Sample viewer

vx.netlux.org/Virus.DOS.AntiEta.5297

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:14:28.617982175Z 48 PC: 12a63 | Get DOS version
2018-12-17T22:14:28.625305387Z 53 PC: 12a79 | Get interrupt vector (Interrupt = '40' AKA 'Random block write')
2018-12-17T22:14:28.627190044Z 98 PC: 12a85 | Get current PSP
2018-12-17T22:14:28.628106895Z 74 PC: 12aab | Reallocate memory
2018-12-17T22:14:28.630064896Z 74 PC: 12ab2 | Reallocate memory
2018-12-17T22:14:28.632012877Z 80 PC: 12abc | Set current PSP
2018-12-17T22:14:28.632803279Z 72 PC: 12ac7 | Allocate memory
2018-12-17T22:14:28.635323534Z 80 PC: 12ae9 | Set current PSP
2018-12-17T22:14:28.63629013Z 76 PC: 12b0a | Terminate with return code (Return code = '0')
2018-12-17T22:14:28.639502259Z 80 PC: 9e729 | Set current PSP
2018-12-17T22:14:28.642335502Z 76 PC: 9e74a | Terminate with return code (Return code = '0')