Sample viewer

vx.netlux.org/Virus.DOS.Sina.1823

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:09:13.98338995Z 255 PC: 12a53 | UNKNOWN!
2018-12-17T23:09:13.993000804Z 53 PC: 12aaa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:13.994057689Z 37 PC: 12abc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:13.995456492Z 74 PC: 12acd | Reallocate memory
2018-12-17T23:09:13.997851042Z 75 PC: 12b57 | Execute program
2018-12-17T23:09:14.013576658Z 53 PC: 12b57 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:14.014640291Z 37 PC: 12b57 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:14.016172533Z 67 PC: 12b57 | Get or set file attributes
2018-12-17T23:09:14.02553422Z 67 PC: 12b57 | Get or set file attributes
2018-12-17T23:09:14.71008201Z 61 PC: 12b57 | Open file (Filename = 'C:\DOS\KEYB.COM')
2018-12-17T23:09:14.717037636Z 87 PC: 12b57 | Get or set file date and time
2018-12-17T23:09:14.718611929Z 63 PC: 12b57 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:09:14.724101715Z 63 PC: 12b57 | Read file or device (Read 30 bytes on handle 5)
2018-12-17T23:09:14.726683394Z 66 PC: 12b57 | Move file pointer
2018-12-17T23:09:14.728814092Z 63 PC: 12b57 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:09:14.734718681Z 72 PC: 12b57 | Allocate memory
2018-12-17T23:09:14.736315076Z 64 PC: 12b57 | Write file or device (Write 1820 bytes on handle 5)
2018-12-17T23:09:14.746787144Z 73 PC: 12b57 | Release memory
2018-12-17T23:09:14.748071231Z 64 PC: 12b57 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:09:14.750839317Z 66 PC: 12b57 | Move file pointer
2018-12-17T23:09:14.754425182Z 64 PC: 12b57 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:09:14.757674101Z 87 PC: 12b57 | Get or set file date and time
2018-12-17T23:09:14.759190815Z 62 PC: 12b57 | Close file
2018-12-17T23:09:14.766499045Z 67 PC: 12b57 | Get or set file attributes
2018-12-17T23:09:14.776971048Z 37 PC: 12b57 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:09:14.778109754Z 75 PC: 12b02 | Execute program
2018-12-17T23:09:14.786271259Z 42 PC: 12b57 | Get date 0x12b57: ret
0x12b58: nop
0x12b59: iret
0x12b5a: push bp
0x12b5b: add word ptr [bx + 0x11], dx
0x12b5e: push ax
0x12b5f: push bx
0x12b60: push ds
0x12b61: push dx
0x12b62: push es
0x12b63: mov ax, 0x3524
0x12b66: call 0x22b51
0x12b69: mov word ptr cs:[0x21a], bx
0x12b6e: mov word ptr cs:[0x21c], es
0x12b73: push cs
0x12b74: pop ds
0x12b75: mov dx, 0x218
0x12b78: mov ax, 0x2524
0x12b7b: call 0x22b51
0x12b7e: pop es
2018-12-17T23:09:14.789062753Z 77 PC: 12b27 | Get program return code
2018-12-17T23:09:14.790496792Z 49 PC: 12b36 | Terminate and stay resident (Return code = '0' | Memory size = '130')