Sample viewer

vx.netlux.org/Virus.DOS.Yankee.3096

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:39:08.22623239Z 198 PC: 13841 | UNKNOWN!
2018-12-17T22:39:08.228016274Z 53 PC: 138c6 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:39:08.230167966Z 53 PC: 138db | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:39:08.241457732Z 37 PC: 138ec | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:39:08.243646274Z 37 PC: 1384c | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:39:08.253128368Z 53 PC: 12aea | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:39:08.255458174Z 53 PC: 12aea | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:39:08.257225405Z 53 PC: 12aea | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:39:08.259856916Z 53 PC: 12aea | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:39:08.261704542Z 53 PC: 12aea | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:39:08.263469429Z 53 PC: 12aea | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:39:08.266322532Z 53 PC: 12aea | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:39:08.268118944Z 53 PC: 12aea | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:39:08.269873199Z 53 PC: 12aea | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:39:08.272662376Z 53 PC: 12aea | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:39:08.275766087Z 53 PC: 12aea | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:39:08.277534648Z 53 PC: 12aea | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:39:08.279562652Z 53 PC: 12aea | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:39:08.282178072Z 53 PC: 12aea | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:39:08.283941068Z 53 PC: 12aea | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:39:08.285712438Z 53 PC: 12aea | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:39:08.288494205Z 53 PC: 12aea | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:39:08.290248444Z 53 PC: 12aea | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:39:08.292015506Z 53 PC: 12aea | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:39:08.294808945Z 37 PC: 12aff | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:39:08.296556032Z 37 PC: 12b07 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:39:08.298246131Z 37 PC: 12b0f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:39:08.301038654Z 37 PC: 12b17 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:39:08.303648462Z 68 PC: 13175 | I/O control for devices (Set for = '�n$P3�&���t&�&�>�t��&�')
2018-12-17T22:39:08.30606671Z 64 PC: 12f08 | Write file or device (Write 15 bytes on handle 1)
2018-12-17T22:39:08.31314062Z 64 PC: 12f08 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:39:08.31569061Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:39:08.317424426Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:39:08.319173564Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:39:08.321932568Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:39:08.32365753Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:39:08.325374136Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:39:08.328951825Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:39:08.330693098Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:39:08.332412346Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:39:08.335081193Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:39:08.33717643Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:39:08.338898358Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:39:08.341339986Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:39:08.343432853Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:39:08.345154149Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:39:08.346876982Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:39:08.349666249Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:39:08.351957722Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:39:08.353663721Z 37 PC: 12c41 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:39:08.356145094Z 76 PC: 12c80 | Terminate with return code (Return code = '0')