Sample viewer

vx.netlux.org/Virus.DOS.WpcBats.2793

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:18:54.66397147Z 48 PC: 12ea2 | Get DOS version
2018-12-17T22:18:54.66633895Z 72 PC: 12eb1 | Allocate memory
2018-12-17T22:18:54.668201884Z 74 PC: 12ec3 | Reallocate memory
2018-12-17T22:18:54.669952762Z 74 PC: 12ed2 | Reallocate memory
2018-12-17T22:18:54.671616178Z 72 PC: 12ee8 | Allocate memory
2018-12-17T22:18:54.674714136Z 53 PC: 9ef5c | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:18:54.675953792Z 37 PC: 9ef7c | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:18:54.677730911Z 47 PC: 9f73e | Get disk transfer address
2018-12-17T22:18:54.679144293Z 53 PC: 9f73e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:18:54.680453658Z 37 PC: 9f73e | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:18:54.681646056Z 26 PC: 9f73e | Set disk transfer address
2018-12-17T22:18:54.683391007Z 46 PC: 9f73e | Set verify flag
2018-12-17T22:18:54.684721916Z 78 PC: 9f73e | Find first file
2018-12-17T22:18:54.691256112Z 26 PC: 9f73e | Set disk transfer address
2018-12-17T22:18:54.692922279Z 37 PC: 9f73e | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:18:54.695822986Z 9 PC: 12ad3 | Display string (String= ' Mabuhay! This program came from Bahay Kawayan at http://come.to/hexfiles Putoksa Kawayan [email protected] ')
2018-12-17T22:18:54.711569851Z 76 PC: 12ad7 | Terminate with return code (Return code = '36')