Sample viewer

vx.netlux.org/Virus.DOS.Beer.1928

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:33:12.382243117Z 48 PC: 1494b | Get DOS version
2018-12-17T22:33:12.384092871Z 37 PC: 149d5 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:33:12.38527341Z 48 PC: 141c3 | Get DOS version
2018-12-17T22:33:12.386480244Z 48 PC: 12a63 | Get DOS version
2018-12-17T22:33:12.406269189Z 53 PC: 9ef06 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:33:12.407607039Z 37 PC: 9ef06 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:33:12.409187004Z 67 PC: 9ef06 | Get or set file attributes
2018-12-17T22:33:12.41569708Z 67 PC: 9ef06 | Get or set file attributes
2018-12-17T22:33:12.432305128Z 61 PC: 9ef06 | Open file (Filename = '4 Microsoft Corp Licensed Material - Property of Microsoft All rights reserved ')
2018-12-17T22:33:12.438595908Z 87 PC: 9ef06 | Get or set file date and time
2018-12-17T22:33:12.440454388Z 66 PC: 9ef06 | Move file pointer
2018-12-17T22:33:12.44197712Z 66 PC: 9ef06 | Move file pointer
2018-12-17T22:33:12.443362201Z 63 PC: 9ef06 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:33:12.446916625Z 66 PC: 9ef06 | Move file pointer
2018-12-17T22:33:12.449200623Z 63 PC: 9ef06 | Read file or device (Read 16 bytes on handle 5)
2018-12-17T22:33:12.456071444Z 66 PC: 9ef06 | Move file pointer
2018-12-17T22:33:12.458032369Z 64 PC: 9ef06 | Write file or device (Write 1928 bytes on handle 5)
2018-12-17T22:33:12.467203036Z 66 PC: 9ef06 | Move file pointer
2018-12-17T22:33:12.468574667Z 64 PC: 9ef06 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:33:12.471728035Z 87 PC: 9ef06 | Get or set file date and time
2018-12-17T22:33:12.478411327Z 62 PC: 9ef06 | Close file
2018-12-17T22:33:12.486301706Z 37 PC: 9ef06 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:33:12.488070837Z 61 PC: 12cb5 | Open file (Filename = '')
2018-12-17T22:33:12.495193405Z 9 PC: 12a87 | Display string (String= 'Self test: ')
2018-12-17T22:33:12.497725176Z 93 PC: 12b22 | File sharing functions
2018-12-17T22:33:12.503354433Z 76 PC: 12b07 | Terminate with return code (Return code = '1')