775953239Z 64 PC: 13000 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:03:16.781363263Z 66 PC: 13009 | Move file pointer
2018-12-17T23:03:16.783534276Z 64 PC: 13015 | Write file or device (Write 575 bytes on handle 5)
2018-12-17T23:03:16.792956955Z 62 PC: 13020 | Close file
2018-12-17T23:03:16.80276684Z 67 PC: 1302b | Get or set file attributes
2018-12-17T23:03:16.815067362Z 26 PC: 12eea | Set disk transfer address
2018-12-17T23:03:16.816696526Z 59 PC: 12ef2 | Change current directory
2018-12-17T23:03:16.823016756Z 14 PC: 13d54 | Set default drive (Drive = '')
2018-12-17T23:03:16.824837668Z 46 PC: 13d69 | Set verify flag