Sample viewer

vx.netlux.org/Virus.DOS.Duwende.432.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:13.358604955Z 255 PC: 130b6 | UNKNOWN!
2018-12-17T22:46:13.362001603Z 74 PC: 130d1 | Reallocate memory
2018-12-17T22:46:13.365318129Z 72 PC: 130d9 | Allocate memory
2018-12-17T22:46:13.367621308Z 53 PC: 9fa76 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:13.369134219Z 37 PC: 9fa85 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:13.373184004Z 61 PC: 12c4f | Open file (Filename = '')
2018-12-17T22:46:13.380648613Z 63 PC: 12c5d | Read file or device (Read 278 bytes on handle 5)
2018-12-17T22:46:13.38408051Z 62 PC: 12c63 | Close file
2018-12-17T22:46:13.387252142Z 9 PC: 12e3b | Display string (String= ' The program has been altered. Possible virus infection! ')
2018-12-17T22:46:13.395162315Z 9 PC: 12e3b | Display string (String= ' Checking memory ... ')
2018-12-17T22:46:13.400495302Z 37 PC: 12d0e | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:46:13.407513961Z 52 PC: 12e82 | Get InDOS flag pointer
2018-12-17T22:46:13.410030357Z 37 PC: 12d6c | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:46:13.411745923Z 9 PC: 12e3b | Display string (String= 'Memory may be infected by resident virus! ')
2018-12-17T22:46:13.418121697Z 76 PC: 12d97 | Terminate with return code (Return code = '1')