Sample viewer

vx.netlux.org/Virus.DOS.Kak.391

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:08:02.738337759Z 26 PC: 12e42 | Set disk transfer address
2018-12-17T22:08:02.743865169Z 78 PC: 12e4d | Find first file
2018-12-17T22:08:02.750212738Z 61 PC: 12e99 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:08:02.756870868Z 66 PC: 12ea4 | Move file pointer
2018-12-17T22:08:02.760277828Z 63 PC: 12eaf | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:08:02.766699471Z 66 PC: 12eb8 | Move file pointer
2018-12-17T22:08:02.76811771Z 64 PC: 12ec3 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:08:02.774980689Z 66 PC: 12ecc | Move file pointer
2018-12-17T22:08:02.77637031Z 64 PC: 12ed7 | Write file or device (Write 391 bytes on handle 5)
2018-12-17T22:08:02.798420628Z 87 PC: 12ef2 | Get or set file date and time
2018-12-17T22:08:02.801798257Z 62 PC: 12ef6 | Close file
2018-12-17T22:08:02.812546733Z 9 PC: 13064 | Display string (String= 'Process killer Version 2.03 ')
2018-12-17T22:08:02.816482057Z 48 PC: 13068 | Get DOS version
2018-12-17T22:08:02.817626582Z 53 PC: 1307d | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:08:02.819375925Z 37 PC: 1308d | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:08:02.821022859Z 53 PC: 1309c | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:08:02.822530774Z 37 PC: 130ac | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:08:02.824373196Z 9 PC: 130c9 | Display string (String= 'Kill is now installed! Alt+ESC will kill the current process ')
2018-12-17T22:08:02.832553296Z 49 PC: 130ce | Terminate and stay resident (Return code = '0' | Memory size = '105')