Sample viewer

vx.netlux.org/Virus.DOS.Gotcha.628

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:13:11.084368618Z 218 PC: 12a8b | UNKNOWN!
2018-12-17T22:13:11.08636451Z 48 PC: 12a95 | Get DOS version
2018-12-17T22:13:11.088121845Z 37 PC: 12ad7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:13:11.091373467Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:13:11.093296727Z 72 PC: 12174 | Allocate memory
2018-12-17T22:13:11.095250491Z 72 PC: 1218d | Allocate memory
2018-12-17T22:13:11.098275289Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:13:11.101117096Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:13:11.102261282Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:13:11.103454492Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:11.105252878Z 62 PC: 122ab | Close file
2018-12-17T22:13:11.10667662Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:11.108087074Z 62 PC: 122ab | Close file
2018-12-17T22:13:11.109495775Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:11.112222208Z 62 PC: 122ab | Close file
2018-12-17T22:13:11.11392165Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:11.1155489Z 62 PC: 122ab | Close file
2018-12-17T22:13:11.118139365Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:11.119857918Z 62 PC: 122ab | Close file
2018-12-17T22:13:11.121711761Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:11.124088708Z 62 PC: 122ab | Close file
2018-12-17T22:13:11.130014333Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:11.131932844Z 62 PC: 122ab | Close file
2018-12-17T22:13:11.134275685Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:11.135551049Z 62 PC: 122ab | Close file
2018-12-17T22:13:11.136753799Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:11.139169888Z 62 PC: 122ab | Close file
2018-12-17T22:13:11.140525259Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:11.142374049Z 62 PC: 122ab | Close file
2018-12-17T22:13:11.144724568Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:11.14600764Z 62 PC: 122ab | Close file
2018-12-17T22:13:11.147368685Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:11.149453312Z 62 PC: 122ab | Close file
2018-12-17T22:13:11.150918224Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:11.152262714Z 62 PC: 122ab | Close file
2018-12-17T22:13:11.153721307Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:11.157252901Z 62 PC: 122ab | Close file
2018-12-17T22:13:11.158552454Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:11.159662922Z 62 PC: 122ab | Close file
2018-12-17T22:13:11.162765015Z 99 PC: 9a247 | Get DBCS lead byte table pointer
2018-12-17T22:13:11.163803772Z 56 PC: 94a69 | Get or set country info
2018-12-17T22:13:11.16625588Z 64 PC: 9a4b8 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:13:11.170254224Z 25 PC: 94ad2 | Get default drive
2018-12-17T22:13:11.172150516Z 71 PC: 96d4d | Get current directory
2018-12-17T22:13:11.17638131Z 64 PC: 9a4b8 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:13:11.180256178Z 2 PC: 96d22 | Character output (Char = '3e')
2018-12-17T22:13:11.182836867Z 93 PC: 94b90 | File sharing functions
2018-12-17T22:13:11.184697944Z 93 PC: 94b97 | File sharing functions
2018-12-17T22:13:11.186960873Z 10 PC: 94ba9 | Buffered keyboard input
2018-12-17T22:13:26.054875518Z 0 PC: 0 | Program terminate
2018-12-17T22:13:27.420093003Z 0 PC: 0 | Program terminate
2018-12-17T22:13:27.522319341Z 64 PC: 9a4b8 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:13:27.528815738Z 41 PC: 94c1e | Parse filename
2018-12-17T22:13:27.531710906Z 41 PC: 94c9f | Parse filename
2018-12-17T22:13:27.533589438Z 41 PC: 94cbc | Parse filename
2018-12-17T22:13:27.537166311Z 26 PC: 98167 | Set disk transfer address
2018-12-17T22:13:27.540115907Z 71 PC: 98363 | Get current directory
2018-12-17T22:13:27.547872089Z 78 PC: 9836e | Find first file
2018-12-17T22:13:27.557073422Z 71 PC: 981dc | Get current directory
2018-12-17T22:13:27.560644967Z 73 PC: 97879 | Release memory
2018-12-17T22:13:27.562390045Z 61 PC: 9fa2a | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T22:13:27.56980974Z 98 PC: 9fa51 | Get current PSP
2018-12-17T22:13:27.571193661Z 51 PC: 9fa78 | Get or set Ctrl-Break
2018-12-17T22:13:27.572030598Z 51 PC: 9fa7e | Get or set Ctrl-Break
2018-12-17T22:13:27.572844054Z 53 PC: 9fa85 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:13:27.574480587Z 37 PC: 9fa93 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:13:27.57611944Z 63 PC: 9fb07 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:13:27.582259917Z 63 PC: 9fb18 | Read file or device (Read 24 bytes on handle 5)
2018-12-17T22:13:27.585087959Z 62 PC: 9fa4a | Close file
2018-12-17T22:13:27.586861584Z 37 PC: 9fba0 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:13:27.588509941Z 51 PC: 9fba4 | Get or set Ctrl-Break
2018-12-17T22:13:27.590664187Z 75 PC: 11821 | Execute program
2018-12-17T22:13:27.602032228Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T22:13:27.60623894Z 76 PC: 12a4b | Terminate with return code (Return code = '36')
2018-12-17T22:13:27.609913846Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:13:27.611383667Z 72 PC: 12174 | Allocate memory
2018-12-17T22:13:27.61313789Z 72 PC: 1218d | Allocate memory
2018-12-17T22:13:27.615126077Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:13:27.616190088Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:13:27.617192451Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:13:27.61864233Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:27.620051835Z 62 PC: 122ab | Close file
2018-12-17T22:13:27.621448759Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:27.623299041Z 62 PC: 122ab | Close file
2018-12-17T22:13:27.624699863Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:27.626090411Z 62 PC: 122ab | Close file
2018-12-17T22:13:27.627982307Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:27.62943593Z 62 PC: 122ab | Close file
2018-12-17T22:13:27.630808785Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:27.632761433Z 62 PC: 122ab | Close file
2018-12-17T22:13:27.634148339Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:27.635239177Z 62 PC: 122ab | Close file
2018-12-17T22:13:27.636804001Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:27.637828512Z 62 PC: 122ab | Close file
2018-12-17T22:13:27.638874523Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:27.640338377Z 62 PC: 122ab | Close file
2018-12-17T22:13:27.641750599Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:27.643094933Z 62 PC: 122ab | Close file
2018-12-17T22:13:27.644778907Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:27.646177296Z 62 PC: 122ab | Close file
2018-12-17T22:13:27.647513152Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:27.649365838Z 62 PC: 122ab | Close file
2018-12-17T22:13:27.650705943Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:27.651959362Z 62 PC: 122ab | Close file
2018-12-17T22:13:27.654098862Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:27.6554912Z 62 PC: 122ab | Close file
2018-12-17T22:13:27.657325035Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:27.659400831Z 62 PC: 122ab | Close file
2018-12-17T22:13:27.660801196Z 69 PC: 9fa2a | Duplicate handle
2018-12-17T22:13:27.662083718Z 62 PC: 122ab | Close file
2018-12-17T22:13:27.665183566Z 99 PC: 9a247 | Get DBCS lead byte table pointer
2018-12-17T22:13:27.666349378Z 56 PC: 94a69 | Get or set country info
2018-12-17T22:13:27.668053094Z 64 PC: 9a4b8 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:13:27.673388946Z 25 PC: 94ad2 | Get default drive
2018-12-17T22:13:27.674862885Z 71 PC: 96d4d | Get current directory
2018-12-17T22:13:27.678953621Z 64 PC: 9a4b8 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:13:27.682273153Z 2 PC: 96d22 | Character output (Char = '3e')
2018-12-17T22:13:27.684605047Z 93 PC: 94b90 | File sharing functions
2018-12-17T22:13:27.686198906Z 93 PC: 94b97 | File sharing functions
2018-12-17T22:13:27.688208771Z 10 PC: 94ba9 | Buffered keyboard input