Sample viewer

vx.netlux.org/Virus.DOS.GW.1201

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:42:04.308250694Z 72 PC: 183cc | Allocate memory
2018-12-17T22:42:04.321686221Z 74 PC: 18344 | Reallocate memory
2018-12-17T22:42:04.327612461Z 72 PC: 183cc | Allocate memory
2018-12-17T22:42:04.329716354Z 48 PC: 15d44 | Get DOS version
2018-12-17T22:42:04.3325578Z 9 PC: 15d58 | Display string (Could not find end pointer)
2018-12-17T22:42:04.351072205Z 53 PC: 15dfe | Get interrupt vector (Interrupt = '51' AKA 'Get or set Ctrl-Break')
2018-12-17T22:42:04.352186476Z 53 PC: 15e0b | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:42:04.353530157Z 53 PC: 15e20 | Get interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:42:04.35589165Z 53 PC: 15e32 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:42:04.357079351Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-17T22:42:04.359022873Z 53 PC: 15e54 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:42:04.3627353Z 37 PC: 1c61e | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:42:04.363925006Z 37 PC: 1c62c | Set interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:42:04.365046067Z 37 PC: 1c63a | Set interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:42:04.367501228Z 37 PC: 12f55 | Set interrupt vector (Interrupt = '68' AKA 'I/O control for devices')
2018-12-17T22:42:04.369017022Z 37 PC: 12f7a | Set interrupt vector (Interrupt = '31' AKA 'Get disk parameter block for default drive')
2018-12-17T22:42:04.3716333Z 73 PC: 1559a | Release memory
2018-12-17T22:42:04.374311295Z 49 PC: 1559d | Terminate and stay resident (Return code = '0' | Memory size = '709')
2018-12-17T22:42:04.376215377Z 72 PC: 9f819 | Allocate memory
2018-12-17T22:42:04.377653666Z 82 PC: 9f831 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:42:04.379371067Z 37 PC: 156ed | Set interrupt vector (Interrupt = '221' AKA 'UNKNOWN!')
2018-12-17T22:42:04.380480542Z 37 PC: 15a0b | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:42:04.381570666Z 53 PC: 15a11 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')