Sample viewer

vx.netlux.org/Virus.DOS.DAN.Octubre.1384

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:12:51.462510839Z 68 PC: 12a7e | I/O control for devices (Set for = 'is started by using +the SHELL command in the CONFIG.SYS file. F####,$z$$%U%%%,&y&')
2018-12-17T22:12:51.464495966Z 53 PC: 12ae0 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:12:51.466634155Z 37 PC: 12af5 | Set interrupt vector (Interrupt = '24' AKA 'Reserved')
2018-12-17T22:12:51.468729646Z 74 PC: 12b11 | Reallocate memory
2018-12-17T22:12:51.471522534Z 72 PC: 12b17 | Allocate memory
2018-12-17T22:12:51.473382435Z 37 PC: 12b41 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:12:51.474816729Z 98 PC: 12b45 | Get current PSP
2018-12-17T22:12:51.476046743Z 61 PC: 9f3b2 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:12:51.483221808Z 53 PC: 9f4f4 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:12:51.484327508Z 37 PC: 9f504 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:12:51.485359069Z 63 PC: 9f50f | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:12:51.493604028Z 64 PC: 9f640 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:12:51.498789862Z 64 PC: 9f640 | Write file or device (Write 1384 bytes on handle 5)
2018-12-17T22:12:52.166315913Z 37 PC: 9f58a | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:12:52.173785133Z 62 PC: 12b70 | Close file
2018-12-17T22:12:52.181170899Z 76 PC: 12b7e | Terminate with return code (Return code = '0')