Sample viewer

vx.netlux.org/Virus.DOS.Ply.4224

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:27:05.247542769Z 26 PC: 133fe | Set disk transfer address
2018-12-17T22:27:05.249334376Z 53 PC: 13bc0 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:05.250386652Z 37 PC: 12f13 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:05.251403586Z 78 PC: 12f37 | Find first file
2018-12-17T22:27:05.257796129Z 61 PC: 12fc9 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:27:05.264515277Z 63 PC: 12fd9 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:27:05.26692638Z 62 PC: 13b7f | Close file
2018-12-17T22:27:05.274788939Z 79 PC: 12f37 | Find next file
2018-12-17T22:27:05.277247143Z 37 PC: 12f49 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:05.278385559Z 98 PC: 133f2 | Get current PSP
2018-12-17T22:27:05.279686748Z 26 PC: 13ae8 | Set disk transfer address
2018-12-17T22:27:05.280709253Z 98 PC: 13131 | Get current PSP
2018-12-17T22:27:05.288315077Z 76 PC: 12aa4 | Terminate with return code (Return code = '0')