Sample viewer

vx.netlux.org/Virus.DOS.Australian.AIH.972

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:28.930563232Z 84 PC: 1cef4 | Get verify flag
2018-12-17T23:04:28.955408667Z 48 PC: 18800 | Get DOS version
2018-12-17T23:04:28.957251389Z 74 PC: 18879 | Reallocate memory
2018-12-17T23:04:28.960702908Z 53 PC: 188f7 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:04:28.962750996Z 37 PC: 18909 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:04:28.965514395Z 68 PC: 18999 | I/O control for devices
2018-12-17T23:04:28.96753339Z 68 PC: 18999 | I/O control for devices (Set for = '^�')
2018-12-17T23:04:28.969606515Z 68 PC: 18999 | I/O control for devices (Set for = 'F�@�F��v��')
2018-12-17T23:04:28.972509047Z 68 PC: 18999 | I/O control for devices (Set for = '��� RQ�N���RQ�N��RQ�r��v��')
2018-12-17T23:04:28.974124539Z 68 PC: 18999 | I/O control for devices (Set for = '��� RQ�N���RQ�N��RQ�r��v��')
2018-12-17T23:04:28.979423619Z 56 PC: 18e06 | Get or set country info
2018-12-17T23:04:28.983637387Z 68 PC: 16d11 | I/O control for devices (Set for = '���=�ZҼ߱�(ڭ27��ʺ9U*C�Z �����T���:�z�{$���@� W`y��㨆 p��w�q��. �[Ɍ44R��R�~��')
2018-12-17T23:04:28.985417218Z 68 PC: 16d26 | I/O control for devices (Set for = '*eg?\I8�`�{9U��jl��˝sWkb��bh��+"`g�>�:�e��=��R2h��h�!�܅���N��S"޿DY��ug�y���y��r����0eqUŢm8u1��P���N�~l'��d�N��s�a�+�j����')
2018-12-17T23:04:28.987024932Z 84 PC: 174f7 | Get verify flag
2018-12-17T23:04:28.988832647Z 51 PC: 174ff | Get or set Ctrl-Break
2018-12-17T23:04:28.990123176Z 51 PC: 1750a | Get or set Ctrl-Break
2018-12-17T23:04:28.991445058Z 37 PC: 17514 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:04:28.994482826Z 53 PC: 17046 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:29.000277177Z 37 PC: 17056 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:29.002974045Z 55 PC: 16d4c | Get or set switch character
2018-12-17T23:04:29.006078752Z 43 PC: 174db | Set date
2018-12-17T23:04:29.009667346Z 61 PC: 18f65 | Open file (Filename = '�:*O�k')
2018-12-17T23:04:29.01850518Z 61 PC: 18f65 | Open file (Filename = 'A:/PKZIP.CFG')
2018-12-17T23:04:29.026649565Z 68 PC: 169f5 | I/O control for devices (Set for = '!')
2018-12-17T23:04:29.041666722Z 61 PC: 17292 | Open file (Filename = '�LNf��ƚ�juF�D�� �iU�U���t��e���N�P��/���g/!��"w��9>��N�gfW�c�LEg�qOv�����ӷ �ص����A��1M���Y��A3�t���Q]*�?��ˇ9��CB�'��,�a�7�5�CÄ#�9t�4�� ֌_c��p�c���2����Q�ia/��
2018-12-17T23:04:29.049750114Z 227 PC: 16df6 | UNKNOWN!
2018-12-17T23:04:29.051641264Z 96 PC: 16dac | Qualify filename
2018-12-17T23:04:29.058641013Z 64 PC: 17184 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:04:29.065085755Z 64 PC: 17184 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:04:29.105174422Z 12 PC: 18e06 | Flush input buffer and input