Sample viewer

vx.netlux.org/Virus.DOS.Albania.606

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:05.35748006Z 48 PC: 12aec | Get DOS version
2018-12-17T23:06:05.359595461Z 53 PC: 12af9 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:05.361235911Z 63 PC: 12c64 | Read file or device (Read 0 bytes on handle 341)
2018-12-17T23:06:05.363019866Z 66 PC: 12cde | Move file pointer
2018-12-17T23:06:05.365313324Z 63 PC: 12c81 | Read file or device (Read 3 bytes on handle 341)
2018-12-17T23:06:05.366822694Z 66 PC: 12cde | Move file pointer
2018-12-17T23:06:05.368302138Z 64 PC: 12c9c | Write file or device (Write 3 bytes on handle 341)
2018-12-17T23:06:05.374138676Z 66 PC: 12ca5 | Move file pointer
2018-12-17T23:06:05.386353572Z 64 PC: 12cb1 | Write file or device (Write 606 bytes on handle 341)
2018-12-17T23:06:05.387958738Z 62 PC: 12cbc | Close file
2018-12-17T23:06:05.389528222Z 67 PC: 12cc7 | Get or set file attributes