Sample viewer

vx.netlux.org/Virus.DOS.FrodoSoft.656

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:58.089177957Z 48 PC: 1333f | Get DOS version
2018-12-17T22:43:58.091612791Z 74 PC: 13366 | Reallocate memory
2018-12-17T22:43:58.09467484Z 72 PC: 1336d | Allocate memory
2018-12-17T22:43:58.096850559Z 198 PC: 229b4 | UNKNOWN!
2018-12-17T22:43:58.098435347Z 47 PC: 229b8 | Get disk transfer address
2018-12-17T22:43:58.1154977Z 26 PC: 229c7 | Set disk transfer address
2018-12-17T22:43:58.117123453Z 54 PC: 229ce | Get free disk space
2018-12-17T22:43:58.127231481Z 78 PC: 229e5 | Find first file
2018-12-17T22:43:58.136030722Z 79 PC: 22a39 | Find next file
2018-12-17T22:43:58.139398883Z 79 PC: 22a39 | Find next file
2018-12-17T22:43:58.143634349Z 79 PC: 22a39 | Find next file
2018-12-17T22:43:58.151362216Z 79 PC: 22a39 | Find next file
2018-12-17T22:43:58.159873534Z 79 PC: 22a39 | Find next file
2018-12-17T22:43:58.163107895Z 79 PC: 22a39 | Find next file
2018-12-17T22:43:58.168346426Z 79 PC: 22a39 | Find next file
2018-12-17T22:43:58.171558441Z 61 PC: 229ff | Open file (Filename = '')
2018-12-17T22:43:58.179322172Z 63 PC: 22a0d | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:43:58.183783416Z 62 PC: 22a35 | Close file
2018-12-17T22:43:58.185786268Z 79 PC: 22a39 | Find next file
2018-12-17T22:43:58.187823337Z 78 PC: 22a56 | Find first file
2018-12-17T22:43:58.191979702Z 26 PC: 22b33 | Set disk transfer address
2018-12-17T22:43:58.194252996Z 73 PC: 22b3a | Release memory
2018-12-17T22:43:58.195396472Z 74 PC: 22b46 | Reallocate memory
2018-12-17T22:43:58.196693272Z 73 PC: 22b50 | Release memory
2018-12-17T22:43:58.199538745Z 53 PC: 12ca9 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:43:58.20069473Z 37 PC: 12cc0 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:43:58.201789095Z 53 PC: 12cc5 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:43:58.203404435Z 37 PC: 12cdc | Set interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:43:58.212945247Z 9 PC: 12cf6 | Display string (Could not find end pointer)
2018-12-17T22:43:58.215918824Z 49 PC: 12d22 | Terminate and stay resident (Return code = '0' | Memory size = '48')