Sample viewer

vx.netlux.org/Virus.DOS.Ninja.Raving.1195

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:30:02.890429239Z 149 PC: 1316d | UNKNOWN!
2018-12-17T22:30:02.892512308Z 9 PC: 12f33 | Display string (String= ' Dos Navigator Version 1.42 Copyright (C) 1991,96 RIT Research Labs ')
2018-12-17T22:30:02.8991151Z 82 PC: 12f37 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:30:02.900914784Z 53 PC: 12f84 | Get interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:30:02.913908864Z 37 PC: 12f93 | Set interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:30:02.915919363Z 61 PC: 130a0 | Open file (Filename = 'A:\TEST.FLG')
2018-12-17T22:30:02.92328379Z 60 PC: 130ab | Create or truncate file
2018-12-17T22:30:02.944443503Z 66 PC: 130ea | Move file pointer
2018-12-17T22:30:02.947125304Z 64 PC: 130fa | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:30:02.952103354Z 62 PC: 13102 | Close file
2018-12-17T22:30:02.961466731Z 74 PC: 13117 | Reallocate memory
2018-12-17T22:30:02.964635711Z 75 PC: 12b30 | Execute program
2018-12-17T22:30:02.975689049Z 9 PC: 12ba4 | Display string (String= 'Not able to run DN.PRG ')
2018-12-17T22:30:02.98044176Z 37 PC: 12bb1 | Set interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:30:02.982622795Z 76 PC: 12bb6 | Terminate with return code (Return code = '255')