Sample viewer

vx.netlux.org/Virus.DOS.Ki.962

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:48:12.436490658Z 253 PC: 12a49 | UNKNOWN!
2018-12-17T22:48:12.437955717Z 53 PC: 12a69 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:48:12.439064328Z 53 PC: 12a75 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:48:12.440171703Z 37 PC: 12a9e | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:48:12.441765529Z 37 PC: 12aa5 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:48:12.443068747Z 9 PC: 13dc6 | Display string (String= 'CDEFG-This is a 5000 byte COM test, 1994 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":9472,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:23:13.786599075Z 253 PC: 12a49 | UNKNOWN!
2018-12-25T12:23:13.787978395Z 53 PC: 12a69 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:23:13.789412511Z 53 PC: 12a75 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:23:13.790635163Z 37 PC: 12a9e | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:23:13.794654808Z 37 PC: 12aa5 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:23:13.796058904Z 9 PC: 13dc6 | Display string (String= 'CDEFG-This is a 5000 byte COM test, 1994 ')

{"DateBased":true,"Day":7,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":9472,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:23:13.806938396Z 253 PC: 12a49 | UNKNOWN!
2018-12-25T12:23:13.808441628Z 53 PC: 12a69 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:23:13.810149052Z 53 PC: 12a75 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:23:13.812283075Z 37 PC: 12a9e | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:23:13.817290076Z 37 PC: 12aa5 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:23:13.820445501Z 9 PC: 13dc6 | Display string (String= 'CDEFG-This is a 5000 byte COM test, 1994 ')