Sample viewer

vx.netlux.org/Virus.DOS.MtE.Shocker

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:18:49.807467144Z 53 PC: 132ff | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:18:49.80941376Z 74 PC: 1337c | Reallocate memory
2018-12-17T22:18:49.81087394Z 85 PC: 13398 | Create program PSP
2018-12-17T22:18:49.812695406Z 26 PC: 133b0 | Set disk transfer address
2018-12-17T22:18:49.821993738Z 37 PC: 18d41 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:18:49.826152346Z 48 PC: 18d58 | Get DOS version
2018-12-17T22:18:49.828534924Z 51 PC: 13bf4 | Get or set Ctrl-Break
2018-12-17T22:18:49.829750909Z 51 PC: 13bfb | Get or set Ctrl-Break
2018-12-17T22:18:49.83078902Z 53 PC: 12d0b | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:18:49.832012544Z 37 PC: 12d15 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:18:49.833164601Z 53 PC: 12d19 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:18:49.834456247Z 37 PC: 12d2b | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:18:49.83555266Z 47 PC: 12d2e | Get disk transfer address
2018-12-17T22:18:49.836649588Z 26 PC: 12d37 | Set disk transfer address
2018-12-17T22:18:49.838486413Z 81 PC: 12f6a | Get current PSP
2018-12-17T22:18:49.840724311Z 67 PC: 12c53 | Get or set file attributes
2018-12-17T22:18:49.842619879Z 44 PC: 12bec | Get time 0x12bec: xchg ax, dx
0x12bed: sub al, 0x64
0x12bef: xchg ax, bx
0x12bf0: xor dx, dx
0x12bf2: mov di, 0x1d77
0x12bf5: cmp dx, word ptr [di]
0x12bf7: je 0x12c31
0x12bf9: sub cx, word ptr [di]
0x12bfb: dec ch
0x12bfd: jne 0x12c31
0x12bff: mov word ptr [di], dx
0x12c01: mov ds, dx
0x12c03: mov si, 0x400
0x12c06: mov cx, 4
0x12c09: inc dx
0x12c0a: lodsw ax, word ptr [si]
0x12c0b: test ax, ax
0x12c0d: loope 0x12c09
0x12c0f: push cs
0x12c10: pop ds
2018-12-17T22:18:49.846010962Z 78 PC: 12b59 | Find first file
2018-12-17T22:18:49.852722526Z 79 PC: 12b59 | Find next file
2018-12-17T22:18:49.855844331Z 79 PC: 12b59 | Find next file
2018-12-17T22:18:49.859389275Z 79 PC: 12b59 | Find next file
2018-12-17T22:18:49.862272674Z 79 PC: 12b59 | Find next file
2018-12-17T22:18:49.865223337Z 79 PC: 12b59 | Find next file
2018-12-17T22:18:49.86863422Z 79 PC: 12b59 | Find next file
2018-12-17T22:18:49.871513846Z 79 PC: 12b59 | Find next file
2018-12-17T22:18:49.874365284Z 79 PC: 12b59 | Find next file
2018-12-17T22:18:49.87858769Z 79 PC: 12b59 | Find next file
2018-12-17T22:18:49.881774758Z 78 PC: 12b59 | Find first file
2018-12-17T22:18:49.88837423Z 79 PC: 12b59 | Find next file
2018-12-17T22:18:49.891887537Z 79 PC: 12b59 | Find next file
2018-12-17T22:18:49.894772789Z 79 PC: 12b59 | Find next file
2018-12-17T22:18:49.897653928Z 79 PC: 12b59 | Find next file
2018-12-17T22:18:49.90094247Z 79 PC: 12b59 | Find next file
2018-12-17T22:18:49.903842575Z 79 PC: 12b59 | Find next file
2018-12-17T22:18:49.906813134Z 67 PC: 12c53 | Get or set file attributes
2018-12-17T22:18:49.913233652Z 61 PC: 12c67 | Open file (Filename = 'A:\MANDEL.COM')
2018-12-17T22:18:49.920839138Z 63 PC: 138e0 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:18:49.928005318Z 66 PC: 138e0 | Move file pointer
2018-12-17T22:18:49.92942846Z 63 PC: 138e0 | Read file or device (Read 8192 bytes on handle 5)
2018-12-17T22:18:49.932810426Z 63 PC: 138e0 | Read file or device (Read 28672 bytes on handle 5)
2018-12-17T22:18:49.934943123Z 66 PC: 138e0 | Move file pointer
2018-12-17T22:18:49.936471109Z 67 PC: 13895 | Get or set file attributes
2018-12-17T22:18:49.944165257Z 60 PC: 1389d | Create or truncate file
2018-12-17T22:18:49.962339983Z 66 PC: 138e0 | Move file pointer
2018-12-17T22:18:49.963805822Z 63 PC: 138e0 | Read file or device (Read 58874 bytes on handle 5)
2018-12-17T22:18:49.966869521Z 64 PC: 138bc | Write file or device (Write 501 bytes on handle 6)
2018-12-17T22:18:49.969355456Z 63 PC: 138e0 | Read file or device (Read 58874 bytes on handle 5)
2018-12-17T22:18:49.970636349Z 62 PC: 138c6 | Close file
2018-12-17T22:18:49.976461404Z 66 PC: 138e0 | Move file pointer
2018-12-17T22:18:49.977609632Z 87 PC: 12c75 | Get or set file date and time
2018-12-17T22:18:49.982216284Z 64 PC: 138e0 | Write file or device (Write 7482 bytes on handle 5)
2018-12-17T22:18:49.988460584Z 87 PC: 12c81 | Get or set file date and time
2018-12-17T22:18:49.990076922Z 62 PC: 138e0 | Close file
2018-12-17T22:18:49.998869602Z 73 PC: 12d7f | Release memory
2018-12-17T22:18:50.000953376Z 26 PC: 12d86 | Set disk transfer address
2018-12-17T22:18:50.002106842Z 37 PC: 12d86 | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:18:50.003115444Z 37 PC: 12d86 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:18:50.005348265Z 51 PC: 13c09 | Get or set Ctrl-Break
2018-12-17T22:18:50.007230719Z 108 PC: 18d6c | Extended open/create file
2018-12-17T22:18:50.009248509Z 9 PC: 169b6 | Display string (String= 'Hello - Copyright S & S International, 1990 ')