Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Saboteur.41961

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:39:23.777844712Z 48 PC: 12f37 | Get DOS version
2018-12-17T22:39:23.781128756Z 74 PC: 12cf6 | Reallocate memory
2018-12-17T22:39:23.783138681Z 74 PC: 12cfa | Reallocate memory
2018-12-17T22:39:23.857072314Z 25 PC: 160b6 | Get default drive
2018-12-17T22:39:23.858924602Z 71 PC: 198e3 | Get current directory
2018-12-17T22:39:23.863994339Z 26 PC: 155e0 | Set disk transfer address
2018-12-17T22:39:23.865794379Z 78 PC: 198e3 | Find first file
2018-12-17T22:39:23.871949158Z 89 PC: 144e5 | Get extended error info
2018-12-17T22:39:23.874964597Z 74 PC: 162ea | Reallocate memory
2018-12-17T22:39:23.877893131Z 75 PC: 163fa | Execute program
2018-12-17T22:39:23.89987254Z 80 PC: 2aba9 | Set current PSP
2018-12-17T22:39:23.900774048Z 48 PC: 2abae | Get DOS version
2018-12-17T22:39:23.902818267Z 99 PC: 31390 | Get DBCS lead byte table pointer
2018-12-17T22:39:23.905919497Z 101 PC: 2ac34 | Get extended country info
2018-12-17T22:39:23.907457032Z 99 PC: 2ac3a | Get DBCS lead byte table pointer
2018-12-17T22:39:23.909235401Z 74 PC: 2ac9c | Reallocate memory
2018-12-17T22:39:23.911165566Z 25 PC: 2acd3 | Get default drive
2018-12-17T22:39:23.912570341Z 37 PC: 2a793 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:39:23.914389637Z 37 PC: 2a79a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:39:23.915721264Z 37 PC: 2a7a1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:39:23.920165434Z 74 PC: 2993c | Reallocate memory
2018-12-17T22:39:23.921880844Z 72 PC: 2997d | Allocate memory
2018-12-17T22:39:23.923694179Z 72 PC: 299b5 | Allocate memory
2018-12-17T22:39:23.925481244Z 72 PC: 299bd | Allocate memory