Sample viewer

vx.netlux.org/Virus.DOS.Elf.2731

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:11.043055282Z 53 PC: 18c5d | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:45:11.045233765Z 53 PC: 18ca1 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:45:11.046750153Z 53 PC: 18cbd | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:11.048980324Z 202 PC: 18d99 | UNKNOWN!
2018-12-17T22:45:11.050331029Z 51 PC: 18da0 | Get or set Ctrl-Break
2018-12-17T22:45:11.051098214Z 53 PC: 1948a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:45:11.052126291Z 37 PC: 19497 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:45:11.054332046Z 48 PC: 194b4 | Get DOS version
2018-12-17T22:45:11.055737678Z 37 PC: 194bb | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:45:11.056987207Z 81 PC: 1636c | Get current PSP
2018-12-17T22:45:11.058654433Z 61 PC: 163c5 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:45:11.065673203Z 66 PC: 16430 | Move file pointer
2018-12-17T22:45:11.066961618Z 63 PC: 16448 | Read file or device (Read 7 bytes on handle 5)
2018-12-17T22:45:11.070306114Z 66 PC: 164d3 | Move file pointer
2018-12-17T22:45:11.071483217Z 63 PC: 164de | Read file or device (Read 16 bytes on handle 5)
2018-12-17T22:45:11.078867107Z 63 PC: 16542 | Read file or device (Read 5123 bytes on handle 5)
2018-12-17T22:45:11.086301143Z 62 PC: 163db | Close file
2018-12-17T22:45:11.088158529Z 48 PC: 165fb | Get DOS version
2018-12-17T22:45:11.089493872Z 74 PC: 139bc | Reallocate memory
2018-12-17T22:45:11.091792005Z 53 PC: 13e45 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:11.092935616Z 37 PC: 13e55 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:11.093916358Z 82 PC: 13e5a | Get DOS internal pointers (SYSVARS)
2018-12-17T22:45:11.09517273Z 68 PC: 13e9c | I/O control for devices (Set for = '���$5�!�������$%�!�')
2018-12-17T22:45:11.097150302Z 68 PC: 13eb5 | I/O control for devices (Set for = 'u�6�>7��v@��')
2018-12-17T22:45:11.099013466Z 115 PC: 13ece | UNKNOWN!
2018-12-17T22:45:11.099822901Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.101806515Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.103251102Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.104687011Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.107870009Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.109656258Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.111308559Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.113552273Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.11492445Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.116293684Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.117862276Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.119264795Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.120611047Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.12255398Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.124397865Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.126206031Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.128249929Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.129739467Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.131467231Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.133005448Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.134341547Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.135650711Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.137255462Z 68 PC: 13e9c | I/O control for devices (Set for = '')
2018-12-17T22:45:11.139113148Z 37 PC: 14085 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:11.14082514Z 67 PC: 12c94 | Get or set file attributes
2018-12-17T22:45:11.147448874Z 48 PC: 1458a | Get DOS version
2018-12-17T22:45:11.149074834Z 9 PC: 13da7 | Display string (String= '������ ����� Windows �� ����᪠���� � MS-DOS 7.00 ��� ����� ࠭���. ')
2018-12-17T22:45:11.154799204Z 76 PC: 13d9b | Terminate with return code (Return code = '255')