Sample viewer

vx.netlux.org/Virus.DOS.Dikshev.Yj.404

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:41:58.101873294Z 98 PC: 12a44 | Get current PSP
2018-12-17T22:41:58.10343592Z 60 PC: 12a82 | Create or truncate file
2018-12-17T22:41:58.957127918Z 64 PC: 12a8d | Write file or device (Write 62 bytes on handle 5)
2018-12-17T22:41:58.961243833Z 62 PC: 12a91 | Close file
2018-12-17T22:41:59.020393908Z 60 PC: 12a9a | Create or truncate file
2018-12-17T22:41:59.084582527Z 64 PC: 12aa6 | Write file or device (Write 404 bytes on handle 5)
2018-12-17T22:41:59.088267952Z 62 PC: 12aaa | Close file
2018-12-17T22:41:59.182806158Z 78 PC: 12ab4 | Find first file
2018-12-17T22:41:59.189258787Z 74 PC: 12af8 | Reallocate memory
2018-12-17T22:41:59.190720202Z 75 PC: 12b1e | Execute program
2018-12-17T22:41:59.212430081Z 80 PC: 18029 | Set current PSP
2018-12-17T22:41:59.214864666Z 48 PC: 1802e | Get DOS version
2018-12-17T22:41:59.216491831Z 99 PC: 1e810 | Get DBCS lead byte table pointer
2018-12-17T22:41:59.219231581Z 101 PC: 180b4 | Get extended country info
2018-12-17T22:41:59.221680711Z 99 PC: 180ba | Get DBCS lead byte table pointer
2018-12-17T22:41:59.223047046Z 74 PC: 1811c | Reallocate memory
2018-12-17T22:41:59.224579713Z 25 PC: 18153 | Get default drive
2018-12-17T22:41:59.226578355Z 37 PC: 17c13 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:41:59.227599832Z 37 PC: 17c1a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:41:59.228449479Z 37 PC: 17c21 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:59.233207164Z 74 PC: 16dbc | Reallocate memory
2018-12-17T22:41:59.235572987Z 72 PC: 16dfd | Allocate memory
2018-12-17T22:41:59.237408576Z 72 PC: 16e35 | Allocate memory
2018-12-17T22:41:59.239350649Z 72 PC: 16e3d | Allocate memory