Sample viewer

vx.netlux.org/Virus.DOS.Polymorph.924

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:30:03.666553128Z 53 PC: 12aaa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:03.668394208Z 37 PC: 12ab9 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:30:03.670159522Z 25 PC: 12bd8 | Get default drive
2018-12-17T22:30:03.671468316Z 14 PC: 12be9 | Set default drive (Drive = 'C')
2018-12-17T22:30:03.674242999Z 47 PC: 12bf9 | Get disk transfer address
2018-12-17T22:30:03.676339468Z 26 PC: 12c12 | Set disk transfer address
2018-12-17T22:30:03.677645628Z 78 PC: 12c1e | Find first file
2018-12-17T22:30:03.683798708Z 67 PC: 12c4e | Get or set file attributes
2018-12-17T22:30:03.697620852Z 67 PC: 12c59 | Get or set file attributes
2018-12-17T22:30:04.593422612Z 61 PC: 12c60 | Open file (Filename = 'COMMAND.COM')
2018-12-17T22:30:04.6044857Z 66 PC: 12c75 | Move file pointer
2018-12-17T22:30:04.607132642Z 87 PC: 12cb3 | Get or set file date and time
2018-12-17T22:30:04.608987189Z 66 PC: 12ce7 | Move file pointer
2018-12-17T22:30:04.611458862Z 63 PC: 12cfb | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:30:04.616004377Z 66 PC: 12d07 | Move file pointer
2018-12-17T22:30:04.618694434Z 64 PC: 12d1e | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:30:04.622526221Z 66 PC: 12d29 | Move file pointer
2018-12-17T22:30:04.625981403Z 64 PC: 12dd5 | Write file or device (Write 924 bytes on handle 5)
2018-12-17T22:30:04.644806018Z 87 PC: 12df3 | Get or set file date and time
2018-12-17T22:30:04.646429965Z 62 PC: 12df7 | Close file
2018-12-17T22:30:04.653102357Z 26 PC: 12c3e | Set disk transfer address
2018-12-17T22:30:04.654898318Z 37 PC: 12ba7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')