Sample viewer

vx.netlux.org/Virus.DOS.Plovdiv.800

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:44:57.867513668Z 53 PC: 12b8c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:44:57.87020875Z 37 PC: 12b95 | Set interrupt vector (Interrupt = '50' AKA 'Get disk parameter block for specified drive')
2018-12-17T22:44:57.871349077Z 37 PC: 12ba1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:44:57.872720644Z 25 PC: 6cd | Get default drive
2018-12-17T22:44:57.875857669Z 53 PC: 994e1 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:57.877356694Z 37 PC: 994f0 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:57.878648213Z 47 PC: 994f6 | Get disk transfer address
2018-12-17T22:44:57.880152401Z 26 PC: 99505 | Set disk transfer address
2018-12-17T22:44:57.88232775Z 78 PC: 9950e | Find first file
2018-12-17T22:44:57.888350111Z 79 PC: 99514 | Find next file
2018-12-17T22:44:57.891006005Z 79 PC: 99514 | Find next file
2018-12-17T22:44:57.894524081Z 79 PC: 99514 | Find next file
2018-12-17T22:44:57.897603885Z 79 PC: 99514 | Find next file
2018-12-17T22:44:57.901122029Z 79 PC: 99514 | Find next file
2018-12-17T22:44:57.904600871Z 79 PC: 99514 | Find next file
2018-12-17T22:44:57.907134003Z 79 PC: 99514 | Find next file
2018-12-17T22:44:57.90990888Z 61 PC: 99555 | Open file (Filename = '')
2018-12-17T22:44:57.918752717Z 63 PC: 99563 | Read file or device (Read 800 bytes on handle 5)
2018-12-17T22:44:57.925728879Z 66 PC: 9956e | Move file pointer
2018-12-17T22:44:57.927323354Z 48 PC: 657 | Get DOS version
2018-12-17T22:44:57.928739355Z 64 PC: 9957e | Write file or device (Write 800 bytes on handle 5)
2018-12-17T22:44:57.942360391Z 66 PC: 99587 | Move file pointer
2018-12-17T22:44:57.943698918Z 64 PC: 99591 | Write file or device (Write 800 bytes on handle 5)
2018-12-17T22:44:57.950949989Z 87 PC: 995a4 | Get or set file date and time
2018-12-17T22:44:57.952522503Z 62 PC: 995a8 | Close file
2018-12-17T22:44:57.960206944Z 48 PC: 657 | Get DOS version
2018-12-17T22:44:57.961286661Z 37 PC: 994c7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:44:57.962828822Z 26 PC: 994d5 | Set disk transfer address
2018-12-17T22:44:57.964048976Z 14 PC: 6dd | Set default drive (Drive = 'A')
2018-12-17T22:44:57.96542691Z 78 PC: 657 | Find first file