Sample viewer

vx.netlux.org/Virus.DOS.Kaliostro.2098

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:09:10.619781434Z 153 PC: 15764 | UNKNOWN!
2018-12-17T23:09:10.62099383Z 74 PC: 15783 | Reallocate memory
2018-12-17T23:09:10.622277232Z 53 PC: 157bc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:10.623680226Z 98 PC: 156dd | Get current PSP
2018-12-17T23:09:10.625628656Z 88 PC: 157e5 | case 0xGet or set allocation strateg:
2018-12-17T23:09:10.626847558Z 88 PC: 157eb | case 0xGet or set allocation strateg:
2018-12-17T23:09:10.62803483Z 88 PC: 157f4 | case 0xGet or set allocation strateg:
2018-12-17T23:09:10.630264121Z 88 PC: 15801 | case 0xGet or set allocation strateg:
2018-12-17T23:09:10.631361278Z 72 PC: 15809 | Allocate memory
2018-12-17T23:09:10.632597496Z 88 PC: 15820 | case 0xGet or set allocation strateg:
2018-12-17T23:09:10.634318275Z 88 PC: 15828 | case 0xGet or set allocation strateg:
2018-12-17T23:09:10.635235255Z 37 PC: 15842 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:10.636064032Z 9 PC: 12a86 | Display string (Could not find end pointer)
2018-12-17T23:09:10.639504459Z 48 PC: 12a8f | Get DOS version
2018-12-17T23:09:10.641773473Z 44 PC: 9f320 | Get time 0x9f320: xor ch, ch
0x9f322: add cl, 5
0x9f325: mov word ptr [0x68b], cx
0x9f329: mov word ptr [0x6ec], 0
0x9f32f: mov ax, 0x4301
0x9f332: mov cx, 0x20
0x9f335: mov dx, 0x5f8
0x9f338: pushf
0x9f339: lcall ptr [0x6f3]
0x9f33d: mov ax, 0x3d02
0x9f340: pushf
0x9f341: lcall ptr [0x6f3]
0x9f345: jae 0x9f34a
0x9f347: jmp 0x9f4c0
0x9f34a: mov word ptr [0x6f1], ax
0x9f34d: mov ah, 0x3f
0x9f34f: mov bx, word ptr [0x6f1]
0x9f353: mov cx, 0x1c
0x9f356: mov dx, 3
0x9f359: pushf
2018-12-17T23:09:10.643761659Z 67 PC: 9f33d | Get or set file attributes
2018-12-17T23:09:10.660298566Z 61 PC: 9f345 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T23:09:10.668140875Z 63 PC: 9f35e | Read file or device (Read 28 bytes on handle 5)
2018-12-17T23:09:10.670627054Z 62 PC: 9f4c0 | Close file
2018-12-17T23:09:10.680196863Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-17T23:09:10.697604824Z 93 PC: 12afe | File sharing functions
2018-12-17T23:09:10.699375797Z 9 PC: 12a86 | Display string (String= 'Size change=0856h/02134d. ')
2018-12-17T23:09:10.703608029Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')