Sample viewer

vx.netlux.org/Virus.DOS.Ply.5143

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:05:19.852189437Z 65 PC: 12a7b | Delete file (Filename = '\NCDTREE')
2018-12-17T23:05:19.86120048Z 47 PC: 133bb | Get disk transfer address
2018-12-17T23:05:19.862908491Z 26 PC: 12d9f | Set disk transfer address
2018-12-17T23:05:19.864224132Z 53 PC: 12da5 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:05:19.866198193Z 37 PC: 12dc0 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:05:19.868410375Z 78 PC: 12e0f | Find first file
2018-12-17T23:05:19.875613502Z 37 PC: 12e3f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:05:19.876915093Z 0 PC: 12e5a | Program terminate