Sample viewer

vx.netlux.org/Virus.DOS.Slam.Daemon.328

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:13.859166329Z 53 PC: 12aa4 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:13.865711174Z 37 PC: 12ab4 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:13.86809895Z 71 PC: 12abd | Get current directory
2018-12-17T22:51:13.87150046Z 53 PC: 12ac4 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:13.873041064Z 37 PC: 12acd | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:51:13.875239464Z 78 PC: 12afe | Find first file
2018-12-17T22:51:13.884050957Z 67 PC: 12b07 | Get or set file attributes
2018-12-17T22:51:13.891850219Z 67 PC: 12b11 | Get or set file attributes
2018-12-17T22:51:13.910810338Z 61 PC: 12b15 | Open file (Filename = '')
2018-12-17T22:51:13.919011624Z 87 PC: 12b1a | Get or set file date and time
2018-12-17T22:51:13.920847253Z 63 PC: 12b25 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:51:13.928428004Z 66 PC: 12b34 | Move file pointer
2018-12-17T22:51:13.930194432Z 44 PC: 12a4e | Get time 0x12a4e: cmp dl, 0
0x12a51: je 0x12a4a
0x12a53: mov byte ptr [0x108], dl
0x12a57: call 0x12a6c
0x12a5a: pop bx
0x12a5b: mov cx, 0x149
0x12a5e: mov dx, 0x100
0x12a61: mov ah, 0x40
0x12a63: int3
0x12a64: inc byte ptr [0x249]
0x12a68: call 0x12a6c
0x12a6b: ret
0x12a6c: mov bx, 0x144
0x12a6f: mov al, byte ptr [0x108]
0x12a73: cmp al, 0
0x12a75: je 0x12a83
0x12a77: xor byte ptr [bx], al
0x12a7a: inc bx
0x12a7b: add al, bh
0x12a7d: cmp bx, 0x22a
2018-12-17T22:51:13.932637181Z 64 PC: 12a64 | Write file or device (Write 329 bytes on handle 5)
2018-12-17T22:51:13.937826691Z 87 PC: 12b3f | Get or set file date and time
2018-12-17T22:51:13.939112606Z 62 PC: 12b42 | Close file
2018-12-17T22:51:13.94489568Z 67 PC: 12b4d | Get or set file attributes
2018-12-17T22:51:13.952737051Z 79 PC: 12afe | Find next file
2018-12-17T22:51:13.955194217Z 67 PC: 12b07 | Get or set file attributes
2018-12-17T22:51:13.959650869Z 67 PC: 12b11 | Get or set file attributes
2018-12-17T22:51:13.971247786Z 61 PC: 12b15 | Open file (Filename = '')
2018-12-17T22:51:13.982220969Z 87 PC: 12b1a | Get or set file date and time
2018-12-17T22:51:13.983752487Z 63 PC: 12b25 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:51:13.990627993Z 66 PC: 12b34 | Move file pointer
2018-12-17T22:51:13.996406668Z 44 PC: 12a4e | Get time 0x12a4e: cmp dl, 0
0x12a51: je 0x12a4a
0x12a53: mov byte ptr [0x108], dl
0x12a57: call 0x12a6c
0x12a5a: pop bx
0x12a5b: mov cx, 0x149
0x12a5e: mov dx, 0x100
0x12a61: mov ah, 0x40
0x12a63: int3
0x12a64: inc byte ptr [0x249]
0x12a68: call 0x12a6c
0x12a6b: ret
0x12a6c: mov bx, 0x144
0x12a6f: mov al, byte ptr [0x108]
0x12a73: cmp al, 0
0x12a75: je 0x12a83
0x12a77: xor byte ptr [bx], al
0x12a7a: inc bx
0x12a7b: add al, bh
0x12a7d: cmp bx, 0x22a
2018-12-17T22:51:13.99837184Z 64 PC: 12a64 | Write file or device (Write 329 bytes on handle 5)
2018-12-17T22:51:14.001247042Z 87 PC: 12b3f | Get or set file date and time
2018-12-17T22:51:14.003194771Z 62 PC: 12b42 | Close file
2018-12-17T22:51:14.009030925Z 67 PC: 12b4d | Get or set file attributes
2018-12-17T22:51:14.017155798Z 79 PC: 12afe | Find next file
2018-12-17T22:51:14.020294705Z 67 PC: 12b07 | Get or set file attributes
2018-12-17T22:51:14.024866914Z 67 PC: 12b11 | Get or set file attributes
2018-12-17T22:51:14.032484926Z 61 PC: 12b15 | Open file (Filename = '')
2018-12-17T22:51:14.042277622Z 87 PC: 12b1a | Get or set file date and time
2018-12-17T22:51:14.043704262Z 63 PC: 12b25 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:51:14.048851462Z 66 PC: 12b34 | Move file pointer
2018-12-17T22:51:14.051393287Z 44 PC: 12a4e | Get time 0x12a4e: cmp dl, 0
0x12a51: je 0x12a4a
0x12a53: mov byte ptr [0x108], dl
0x12a57: call 0x12a6c
0x12a5a: pop bx
0x12a5b: mov cx, 0x149
0x12a5e: mov dx, 0x100
0x12a61: mov ah, 0x40
0x12a63: int3
0x12a64: inc byte ptr [0x249]
0x12a68: call 0x12a6c
0x12a6b: ret
0x12a6c: mov bx, 0x144
0x12a6f: mov al, byte ptr [0x108]
0x12a73: cmp al, 0
0x12a75: je 0x12a83
0x12a77: xor byte ptr [bx], al
0x12a7a: inc bx
0x12a7b: add al, bh
0x12a7d: cmp bx, 0x22a
2018-12-17T22:51:14.053911197Z 64 PC: 12a64 | Write file or device (Write 329 bytes on handle 5)
2018-12-17T22:51:14.05612746Z 87 PC: 12b3f | Get or set file date and time
2018-12-17T22:51:14.057758965Z 62 PC: 12b42 | Close file
2018-12-17T22:51:14.06397336Z 67 PC: 12b4d | Get or set file attributes
2018-12-17T22:51:14.072545172Z 59 PC: 12aea | Change current directory
2018-12-17T22:51:14.07435356Z 37 PC: 12af6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')