Sample viewer

vx.netlux.org/Virus.DOS.Drepo.2461

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:47.324817777Z 98 PC: 14fca | Get current PSP
2018-12-17T22:52:47.32660635Z 62 PC: 14fd6 | Close file
2018-12-17T22:52:47.327924432Z 72 PC: 15030 | Allocate memory
2018-12-17T22:52:47.329393467Z 74 PC: 15040 | Reallocate memory
2018-12-17T22:52:47.331571157Z 72 PC: 15030 | Allocate memory
2018-12-17T22:52:47.333071148Z 50 PC: 15052 | Get disk parameter block for specified drive
2018-12-17T22:52:48.143571326Z 42 PC: 150dc | Get date 0x150dc: mov byte ptr [0x8ce], dh
0x150e0: mov word ptr [0x8cf], cx
0x150e4: mov ax, 0x3d22
0x150e7: mov dx, 0x84d
0x150ea: int 0x21
0x150ec: mov bx, ax
0x150ee: call 0x152a3
0x150f1: mov byte ptr [0x858], 0x43
0x150f6: nop
0x150f7: mov byte ptr [0x857], 0x20
0x150fc: nop
0x150fd: mov ax, word ptr [0x889]
0x15100: add ax, 3
0x15103: mov word ptr [0x8b8], ax
0x15106: call 0x1570d
0x15109: call 0x152a3
0x1510c: mov ax, 0x4202
0x1510f: mov cx, 0xffff
0x15112: mov dx, 0xf663
0x15115: int 0x21
2018-12-17T22:52:48.146548135Z 61 PC: 150ec | Open file (Filename = 'C:\COMMAND.LOM')
2018-12-17T22:52:48.155722418Z 63 PC: 152ad | Read file or device (Read 46 bytes on handle 5)
2018-12-17T22:52:48.15871548Z 66 PC: 15718 | Move file pointer
2018-12-17T22:52:48.160468733Z 63 PC: 152ad | Read file or device (Read 46 bytes on handle 5)
2018-12-17T22:52:48.167067171Z 66 PC: 15117 | Move file pointer
2018-12-17T22:52:48.168869383Z 63 PC: 15121 | Read file or device (Read 10 bytes on handle 5)
2018-12-17T22:52:48.175721957Z 66 PC: 15138 | Move file pointer
2018-12-17T22:52:48.177693896Z 66 PC: 1515d | Move file pointer
2018-12-17T22:52:48.183610229Z 64 PC: 158cd | Write file or device (Write 2469 bytes on handle 5)
2018-12-17T22:52:48.19482533Z 66 PC: 15718 | Move file pointer
2018-12-17T22:52:48.197111825Z 64 PC: 15720 | Write file or device (Write 46 bytes on handle 5)
2018-12-17T22:52:48.200233937Z 62 PC: 15170 | Close file
2018-12-17T22:52:48.208445904Z 73 PC: 15189 | Release memory
2018-12-17T22:52:48.210444931Z 74 PC: 15197 | Reallocate memory
2018-12-17T22:52:48.211859676Z 48 PC: 12bc6 | Get DOS version
2018-12-17T22:52:48.213025332Z 74 PC: 12c20 | Reallocate memory
2018-12-17T22:52:48.215135767Z 48 PC: 12c78 | Get DOS version
2018-12-17T22:52:48.216511836Z 53 PC: 12c80 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:48.217952902Z 37 PC: 12c92 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:52:48.22028522Z 68 PC: 12d16 | I/O control for devices (Set for = '')
2018-12-17T22:52:48.22159233Z 68 PC: 12d16 | I/O control for devices
2018-12-17T22:52:48.222890226Z 68 PC: 12d16 | I/O control for devices
2018-12-17T22:52:48.225394305Z 68 PC: 12d16 | I/O control for devices
2018-12-17T22:52:48.226945865Z 68 PC: 12d16 | I/O control for devices
2018-12-17T22:52:48.230265079Z 64 PC: 145b8 | Write file or device (Write 53 bytes on handle 1)
2018-12-17T22:52:48.237203245Z 64 PC: 145b8 | Write file or device (Write 56 bytes on handle 1)
2018-12-17T22:52:48.24547673Z 64 PC: 145b8 | Write file or device (Write 12 bytes on handle 1)
2018-12-17T22:52:48.252728135Z 64 PC: 145b8 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:52:48.259362049Z 64 PC: 145b8 | Write file or device (Write 66 bytes on handle 1)
2018-12-17T22:52:48.26619864Z 63 PC: 14451 | Read file or device (Read 512 bytes on handle 0)