Sample viewer

vx.netlux.org/Virus.DOS.Naive.1647

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:43.571479216Z 241 PC: 2025b | UNKNOWN!
2018-12-17T23:04:43.572515411Z 53 PC: 9f5b6 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:43.57376767Z 37 PC: 9f5c6 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:43.575979029Z 53 PC: 9f5cb | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:04:43.577239287Z 37 PC: 9f5db | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:04:43.5783541Z 48 PC: 12a8b | Get DOS version
2018-12-17T23:04:43.587863993Z 74 PC: 1da96 | Reallocate memory
2018-12-17T23:04:43.591713564Z 26 PC: 1d60c | Set disk transfer address
2018-12-17T23:04:43.592446802Z 78 PC: 1d616 | Find first file
2018-12-17T23:04:43.596539727Z 25 PC: 1d765 | Get default drive
2018-12-17T23:04:43.597773228Z 71 PC: 1d64e | Get current directory
2018-12-17T23:04:43.601415041Z 26 PC: 1d60c | Set disk transfer address
2018-12-17T23:04:43.602507802Z 78 PC: 1d616 | Find first file
2018-12-17T23:04:43.61437552Z 26 PC: 1d60c | Set disk transfer address
2018-12-17T23:04:43.615302009Z 78 PC: 1d616 | Find first file
2018-12-17T23:04:43.625485962Z 25 PC: 1d765 | Get default drive
2018-12-17T23:04:43.627226447Z 53 PC: 9f647 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:43.628356226Z 37 PC: 9f657 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:43.629655628Z 61 PC: 9f662 | Open file
2018-12-17T23:04:43.636927362Z 37 PC: 9f78e | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:43.637949999Z 61 PC: 1daf6 | Open file (Filename = 'A:\nc.ini')
2018-12-17T23:04:43.644216169Z 102 PC: 1cbeb | Get or set code page
2018-12-17T23:04:43.647365024Z 26 PC: 1d60c | Set disk transfer address
2018-12-17T23:04:43.648363601Z 78 PC: 1d616 | Find first file
2018-12-17T23:04:43.654348417Z 25 PC: 1d765 | Get default drive
2018-12-17T23:04:43.669785593Z 71 PC: 1d64e | Get current directory
2018-12-17T23:04:43.673590446Z 26 PC: 1d60c | Set disk transfer address
2018-12-17T23:04:43.674828097Z 78 PC: 1d616 | Find first file
2018-12-17T23:04:43.682119806Z 26 PC: 1d60c | Set disk transfer address
2018-12-17T23:04:43.683072884Z 78 PC: 1d616 | Find first file
2018-12-17T23:04:43.689550768Z 25 PC: 1d765 | Get default drive
2018-12-17T23:04:43.691311023Z 53 PC: 9f647 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:43.692447942Z 37 PC: 9f657 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:43.693686431Z 61 PC: 9f662 | Open file
2018-12-17T23:04:43.70003638Z 37 PC: 9f78e | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:04:43.701039863Z 61 PC: 1d21e | Open file (Filename = 'A:\ansi2437.set')