Sample viewer

vx.netlux.org/Virus.DOS.Dikshev.Yj.414

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:16:14.828310148Z 98 PC: 12a44 | Get current PSP
2018-12-17T23:16:14.829978169Z 60 PC: 12a81 | Create or truncate file
2018-12-17T23:16:16.915690047Z 64 PC: 12a8c | Write file or device (Write 62 bytes on handle 5)
2018-12-17T23:16:16.919960207Z 62 PC: 12a90 | Close file
2018-12-17T23:16:17.049600469Z 60 PC: 12a99 | Create or truncate file
2018-12-17T23:16:17.119550333Z 64 PC: 12aa5 | Write file or device (Write 414 bytes on handle 5)
2018-12-17T23:16:17.123695807Z 62 PC: 12aa9 | Close file
2018-12-17T23:16:17.187726129Z 78 PC: 12ab3 | Find first file
2018-12-17T23:16:17.196381611Z 74 PC: 12b02 | Reallocate memory
2018-12-17T23:16:17.198748139Z 75 PC: 12b28 | Execute program
2018-12-17T23:16:17.225382931Z 80 PC: 18029 | Set current PSP
2018-12-17T23:16:17.2269973Z 48 PC: 1802e | Get DOS version
2018-12-17T23:16:17.228822454Z 99 PC: 1e810 | Get DBCS lead byte table pointer
2018-12-17T23:16:17.232043192Z 101 PC: 180b4 | Get extended country info
2018-12-17T23:16:17.234211204Z 99 PC: 180ba | Get DBCS lead byte table pointer
2018-12-17T23:16:17.235573374Z 74 PC: 1811c | Reallocate memory
2018-12-17T23:16:17.237028526Z 25 PC: 18153 | Get default drive
2018-12-17T23:16:17.238652643Z 37 PC: 17c13 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:16:17.239819417Z 37 PC: 17c1a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:16:17.240957338Z 37 PC: 17c21 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:16:17.245948504Z 74 PC: 16dbc | Reallocate memory
2018-12-17T23:16:17.248140425Z 72 PC: 16dfd | Allocate memory
2018-12-17T23:16:17.250223816Z 72 PC: 16e35 | Allocate memory
2018-12-17T23:16:17.252418579Z 72 PC: 16e3d | Allocate memory