Sample viewer

vx.netlux.org/Virus.DOS.Khizhnjak.753

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:09.108321426Z 78 PC: 17c37 | Find first file
2018-12-17T23:11:09.129799572Z 67 PC: 17c83 | Get or set file attributes
2018-12-17T23:11:09.146245102Z 61 PC: 17c90 | Open file (Filename = ' ')
2018-12-17T23:11:09.151334736Z 63 PC: 17ca6 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:11:09.163137424Z 66 PC: 17cbb | Move file pointer
2018-12-17T23:11:09.164581041Z 66 PC: 17cf5 | Move file pointer
2018-12-17T23:11:09.16610514Z 63 PC: 17d08 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T23:11:09.16940164Z 66 PC: 17d34 | Move file pointer
2018-12-17T23:11:09.174000546Z 64 PC: 17d41 | Write file or device (Write 753 bytes on handle 5)
2018-12-17T23:11:09.182699289Z 66 PC: 17d53 | Move file pointer
2018-12-17T23:11:09.185166807Z 64 PC: 17d63 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:11:09.192071094Z 9 PC: 17d6c | Display string (String= 'EK50B /BTR D) ')
2018-12-17T23:11:09.196696487Z 62 PC: 17d7b | Close file
2018-12-17T23:11:09.219430285Z 48 PC: 18097 | Get DOS version
2018-12-17T23:11:09.221236518Z 37 PC: 182f6 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:11:09.222721406Z 37 PC: 1832a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:11:09.225426294Z 37 PC: 182c4 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')