Sample viewer

vx.netlux.org/Virus.DOS.Forger.1000

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:51:48.226398413Z 53 PC: 12d51 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:51:48.228307227Z 37 PC: 12d61 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:51:48.229977929Z 53 PC: 12d67 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T21:51:48.231531254Z 37 PC: 12d78 | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T21:51:48.233762167Z 74 PC: 12dd9 | Reallocate memory
2018-12-17T21:51:48.23531891Z 73 PC: 12de0 | Release memory
2018-12-17T21:51:48.236727174Z 47 PC: 12aab | Get disk transfer address
2018-12-17T21:51:48.247574273Z 26 PC: 12abe | Set disk transfer address
2018-12-17T21:51:48.249084272Z 78 PC: 12b0e | Find first file
2018-12-17T21:51:48.255217074Z 67 PC: 12b58 | Get or set file attributes
2018-12-17T21:51:48.269593959Z 67 PC: 12b65 | Get or set file attributes
2018-12-17T21:51:48.287952993Z 61 PC: 12b6c | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T21:51:48.29553994Z 87 PC: 12b75 | Get or set file date and time
2018-12-17T21:51:48.297473759Z 63 PC: 12b92 | Read file or device (Read 32 bytes on handle 5)
2018-12-17T21:51:48.301069928Z 66 PC: 12bb2 | Move file pointer
2018-12-17T21:51:48.302956522Z 64 PC: 12bc6 | Write file or device (Write 1000 bytes on handle 5)
2018-12-17T21:51:48.312005077Z 66 PC: 12c06 | Move file pointer
2018-12-17T21:51:48.314965221Z 64 PC: 12c4e | Write file or device (Write 32 bytes on handle 5)
2018-12-17T21:51:48.318177599Z 87 PC: 12c5d | Get or set file date and time
2018-12-17T21:51:48.320093394Z 62 PC: 12c61 | Close file
2018-12-17T21:51:48.32877475Z 67 PC: 12c6a | Get or set file attributes
2018-12-17T21:51:48.332817006Z 26 PC: 12c7e | Set disk transfer address
2018-12-17T21:51:48.333920849Z 75 PC: 12dee | Execute program
2018-12-17T21:51:48.349402715Z 9 PC: 13962 | Display string (Could not find end pointer)
2018-12-17T21:51:48.353525292Z 76 PC: 13968 | Terminate with return code (Return code = '0')
2018-12-17T21:51:48.356434993Z 49 PC: 12df6 | Terminate and stay resident (Return code = '0' | Memory size = '211')