Sample viewer

vx.netlux.org/Virus.DOS.Tver.1000

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:29:51.039669307Z 48 PC: 12a9f | Get DOS version
2018-12-17T22:29:51.041802399Z 47 PC: 12aab | Get disk transfer address
2018-12-17T22:29:51.043193973Z 53 PC: 12ab5 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:51.044659324Z 37 PC: 12ac5 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:51.046736761Z 26 PC: 12acd | Set disk transfer address
2018-12-17T22:29:51.048035349Z 78 PC: 12b5e | Find first file
2018-12-17T22:29:51.061149868Z 67 PC: 12b8c | Get or set file attributes
2018-12-17T22:29:51.067511213Z 67 PC: 12b97 | Get or set file attributes
2018-12-17T22:29:51.084160995Z 61 PC: 12ba1 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:29:51.088525064Z 87 PC: 12bad | Get or set file date and time
2018-12-17T22:29:51.090004428Z 63 PC: 12bbd | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:29:51.094293016Z 66 PC: 12bd4 | Move file pointer
2018-12-17T22:29:51.095794655Z 64 PC: 12bfb | Write file or device (Write 1000 bytes on handle 5)
2018-12-17T22:29:51.101560508Z 66 PC: 12c0b | Move file pointer
2018-12-17T22:29:51.103445071Z 64 PC: 12c17 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:29:51.109832591Z 87 PC: 12c28 | Get or set file date and time
2018-12-17T22:29:51.111233072Z 62 PC: 12c2c | Close file
2018-12-17T22:29:51.119562566Z 67 PC: 12c37 | Get or set file attributes
2018-12-17T22:29:51.137637926Z 26 PC: 12c40 | Set disk transfer address
2018-12-17T22:29:51.138758583Z 37 PC: 12c4f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:51.148530813Z 53 PC: 12a67 | Get interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:29:51.149705641Z 37 PC: 12a7a | Set interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:29:51.150694297Z 2 PC: 12a5e | Character output (Char = '2a')
2018-12-17T22:29:51.153224331Z 49 PC: 12a85 | Terminate and stay resident (Return code = '0' | Memory size = '19')