Sample viewer

vx.netlux.org/Virus.DOS.Elf.3675

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:12:48.743664215Z 53 PC: 17553 | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T23:12:48.745709422Z 44 PC: 175f1 | Get time 0x175f1: shr di, 1
0x175f3: call 0x17603
0x175f6: sub di, sp
0x175f8: test word ptr ss:[0x50dc], dx
0x175fd: add bl, byte ptr ss:[0x24e]
0x17602: mov bp, 0x14c3
0x17605: add cx, dx
0x17607: sahf
0x17608: call 0x1760e
0x1760b: add bp, bp
0x1760d: mov ax, 0xa5c3
0x17610: xor si, bp
0x17612: mov di, 0x793a
0x17615: add word ptr cs:[di - 0x2be1], 0x48d
0x1761c: call 0x17623
0x1761f: rol ax, 1
0x17621: inc di
0x17622: mov bp, 0x5ac3
0x17625: add al, byte ptr es:[0xcd87]
0x1762a: std
2018-12-17T23:12:48.750055802Z 202 PC: 176b9 | UNKNOWN!
2018-12-17T23:12:48.751030859Z 51 PC: 176c0 | Get or set Ctrl-Break
2018-12-17T23:12:48.754385314Z 53 PC: 17e15 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:12:48.755953844Z 37 PC: 17e22 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:12:48.757471985Z 48 PC: 17e3f | Get DOS version
2018-12-17T23:12:48.760082794Z 37 PC: 17e46 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:12:48.761366614Z 26 PC: 12a5f | Set disk transfer address
2018-12-17T23:12:48.762741211Z 81 PC: 1444b | Get current PSP
2018-12-17T23:12:48.76423476Z 61 PC: 144ac | Open file (Filename = 'A:\TEST.COM')
2018-12-17T23:12:48.771711948Z 66 PC: 1450f | Move file pointer
2018-12-17T23:12:48.773490121Z 63 PC: 14529 | Read file or device (Read 7 bytes on handle 5)
2018-12-17T23:12:48.776712086Z 66 PC: 145bf | Move file pointer
2018-12-17T23:12:48.779080255Z 63 PC: 145ca | Read file or device (Read 16 bytes on handle 5)
2018-12-17T23:12:48.785862015Z 63 PC: 14632 | Read file or device (Read 1785 bytes on handle 5)
2018-12-17T23:12:48.793527867Z 62 PC: 144c4 | Close file
2018-12-17T23:12:48.796439058Z 48 PC: 12cad | Get DOS version
2018-12-17T23:12:48.797908667Z 13 PC: 12ac5 | Disk reset
2018-12-17T23:12:48.799616964Z 108 PC: 1275d | Extended open/create file
2018-12-17T23:12:48.808853132Z 66 PC: 12770 | Move file pointer
2018-12-17T23:12:48.810246394Z 63 PC: 1277c | Read file or device (Read 64 bytes on handle 5)
2018-12-17T23:12:48.816354222Z 66 PC: 12770 | Move file pointer
2018-12-17T23:12:48.81835926Z 63 PC: 1277c | Read file or device (Read 64 bytes on handle 5)
2018-12-17T23:12:48.823751809Z 62 PC: 12791 | Close file
2018-12-17T23:12:48.825477592Z 64 PC: 147e1 | Write file or device (Write 26 bytes on handle 2)
2018-12-17T23:12:48.829003088Z 64 PC: 147e1 | Write file or device (Write 2 bytes on handle 2)
2018-12-17T23:12:48.833550542Z 68 PC: 12ae4 | I/O control for devices (Set for = '')
2018-12-17T23:12:48.835732986Z 76 PC: 12ae9 | Terminate with return code (Return code = '1')