Sample viewer

vx.netlux.org/Virus.DOS.Andry.3791

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:27:14.924646583Z 88 PC: 12bd7 | case 0xGet or set allocation strateg:
2018-12-17T22:27:14.926512005Z 88 PC: 12be1 | case 0xGet or set allocation strateg:
2018-12-17T22:27:14.927707315Z 88 PC: 12bee | case 0xGet or set allocation strateg:
2018-12-17T22:27:14.928892998Z 88 PC: 12bf6 | case 0xGet or set allocation strateg:
2018-12-17T22:27:14.931067033Z 88 PC: 12c9b | case 0xGet or set allocation strateg:
2018-12-17T22:27:14.932392036Z 88 PC: 12ca7 | case 0xGet or set allocation strateg:
2018-12-17T22:27:14.934027682Z 74 PC: 12cc0 | Reallocate memory
2018-12-17T22:27:14.936138797Z 74 PC: 12cce | Reallocate memory
2018-12-17T22:27:14.937758174Z 82 PC: 12ceb | Get DOS internal pointers (SYSVARS)
2018-12-17T22:27:14.939200971Z 48 PC: 12d70 | Get DOS version
2018-12-17T22:27:14.94173844Z 98 PC: 9e9c5 | Get current PSP
2018-12-17T22:27:14.942884257Z 61 PC: 9e9c5 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:27:14.949561561Z 53 PC: 9f2e4 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:14.950863502Z 37 PC: 9f2f4 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:14.952966107Z 66 PC: 9f313 | Move file pointer
2018-12-17T22:27:14.954314428Z 63 PC: 9e9c5 | Read file or device (Read 70 bytes on handle 5)
2018-12-17T22:27:14.956800008Z 87 PC: 9f08d | Get or set file date and time
2018-12-17T22:27:14.959486467Z 66 PC: 9f313 | Move file pointer
2018-12-17T22:27:14.962471647Z 66 PC: 9f313 | Move file pointer
2018-12-17T22:27:14.963704902Z 64 PC: 9e9c5 | Write file or device (Write 3791 bytes on handle 5)
2018-12-17T22:27:14.980194029Z 66 PC: 9f313 | Move file pointer
2018-12-17T22:27:14.98170202Z 64 PC: 9e9c5 | Write file or device (Write 32 bytes on handle 5)
2018-12-17T22:27:14.985001042Z 87 PC: 9f29f | Get or set file date and time
2018-12-17T22:27:14.98727914Z 37 PC: 9f309 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:27:14.988833132Z 62 PC: 9e9c5 | Close file
2018-12-17T22:27:15.001719788Z 76 PC: 9ea2f | Terminate with return code (Return code = '0')