Sample viewer

vx.netlux.org/Virus.DOS.Peterburg.529.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:12:26.448381754Z 202 PC: 12a54 | UNKNOWN!
2018-12-17T23:12:26.449992987Z 53 PC: 12aad | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:12:26.466402893Z 37 PC: 12abf | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:12:26.467801506Z 74 PC: 12ac7 | Reallocate memory
2018-12-17T23:12:26.46963044Z 53 PC: 12b5f | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:26.471666592Z 37 PC: 12b6f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:26.473002026Z 67 PC: 12b7b | Get or set file attributes
2018-12-17T23:12:26.479669471Z 67 PC: 12b89 | Get or set file attributes
2018-12-17T23:12:26.497870212Z 61 PC: 12b90 | Open file (Filename = '')
2018-12-17T23:12:26.505303925Z 87 PC: 12b9a | Get or set file date and time
2018-12-17T23:12:26.506937307Z 63 PC: 12bb0 | Read file or device (Read 529 bytes on handle 5)
2018-12-17T23:12:26.516788988Z 87 PC: 12c13 | Get or set file date and time
2018-12-17T23:12:26.518597972Z 62 PC: 12c17 | Close file
2018-12-17T23:12:26.526542563Z 67 PC: 12c26 | Get or set file attributes
2018-12-17T23:12:26.538578428Z 37 PC: 12c30 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:12:26.540273032Z 75 PC: 12aea | Execute program
2018-12-17T23:12:26.556540189Z 48 PC: 13d3b | Get DOS version
2018-12-17T23:12:26.558598626Z 9 PC: 13d47 | Display string (String= ' Incorrect DOS version ')
2018-12-17T23:12:26.566602928Z 77 PC: 12af7 | Get program return code
2018-12-17T23:12:26.568153928Z 49 PC: 12b00 | Terminate and stay resident (Return code = '0' | Memory size = '100')