Sample viewer

vx.netlux.org/Virus.DOS.Sina.1822

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:18:21.642011628Z 255 PC: 12a53 | UNKNOWN!
2018-12-17T22:18:21.64438689Z 53 PC: 12aaa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:18:21.645523291Z 37 PC: 12abc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:18:21.646660741Z 74 PC: 12acd | Reallocate memory
2018-12-17T22:18:21.648457919Z 75 PC: 12b57 | Execute program
2018-12-17T22:18:21.665511095Z 53 PC: 12b57 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:18:21.667078187Z 37 PC: 12b57 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:18:21.668583094Z 67 PC: 12b57 | Get or set file attributes
2018-12-17T22:18:21.67856446Z 67 PC: 12b57 | Get or set file attributes
2018-12-17T22:18:22.363245897Z 61 PC: 12b57 | Open file (Filename = 'C:\DOS\KEYB.COM')
2018-12-17T22:18:22.370642643Z 87 PC: 12b57 | Get or set file date and time
2018-12-17T22:18:22.373269939Z 63 PC: 12b57 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:18:22.379140607Z 63 PC: 12b57 | Read file or device (Read 30 bytes on handle 5)
2018-12-17T22:18:22.381994525Z 66 PC: 12b57 | Move file pointer
2018-12-17T22:18:22.384827578Z 63 PC: 12b57 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:18:22.391677604Z 72 PC: 12b57 | Allocate memory
2018-12-17T22:18:22.393701313Z 64 PC: 12b57 | Write file or device (Write 1819 bytes on handle 5)
2018-12-17T22:18:22.410268585Z 73 PC: 12b57 | Release memory
2018-12-17T22:18:22.411392982Z 64 PC: 12b57 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:18:22.413296503Z 66 PC: 12b57 | Move file pointer
2018-12-17T22:18:22.415063042Z 64 PC: 12b57 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:18:22.416996448Z 87 PC: 12b57 | Get or set file date and time
2018-12-17T22:18:22.418204366Z 62 PC: 12b57 | Close file
2018-12-17T22:18:22.423033766Z 67 PC: 12b57 | Get or set file attributes
2018-12-17T22:18:22.429991866Z 37 PC: 12b57 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:18:22.431378459Z 75 PC: 12b02 | Execute program
2018-12-17T22:18:22.433572383Z 42 PC: 12b57 | Get date 0x12b57: ret
0x12b58: nop
0x12b59: iret
0x12b5a: push bp
0x12b5b: add word ptr [bx + 0x11], dx
0x12b5e: push ax
0x12b5f: push bx
0x12b60: push ds
0x12b61: push dx
0x12b62: push es
0x12b63: mov ax, 0x3524
0x12b66: call 0x22b51
0x12b69: mov word ptr cs:[0x21a], bx
0x12b6e: mov word ptr cs:[0x21c], es
0x12b73: push cs
0x12b74: pop ds
0x12b75: mov dx, 0x218
0x12b78: mov ax, 0x2524
0x12b7b: call 0x22b51
0x12b7e: pop es
2018-12-17T22:18:22.448720654Z 77 PC: 12b27 | Get program return code
2018-12-17T22:18:22.456747841Z 49 PC: 12b36 | Terminate and stay resident (Return code = '0' | Memory size = '130')