Sample viewer

vx.netlux.org/Virus.DOS.Gyro.512

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:44:22.056498125Z 53 PC: 12a84 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:44:22.058350814Z 37 PC: 12a8d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:22.060120498Z 25 PC: 12a97 | Get default drive
2018-12-17T22:44:22.061620105Z 71 PC: 12aa6 | Get current directory
2018-12-17T22:44:22.064930562Z 48 PC: 12aaf | Get DOS version
2018-12-17T22:44:22.079071591Z 14 PC: 12b05 | Set default drive (Drive = 'A')
2018-12-17T22:44:22.080914182Z 59 PC: 12b0c | Change current directory
2018-12-17T22:44:22.085910496Z 78 PC: 12b60 | Find first file
2018-12-17T22:44:22.135116383Z 67 PC: 12b7c | Get or set file attributes
2018-12-17T22:44:22.14180796Z 67 PC: 12b85 | Get or set file attributes
2018-12-17T22:44:22.16462281Z 61 PC: 12b8a | Open file (Filename = '')
2018-12-17T22:44:22.177775743Z 63 PC: 12b96 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T22:44:22.19516329Z 62 PC: 12b9a | Close file
2018-12-17T22:44:22.19754344Z 61 PC: 12bac | Open file (Filename = '')
2018-12-17T22:44:22.206087096Z 87 PC: 12bb3 | Get or set file date and time
2018-12-17T22:44:22.2202891Z 44 PC: 12bb9 | Get time 0x12bb9: mov word ptr [0x11f], dx
0x12bbd: mov word ptr [0x121], 0x125
0x12bc3: jmp 0x12b6b
0x12bc5: mov ax, 0x5701
0x12bc8: pop dx
0x12bc9: pop cx
0x12bca: int 0x21
0x12bcc: mov ah, 0x3e
0x12bce: int 0x21
0x12bd0: mov ah, 0xe
0x12bd2: mov dl, byte ptr [0x2aa]
0x12bd6: int 0x21
0x12bd8: mov ah, 0x3b
0x12bda: mov dx, 0x2ab
0x12bdd: int 0x21
0x12bdf: mov ah, 9
0x12be1: mov dx, 0x2ce
0x12be4: int 0x21
0x12be6: int 0x20
0x12be8: pop sp
2018-12-17T22:44:22.223593045Z 64 PC: 12a76 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:44:22.232640267Z 87 PC: 12bcc | Get or set file date and time
2018-12-17T22:44:22.240467789Z 62 PC: 12bd0 | Close file
2018-12-17T22:44:22.259473524Z 14 PC: 12bd8 | Set default drive (Drive = 'A')
2018-12-17T22:44:22.261152548Z 59 PC: 12bdf | Change current directory
2018-12-17T22:44:22.266006013Z 9 PC: 12be6 | Display string (String= 'j�����Z������[��X����@`�R��h����v���Z��������.����@`�R���� ���Ɓ��@��j@�@�=���Z�UWVS�� �ʼn')