Sample viewer

vx.netlux.org/Virus.DOS.Permutan.544

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:29:33.403803726Z 53 PC: 12acc | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:29:33.405505461Z 37 PC: 12b01 | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:29:33.406459642Z 37 PC: 12b0c | Set interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T22:29:33.407462118Z 61 PC: 12b73 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:29:33.414126331Z 63 PC: 12b8b | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:29:33.417126839Z 62 PC: 12c84 | Close file
2018-12-17T22:29:33.41862066Z 49 PC: 12c92 | Terminate and stay resident (Return code = '0' | Memory size = '54')