Sample viewer

vx.netlux.org/Virus.DOS.Monster.6109

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:06:57.299661177Z 47 PC: 12a44 | Get disk transfer address
2018-12-17T22:06:57.301742663Z 26 PC: 12a55 | Set disk transfer address
2018-12-17T22:06:57.302869256Z 60 PC: 12a7c | Create or truncate file
2018-12-17T22:06:57.32232777Z 64 PC: 12b2c | Write file or device (Write 70 bytes on handle 5)
2018-12-17T22:06:57.325787325Z 64 PC: 12b2c | Write file or device (Write 143 bytes on handle 5)
2018-12-17T22:06:57.331408863Z 64 PC: 12b2c | Write file or device (Write 771 bytes on handle 5)
2018-12-17T22:06:57.339810558Z 64 PC: 12b2c | Write file or device (Write 130 bytes on handle 5)
2018-12-17T22:06:57.349261783Z 64 PC: 12b2c | Write file or device (Write 232 bytes on handle 5)
2018-12-17T22:06:57.354240669Z 64 PC: 12b2c | Write file or device (Write 267 bytes on handle 5)
2018-12-17T22:06:57.377558346Z 64 PC: 12b2c | Write file or device (Write 1147 bytes on handle 5)
2018-12-17T22:06:57.386489765Z 64 PC: 12b2c | Write file or device (Write 204 bytes on handle 5)
2018-12-17T22:06:57.390677099Z 62 PC: 12ab9 | Close file
2018-12-17T22:06:57.398717439Z 74 PC: 12ac3 | Reallocate memory
2018-12-17T22:06:57.400214596Z 75 PC: 12b63 | Execute program
2018-12-17T22:06:57.423572142Z 80 PC: 16ef9 | Set current PSP
2018-12-17T22:06:57.425508414Z 48 PC: 16efe | Get DOS version
2018-12-17T22:06:57.427294581Z 99 PC: 1d6e0 | Get DBCS lead byte table pointer
2018-12-17T22:06:57.431797405Z 101 PC: 16f84 | Get extended country info
2018-12-17T22:06:57.43314442Z 99 PC: 16f8a | Get DBCS lead byte table pointer
2018-12-17T22:06:57.435291231Z 74 PC: 16fec | Reallocate memory
2018-12-17T22:06:57.437085161Z 25 PC: 17023 | Get default drive
2018-12-17T22:06:57.438690664Z 37 PC: 16ae3 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:06:57.440237775Z 37 PC: 16aea | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:06:57.441639239Z 37 PC: 16af1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:06:57.44492217Z 61 PC: 171fa | Open file
2018-12-17T22:06:57.450560515Z 68 PC: 17203 | I/O control for devices
2018-12-17T22:06:57.452485684Z 68 PC: 17218 | I/O control for devices (Set for = ' _MOHCTP_.obj _MOHCTP_.com')
2018-12-17T22:06:57.454795212Z 62 PC: 1722e | Close file
2018-12-17T22:06:57.456700067Z 62 PC: 1722e | Close file
2018-12-17T22:06:57.458867208Z 62 PC: 1722e | Close file
2018-12-17T22:06:57.462408535Z 69 PC: 17237 | Duplicate handle
2018-12-17T22:06:57.464339421Z 69 PC: 1723b | Duplicate handle
2018-12-17T22:06:57.466271807Z 69 PC: 1723f | Duplicate handle
2018-12-17T22:06:57.469325194Z 62 PC: 17243 | Close file
2018-12-17T22:06:57.478039553Z 74 PC: 15c8c | Reallocate memory
2018-12-17T22:06:57.479463457Z 72 PC: 15ccd | Allocate memory
2018-12-17T22:06:57.485806809Z 72 PC: 15d05 | Allocate memory
2018-12-17T22:06:57.489152269Z 72 PC: 15d0d | Allocate memory