Sample viewer

vx.netlux.org/Virus.DOS.Singapore.521

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:39:56.088992376Z 48 PC: 14ac0 | Get DOS version
2018-12-17T22:39:56.090580819Z 53 PC: 14b31 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:39:56.092367797Z 37 PC: 14b3d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:39:56.093874041Z 26 PC: 14b4c | Set disk transfer address
2018-12-17T22:39:56.095313517Z 78 PC: 14b5b | Find first file
2018-12-17T22:39:56.102847721Z 67 PC: 14bb2 | Get or set file attributes
2018-12-17T22:39:56.110540149Z 67 PC: 14bbd | Get or set file attributes
2018-12-17T22:39:56.128350479Z 61 PC: 14bc4 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:39:56.136303348Z 87 PC: 14bd0 | Get or set file date and time
2018-12-17T22:39:56.138089768Z 63 PC: 14bdf | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:39:56.146323021Z 66 PC: 14bf1 | Move file pointer
2018-12-17T22:39:56.148528334Z 64 PC: 14c17 | Write file or device (Write 521 bytes on handle 5)
2018-12-17T22:39:56.157629432Z 66 PC: 14c29 | Move file pointer
2018-12-17T22:39:56.159162279Z 64 PC: 14c37 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:39:56.167329651Z 87 PC: 14c4a | Get or set file date and time
2018-12-17T22:39:56.169251956Z 62 PC: 14c4e | Close file
2018-12-17T22:39:56.260109165Z 67 PC: 14c86 | Get or set file attributes
2018-12-17T22:39:56.268127337Z 26 PC: 14c8d | Set disk transfer address
2018-12-17T22:39:56.269905059Z 37 PC: 14c94 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:39:56.271691074Z 9 PC: 12f77 | Display string (String= ' AUTOBOOT v2.00 (C)1989, 1990, 1991 Angelo Besani <[ Amn�siA ]> *Italy* (2:331/[email protected]) +39-331-772362 [HST/V.32] ')
2018-12-17T22:39:56.282791237Z 53 PC: 13811 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:39:56.285299973Z 53 PC: 13811 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:39:56.286607456Z 53 PC: 13811 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:39:56.287912035Z 53 PC: 13811 | Get interrupt vector (Interrupt = '20' AKA 'Sequential read')
2018-12-17T22:39:56.289968539Z 53 PC: 13811 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:39:56.291294509Z 53 PC: 13811 | Get interrupt vector (Interrupt = '37' AKA 'Set interrupt vector')
2018-12-17T22:39:56.292571809Z 53 PC: 13811 | Get interrupt vector (Interrupt = '38' AKA 'Create PSP')
2018-12-17T22:39:56.294962534Z 53 PC: 13217 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:39:56.296529023Z 37 PC: 13228 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:39:56.298030888Z 37 PC: 13230 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:39:56.302765493Z 53 PC: 1324f | Get interrupt vector (Interrupt = '20' AKA 'Sequential read')
2018-12-17T22:39:56.304327137Z 9 PC: 1326d | Display string (String= '�[�W�|')
2018-12-17T22:39:56.309833641Z 53 PC: 13281 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:39:56.312788839Z 53 PC: 1328e | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:39:56.314616651Z 53 PC: 1329b | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:39:56.316372078Z 53 PC: 132a8 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:39:56.319275573Z 53 PC: 132b5 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:39:56.321338234Z 53 PC: 132c2 | Get interrupt vector (Interrupt = '37' AKA 'Set interrupt vector')
2018-12-17T22:39:56.323116693Z 53 PC: 132cf | Get interrupt vector (Interrupt = '38' AKA 'Create PSP')
2018-12-17T22:39:56.324958181Z 37 PC: 132e4 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:39:56.327362933Z 37 PC: 132ec | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:39:56.328968999Z 37 PC: 132f4 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:39:56.33062119Z 37 PC: 132fc | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:39:56.332953948Z 37 PC: 13304 | Set interrupt vector (Interrupt = '20' AKA 'Sequential read')
2018-12-17T22:39:56.334265239Z 37 PC: 1330c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:39:56.33555778Z 37 PC: 13314 | Set interrupt vector (Interrupt = '37' AKA 'Set interrupt vector')
2018-12-17T22:39:56.337634272Z 37 PC: 1331c | Set interrupt vector (Interrupt = '38' AKA 'Create PSP')
2018-12-17T22:39:56.339348595Z 9 PC: 13323 | Display string (String= 'AUTOBOOT successfully loaded. ')
2018-12-17T22:39:56.347219899Z 37 PC: 131f4 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:39:56.349565194Z 49 PC: 13211 | Terminate and stay resident (Return code = '0' | Memory size = '99')