Sample viewer

vx.netlux.org/Virus.DOS.Preacher.475

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:53:42.06104172Z 53 PC: 12b9c | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T21:53:42.067460747Z 37 PC: 12bb7 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T21:53:42.073727952Z 74 PC: 12bce | Reallocate memory
2018-12-17T21:53:42.075909793Z 60 PC: 12bd8 | Create or truncate file
2018-12-17T21:53:42.093362008Z 64 PC: 12be8 | Write file or device (Write 151 bytes on handle 5)
2018-12-17T21:53:42.097082971Z 62 PC: 12bec | Close file
2018-12-17T21:53:42.105869108Z 75 PC: 12c05 | Execute program
2018-12-17T21:53:42.130720083Z 9 PC: 22b33 | Display string (String= ' Mabuhay! This program came from Bahay Kawayan at http://come.to/hexfiles Putoksa Kawayan [email protected] ')
2018-12-17T21:53:42.144588117Z 76 PC: 22b37 | Terminate with return code (Return code = '36')
2018-12-17T21:53:42.148043912Z 49 PC: 12c12 | Terminate and stay resident (Return code = '0' | Memory size = '4096')