Sample viewer

vx.netlux.org/Virus.DOS.Kazakhstan.2352

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:17.811842376Z 48 PC: 14374 | Get DOS version
2018-12-17T23:06:17.816767346Z 53 PC: 13ff8 | Get interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T23:06:17.818170715Z 37 PC: 14002 | Set interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T23:06:17.819547203Z 53 PC: 13ff8 | Get interrupt vector (Interrupt = '40' AKA 'Random block write')
2018-12-17T23:06:17.821477331Z 37 PC: 14002 | Set interrupt vector (Interrupt = '40' AKA 'Random block write')
2018-12-17T23:06:17.824084533Z 53 PC: 13ff8 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:06:17.82592857Z 37 PC: 14002 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:06:17.828603269Z 52 PC: 14403 | Get InDOS flag pointer
2018-12-17T23:06:17.836892995Z 53 PC: 13ff8 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:17.838995888Z 37 PC: 14002 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:17.842303176Z 73 PC: 1441e | Release memory
2018-12-17T23:06:17.844509394Z 49 PC: 14423 | Terminate and stay resident (Return code = '0' | Memory size = '163')