Sample viewer

vx.netlux.org/Virus.DOS.Gps.2313

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:34:37.803058408Z 26 PC: 13843 | Set disk transfer address
2018-12-17T22:34:37.805388848Z 44 PC: 13357 | Get time 0x13357: jmp 0x1384c
0x1335a: mov cx, 0x1c
0x1335d: jmp 0x133bc
0x13360: mov sp, word ptr cs:[0x5a1]
0x13365: jmp 0x13660
0x13368: add word ptr cs:[0x5a3], ax
0x1336d: jmp 0x134d9
0x13370: loop 0x13375
0x13372: jmp 0x1365f
0x13375: jmp 0x13310
0x13378: mov cx, 0x200
0x1337b: jmp 0x1331c
0x1337e: pop bx
0x1337f: jmp 0x1368b
0x13382: push ax
0x13383: jmp 0x13821
0x13386: je 0x1338b
0x13388: jmp 0x13485
0x1338b: jmp 0x13643
0x1338e: add dx, bx
2018-12-17T22:34:37.808001909Z 78 PC: 1378e | Find first file
2018-12-17T22:34:37.81384766Z 61 PC: 13751 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:34:37.82116802Z 63 PC: 13432 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:34:37.823671364Z 62 PC: 135ff | Close file
2018-12-17T22:34:37.825384172Z 79 PC: 136ea | Find next file
2018-12-17T22:34:37.828128245Z 26 PC: 1361f | Set disk transfer address
2018-12-17T22:34:37.82965547Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:37.830748136Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:34:37.831826492Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:34:37.833138961Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:34:37.834200986Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:34:37.835296653Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:34:37.836880244Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:34:37.838122423Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:34:37.839751968Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:34:37.841921766Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:34:37.843169517Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:34:37.844368982Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:34:37.846477652Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:34:37.848142466Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:34:37.849698343Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:34:37.852386288Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:34:37.853880181Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:34:37.855085684Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:34:37.85648229Z 53 PC: 12b2a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:34:37.857939088Z 37 PC: 12b3f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:37.859027753Z 37 PC: 12b47 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:34:37.860595628Z 37 PC: 12b4f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:34:37.862056937Z 37 PC: 12b57 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:34:37.863457214Z 68 PC: 131b5 | I/O control for devices (Set for = '')
2018-12-17T22:34:37.865028595Z 64 PC: 12f48 | Write file or device (Write 40 bytes on handle 1)
2018-12-17T22:34:37.870666332Z 64 PC: 12f48 | Write file or device (Write 31 bytes on handle 1)
2018-12-17T22:34:37.876472426Z 64 PC: 12f48 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:34:37.878092955Z 37 PC: 12c81 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:34:37.883258681Z 37 PC: 12c81 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:34:37.884563452Z 37 PC: 12c81 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:34:37.885983651Z 37 PC: 12c81 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:34:37.888228Z 37 PC: 12c81 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:34:37.889356253Z 37 PC: 12c81 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:34:37.890451465Z 37 PC: 12c81 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:34:37.892022104Z 37 PC: 12c81 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:34:37.893270768Z 37 PC: 12c81 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:34:37.894577624Z 37 PC: 12c81 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:34:37.90062485Z 37 PC: 12c81 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:34:37.901818551Z 37 PC: 12c81 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:34:37.902916134Z 37 PC: 12c81 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:34:37.904902709Z 37 PC: 12c81 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:34:37.906325606Z 37 PC: 12c81 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:34:37.907768809Z 37 PC: 12c81 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:34:37.909795179Z 37 PC: 12c81 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:34:37.910872905Z 37 PC: 12c81 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:34:37.911888839Z 37 PC: 12c81 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:34:37.913686884Z 76 PC: 12cc0 | Terminate with return code (Return code = '0')