Sample viewer

vx.netlux.org/Virus.DOS.V.563.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:47:37.403974157Z 53 PC: 207a6 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:47:37.406532363Z 37 PC: 207af | Set interrupt vector (Interrupt = '99' AKA 'Get DBCS lead byte table pointer')
2018-12-17T22:47:37.408083146Z 53 PC: 207b4 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:37.409703871Z 37 PC: 207bd | Set interrupt vector (Interrupt = '100' AKA 'Set wait for external event flag')
2018-12-17T22:47:37.412392062Z 37 PC: 207c9 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:47:37.428174713Z 37 PC: 207d1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:37.430044165Z 54 PC: 207e7 | Get free disk space
2018-12-17T22:47:37.440986202Z 26 PC: 207f6 | Set disk transfer address
2018-12-17T22:47:37.443325757Z 78 PC: 20800 | Find first file
2018-12-17T22:47:37.45098178Z 61 PC: 2081e | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:47:37.4585187Z 63 PC: 2082f | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:47:37.466740206Z 66 PC: 2084c | Move file pointer
2018-12-17T22:47:37.468838318Z 63 PC: 2085c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:47:37.47201185Z 66 PC: 2088d | Move file pointer
2018-12-17T22:47:37.474741137Z 63 PC: 208a5 | Read file or device (Read 8 bytes on handle 5)
2018-12-17T22:47:37.494064981Z 66 PC: 208b7 | Move file pointer
2018-12-17T22:47:37.495668915Z 64 PC: 208dd | Write file or device (Write 5 bytes on handle 5)
2018-12-17T22:47:37.499701761Z 66 PC: 208ed | Move file pointer
2018-12-17T22:47:37.501436901Z 64 PC: 20901 | Write file or device (Write 563 bytes on handle 5)
2018-12-17T22:47:37.516816895Z 62 PC: 2090a | Close file
2018-12-17T22:47:37.526908064Z 26 PC: 20911 | Set disk transfer address
2018-12-17T22:47:37.528558985Z 53 PC: 20916 | Get interrupt vector (Interrupt = '99' AKA 'Get DBCS lead byte table pointer')
2018-12-17T22:47:37.530310336Z 37 PC: 2091f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:47:37.532954503Z 53 PC: 20924 | Get interrupt vector (Interrupt = '100' AKA 'Set wait for external event flag')
2018-12-17T22:47:37.534462246Z 37 PC: 2092d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:47:37.53597043Z 80 PC: 141b9 | Set current PSP
2018-12-17T22:47:37.538245273Z 48 PC: 141be | Get DOS version
2018-12-17T22:47:37.540020298Z 2 PC: 1406c | Character output (Char = '56')
2018-12-17T22:47:37.542824406Z 2 PC: 1406c | Character output (Char = '65')
2018-12-17T22:47:37.550609993Z 2 PC: 1406c | Character output (Char = '72')
2018-12-17T22:47:37.553548364Z 2 PC: 1406c | Character output (Char = '73')
2018-12-17T22:47:37.55617064Z 2 PC: 1406c | Character output (Char = '69')
2018-12-17T22:47:37.560136761Z 2 PC: 1406c | Character output (Char = 'a2')
2018-12-17T22:47:37.56297307Z 2 PC: 1406c | Character output (Char = '6e')
2018-12-17T22:47:37.566280353Z 2 PC: 1406c | Character output (Char = '20')
2018-12-17T22:47:37.568985345Z 2 PC: 1406c | Character output (Char = '69')
2018-12-17T22:47:37.572281798Z 2 PC: 1406c | Character output (Char = '6e')
2018-12-17T22:47:37.575042765Z 2 PC: 1406c | Character output (Char = '63')
2018-12-17T22:47:37.577831394Z 2 PC: 1406c | Character output (Char = '6f')
2018-12-17T22:47:37.581329897Z 2 PC: 1406c | Character output (Char = '72')
2018-12-17T22:47:37.584044937Z 2 PC: 1406c | Character output (Char = '72')
2018-12-17T22:47:37.586749919Z 2 PC: 1406c | Character output (Char = '65')
2018-12-17T22:47:37.589913944Z 2 PC: 1406c | Character output (Char = '63')
2018-12-17T22:47:37.592446692Z 2 PC: 1406c | Character output (Char = '74')
2018-12-17T22:47:37.595116117Z 2 PC: 1406c | Character output (Char = '61')
2018-12-17T22:47:37.598724496Z 2 PC: 1406c | Character output (Char = '20')
2018-12-17T22:47:37.60147315Z 2 PC: 1406c | Character output (Char = '64')
2018-12-17T22:47:37.604231352Z 2 PC: 1406c | Character output (Char = '65')
2018-12-17T22:47:37.607968102Z 2 PC: 1406c | Character output (Char = '20')
2018-12-17T22:47:37.610620786Z 2 PC: 1406c | Character output (Char = '44')
2018-12-17T22:47:37.613068033Z 2 PC: 1406c | Character output (Char = '4f')
2018-12-17T22:47:37.617369585Z 2 PC: 1406c | Character output (Char = '53')
2018-12-17T22:47:37.619720311Z 2 PC: 1406c | Character output (Char = '0d')
2018-12-17T22:47:37.621974546Z 2 PC: 1406c | Character output (Char = '0a')