Sample viewer

vx.netlux.org/Virus.DOS.DataFire.1080

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:59:15.537812882Z 25 PC: 12da8 | Get default drive
2018-12-17T21:59:15.53982203Z 42 PC: 12c94 | Get date 0x12c94: cmp dl, 0xd
0x12c97: jne 0x12ca0
0x12c99: cmp al, 5
0x12c9b: jne 0x12ca0
0x12c9d: jmp 0x12cad
0x12ca0: cmp dh, 0xc
0x12ca3: jne 0x12cac
0x12ca5: cmp al, 0
0x12ca7: jne 0x12cac
0x12ca9: jmp 0x12cdd
0x12cac: ret
0x12cad: mov si, 0x6d
0x12cb0: add si, bp
0x12cb2: lodsb al, byte ptr [si]
0x12cb3: mov cx, 0xa
0x12cb6: push cx
0x12cb7: mov ah, 3
0x12cb9: mov bx, 0x100
0x12cbc: mov ch, 0
0x12cbe: mov cl, 1
2018-12-17T21:59:15.542374108Z 71 PC: 12db9 | Get current directory
2018-12-17T21:59:15.54562502Z 26 PC: 12bd8 | Set disk transfer address
2018-12-17T21:59:15.547495943Z 78 PC: 12bf4 | Find first file
2018-12-17T21:59:15.556296929Z 59 PC: 12c06 | Change current directory
2018-12-17T21:59:15.562341458Z 59 PC: 12c37 | Change current directory