Sample viewer

vx.netlux.org/Virus.DOS.Csl.381

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:49.451033398Z 37 PC: 12b00 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:49.454417485Z 48 PC: 12b0c | Get DOS version
2018-12-17T22:51:49.455783021Z 42 PC: 12b4a | Get date 0x12b4a: mov word ptr [0x47c], cx
0x12b4e: mov byte ptr [0x480], dh
0x12b52: mov byte ptr [0x482], dl
0x12b56: mov byte ptr [0x484], al
0x12b59: mov ax, word ptr [0x47a]
0x12b5c: mov ds, ax
0x12b5e: mov ax, word ptr [0x2c]
0x12b61: mov ds, ax
0x12b63: xor si, si
0x12b65: cld
0x12b66: lodsb al, byte ptr [si]
0x12b67: cmp al, 0
0x12b69: jne 0x12b66
0x12b6b: lodsb al, byte ptr [si]
0x12b6c: cmp al, 0
0x12b6e: jne 0x12b66
0x12b70: cmp byte ptr [si], 0x20
0x12b73: jg 0x12b78
0x12b75: inc si
0x12b76: jmp 0x12b70
2018-12-17T22:51:49.458262709Z 61 PC: 2b5c5 | Open file (Filename = 'kS_vir 3.19 ')
2018-12-17T22:51:49.466306319Z 87 PC: 2b5c5 | Get or set file date and time
2018-12-17T22:51:49.46788789Z 63 PC: 2b5c5 | Read file or device (Read 65535 bytes on handle 5)
2018-12-17T22:51:49.478536524Z 62 PC: 12bd7 | Close file
2018-12-17T22:51:49.495301227Z 12 PC: 12d46 | Flush input buffer and input