Sample viewer

vx.netlux.org/Virus.DOS.OhOh.799

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:08:05.997075492Z 37 PC: 17757 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T23:08:05.999470614Z 254 PC: 1776a | UNKNOWN!
2018-12-17T23:08:06.001368562Z 53 PC: 1777a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:08:06.0037776Z 82 PC: 1778b | Get DOS internal pointers (SYSVARS)
2018-12-17T23:08:06.006878028Z 37 PC: 177d0 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:08:06.009120883Z 99 PC: 13726 | Get DBCS lead byte table pointer
2018-12-17T23:08:06.010871634Z 68 PC: 13740 | I/O control for devices (Set for = '')
2018-12-17T23:08:06.013721451Z 68 PC: 1374b | I/O control for devices (Set for = '')
2018-12-17T23:08:06.016131131Z 68 PC: 13756 | I/O control for devices (Set for = '')
2018-12-17T23:08:06.018113557Z 68 PC: 1375e | I/O control for devices (Set for = '��b���g�t�S3����[r�2��W�<t�<u�6�u����>��>W')
2018-12-17T23:08:06.020554294Z 48 PC: 13763 | Get DOS version
2018-12-17T23:08:06.022608876Z 37 PC: 1666f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:06.023976196Z 53 PC: 16678 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:06.029437232Z 37 PC: 1668f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:06.035311823Z 25 PC: 165ed | Get default drive
2018-12-17T23:08:06.036699622Z 71 PC: 165f7 | Get current directory
2018-12-17T23:08:06.041256989Z 64 PC: 139e5 | Write file or device (Write 30 bytes on handle 2)
2018-12-17T23:08:06.055785818Z 64 PC: 139e5 | Write file or device (Write 9 bytes on handle 1)
2018-12-17T23:08:06.058869304Z 64 PC: 139e5 | Write file or device (Write 17 bytes on handle 1)
2018-12-17T23:08:06.064200424Z 76 PC: 147f8 | Terminate with return code (Return code = '4')