Sample viewer

vx.netlux.org/Virus.DOS.Backsu.3152

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:54:10.163057758Z 240 PC: 17483 | UNKNOWN!
2018-12-17T21:54:10.164363755Z 48 PC: 174a7 | Get DOS version
2018-12-17T21:54:10.165672811Z 25 PC: 174b0 | Get default drive
2018-12-17T21:54:10.190001946Z 48 PC: 12a4c | Get DOS version
2018-12-17T21:54:10.192129033Z 53 PC: 12ba8 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:54:10.193224768Z 53 PC: 12bb5 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T21:54:10.194287667Z 53 PC: 12bc2 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T21:54:10.196279313Z 53 PC: 12bcf | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T21:54:10.197514309Z 37 PC: 12be3 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:54:10.198857572Z 74 PC: 12b19 | Reallocate memory
2018-12-17T21:54:10.2029716Z 37 PC: 174e1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:54:10.204545317Z 37 PC: 174e1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:54:10.206215592Z 51 PC: 28141 | Get or set Ctrl-Break
2018-12-17T21:54:10.215307928Z 37 PC: 12bef | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:54:10.225281865Z 37 PC: 12bfa | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T21:54:10.227331376Z 37 PC: 12c05 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T21:54:10.229922426Z 37 PC: 12c10 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T21:54:10.233643383Z 76 PC: 12b98 | Terminate with return code (Return code = '1')