Sample viewer

vx.netlux.org/Virus.DOS.Beer.1787

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:40:29.34071806Z 48 PC: 148be | Get DOS version
2018-12-17T22:40:29.34323615Z 37 PC: 14948 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:40:29.344802622Z 48 PC: 141c3 | Get DOS version
2018-12-17T22:40:29.346325462Z 48 PC: 12a63 | Get DOS version
2018-12-17T22:40:29.355792524Z 53 PC: 9ee76 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:40:29.358407556Z 37 PC: 9ee76 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:40:29.360265946Z 67 PC: 9ee76 | Get or set file attributes
2018-12-17T22:40:29.374448924Z 67 PC: 9ee76 | Get or set file attributes
2018-12-17T22:40:29.393344625Z 61 PC: 9ee76 | Open file (Filename = '4 Microsoft Corp Licensed Material - Property of Microsoft All rights reserved ')
2018-12-17T22:40:29.400281123Z 87 PC: 9ee76 | Get or set file date and time
2018-12-17T22:40:29.405304679Z 66 PC: 9ee76 | Move file pointer
2018-12-17T22:40:29.409547988Z 66 PC: 9ee76 | Move file pointer
2018-12-17T22:40:29.41232275Z 63 PC: 9ee76 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:40:29.416410007Z 66 PC: 9ee76 | Move file pointer
2018-12-17T22:40:29.419000262Z 63 PC: 9ee76 | Read file or device (Read 16 bytes on handle 5)
2018-12-17T22:40:29.42963689Z 66 PC: 9ee76 | Move file pointer
2018-12-17T22:40:29.434249524Z 64 PC: 9ee76 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:40:29.439654636Z 66 PC: 9ee76 | Move file pointer
2018-12-17T22:40:29.443309561Z 64 PC: 9ee76 | Write file or device (Write 1787 bytes on handle 5)
2018-12-17T22:40:29.453280078Z 87 PC: 9ee76 | Get or set file date and time
2018-12-17T22:40:29.455587562Z 62 PC: 9ee76 | Close file
2018-12-17T22:40:29.477248476Z 37 PC: 9ee76 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:40:29.479734876Z 61 PC: 12cb5 | Open file (Filename = '')
2018-12-17T22:40:29.488634742Z 9 PC: 12a87 | Display string (String= 'Self test: ')
2018-12-17T22:40:29.492353857Z 93 PC: 12b22 | File sharing functions
2018-12-17T22:40:29.498005683Z 76 PC: 12b07 | Terminate with return code (Return code = '1')