Sample viewer

vx.netlux.org/Virus.DOS.OneHalf.3544.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:31:05.355050271Z 75 PC: 1a34e | Execute program
2018-12-17T22:31:05.357184951Z 82 PC: 1a357 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:31:05.358281255Z 53 PC: 1a369 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:31:05.359406455Z 53 PC: 1a370 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:31:05.361643708Z 37 PC: 1a381 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:31:05.365387316Z 37 PC: 1a3a9 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:31:05.68381181Z 61 PC: 1a4b6 | Open file (Filename = '')
2018-12-17T22:31:05.691443305Z 66 PC: 1a26d | Move file pointer
2018-12-17T22:31:05.693432439Z 63 PC: 1a26d | Read file or device (Read 48 bytes on handle 5)
2018-12-17T22:31:05.696139879Z 62 PC: 1a26d | Close file
2018-12-17T22:31:05.698617882Z 53 PC: 191f0 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:31:05.70027108Z 37 PC: 191f9 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:31:05.701548288Z 53 PC: 191f0 | Get interrupt vector (Interrupt = '127' AKA 'UNKNOWN!')
2018-12-17T22:31:05.703000733Z 37 PC: 191f9 | Set interrupt vector (Interrupt = '127' AKA 'UNKNOWN!')
2018-12-17T22:31:05.705074231Z 98 PC: 18f34 | Get current PSP
2018-12-17T22:31:05.70648071Z 98 PC: 19f74 | Get current PSP
2018-12-17T22:31:05.708349524Z 61 PC: 13a48 | Open file (Filename = '��������������~^')
2018-12-17T22:31:05.715418745Z 61 PC: 18f56 | Open file (Filename = '��������������~N')
2018-12-17T22:31:05.722398968Z 37 PC: 18fc7 | Set interrupt vector (Interrupt = '127' AKA 'UNKNOWN!')
2018-12-17T22:31:05.723894252Z 9 PC: 18fd1 | Display string (Could not find end pointer)
2018-12-17T22:31:05.728955913Z 9 PC: 18fe0 | Display string (Could not find end pointer)
2018-12-17T22:31:05.732091064Z 9 PC: 18fe7 | Display string (Could not find end pointer)
2018-12-17T22:31:05.736955716Z 37 PC: 190ec | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:31:05.742501203Z 76 PC: 190f2 | Terminate with return code (Return code = '33')