Sample viewer

vx.netlux.org/Virus.DOS.Platov.1644

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:35:10.342246753Z 82 PC: 12b86 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:35:10.352458236Z 53 PC: 12bae | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:35:10.353953223Z 37 PC: 12bbe | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:35:10.355435266Z 53 PC: 12bc3 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:35:10.357186143Z 37 PC: 12bd3 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:35:10.359796783Z 53 PC: 12bd8 | Get interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-17T22:35:10.362440411Z 37 PC: 12be8 | Set interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-17T22:35:10.364865238Z 53 PC: 12bed | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:35:10.367111154Z 37 PC: 12bfd | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:35:10.370567637Z 9 PC: 12a47 | Display string (String= 'Platov-1628 ')
2018-12-17T22:35:10.374058329Z 76 PC: 12a4c | Terminate with return code (Return code = '0')