Sample viewer

vx.netlux.org/Virus.DOS.Trickster

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:50.836175364Z 250 PC: 12e33 | UNKNOWN!
2018-12-17T22:46:50.83720823Z 48 PC: 12e3c | Get DOS version
2018-12-17T22:46:50.838268441Z 53 PC: 9eea7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:50.839247538Z 37 PC: 9eebb | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:50.840619677Z 53 PC: 9ed7a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:46:50.841631217Z 37 PC: 9ed8e | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:46:50.842569371Z 53 PC: 9ed93 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:46:50.844478026Z 37 PC: 9edd3 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:46:50.845517888Z 44 PC: 9eeca | Get time 0x9eeca: mov ah, 3
0x9eecc: mov dl, 0x80
0x9eece: mov dh, 1
0x9eed0: mov al, 6
0x9eed2: int 0x13
0x9eed4: call 0xaece5
0x9eed7: add byte ptr [bx + si], al
2018-12-17T22:46:51.183200127Z 76 PC: 12aa4 | Terminate with return code (Return code = '0')