Sample viewer

vx.netlux.org/Virus.DOS.Roet.1876

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:55:24.030702948Z 177 PC: 1fea4 | UNKNOWN!
2018-12-17T21:55:24.034663376Z 48 PC: 1f113 | Get DOS version
2018-12-17T21:55:24.037807965Z 48 PC: 17606 | Get DOS version
2018-12-17T21:55:24.039474568Z 55 PC: 1762a | Get or set switch character
2018-12-17T21:55:24.042365903Z 68 PC: 17850 | I/O control for devices (Set for = 'ÿ')
2018-12-17T21:55:24.044272426Z 68 PC: 17850 | I/O control for devices (Set for = '')
2018-12-17T21:55:24.046070294Z 51 PC: 1b3f6 | Get or set Ctrl-Break
2018-12-17T21:55:24.048168199Z 51 PC: 1b402 | Get or set Ctrl-Break
2018-12-17T21:55:24.049159444Z 53 PC: 1b40e | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:55:24.050397089Z 53 PC: 1b41c | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T21:55:24.052485244Z 53 PC: 1b42a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:55:24.053701756Z 37 PC: 1b441 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T21:55:24.054625576Z 37 PC: 1b44a | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T21:55:24.056455147Z 37 PC: 1b453 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:55:24.057666228Z 53 PC: 1985b | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T21:55:24.058999949Z 37 PC: 19868 | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T21:55:24.060454917Z 53 PC: 1986f | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T21:55:24.061834861Z 37 PC: 1987c | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T21:55:24.062886409Z 53 PC: 19889 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T21:55:24.067141329Z 48 PC: 198f6 | Get DOS version
2018-12-17T21:55:24.068902931Z 37 PC: 17f64 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T21:55:24.070346505Z 37 PC: 191a2 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T21:55:24.072667294Z 44 PC: 16f06 | Get time 0x16f06: cmp dl, 0x32
0x16f09: jb 0x16f1f
0x16f0b: inc dh
0x16f0d: cmp dh, 0x3c
0x16f10: jb 0x16f1f
0x16f12: mov dh, 0
0x16f14: inc cl
0x16f16: cmp cl, 0x3c
0x16f19: jb 0x16f1f
0x16f1b: mov cl, 0
0x16f1d: inc ch
0x16f1f: pop bx
0x16f20: mov al, ch
0x16f22: call 0x1700e
0x16f25: mov al, 0x3a
0x16f27: call 0x1701a
0x16f2a: mov al, cl
0x16f2c: call 0x1700e
0x16f2f: mov al, 0x3a
0x16f31: call 0x1701a