Sample viewer

vx.netlux.org/Virus.DOS.Beer.1791

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:29:26.857277451Z 48 PC: 148c2 | Get DOS version
2018-12-17T22:29:26.860757069Z 37 PC: 1494d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:29:26.862262729Z 48 PC: 141c3 | Get DOS version
2018-12-17T22:29:26.863832481Z 48 PC: 12a63 | Get DOS version
2018-12-17T22:29:26.874170956Z 53 PC: 9ee78 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:26.87528927Z 37 PC: 9ee78 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:26.876385543Z 67 PC: 9ee78 | Get or set file attributes
2018-12-17T22:29:26.885622646Z 67 PC: 9ee78 | Get or set file attributes
2018-12-17T22:29:26.904078248Z 61 PC: 9ee78 | Open file (Filename = '4 Microsoft Corp Licensed Material - Property of Microsoft All rights reserved ')
2018-12-17T22:29:26.910828708Z 87 PC: 9ee78 | Get or set file date and time
2018-12-17T22:29:26.913353295Z 66 PC: 9ee78 | Move file pointer
2018-12-17T22:29:26.915054723Z 66 PC: 9ee78 | Move file pointer
2018-12-17T22:29:26.916808734Z 63 PC: 9ee78 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:29:26.926318958Z 66 PC: 9ee78 | Move file pointer
2018-12-17T22:29:26.928100584Z 63 PC: 9ee78 | Read file or device (Read 16 bytes on handle 5)
2018-12-17T22:29:26.934940271Z 66 PC: 9ee78 | Move file pointer
2018-12-17T22:29:26.93625167Z 64 PC: 9ee78 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:29:26.939290725Z 66 PC: 9ee78 | Move file pointer
2018-12-17T22:29:26.941244009Z 64 PC: 9ee78 | Write file or device (Write 1791 bytes on handle 5)
2018-12-17T22:29:26.950650564Z 87 PC: 9ee78 | Get or set file date and time
2018-12-17T22:29:26.95338852Z 62 PC: 9ee78 | Close file
2018-12-17T22:29:26.961404908Z 37 PC: 9ee78 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:26.962965818Z 61 PC: 12cb5 | Open file (Filename = '')
2018-12-17T22:29:26.970020109Z 9 PC: 12a87 | Display string (String= 'Self test: ')
2018-12-17T22:29:26.972431221Z 93 PC: 12b22 | File sharing functions
2018-12-17T22:29:26.97744922Z 76 PC: 12b07 | Terminate with return code (Return code = '1')