Sample viewer

vx.netlux.org/Virus.DOS.VCL.Wharps.572

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:38.068952216Z 71 PC: 12eb0 | Get current directory
2018-12-17T22:53:38.072574594Z 44 PC: 12eb4 | Get time 0x12eb4: mov byte ptr ds:[bp + 0x11d], dl
0x12eb9: cmp ch, 3
0x12ebc: je 0x12ec0
0x12ebe: jmp 0x12ed3
0x12ec0: cmp cl, 0
0x12ec3: je 0x12ec7
0x12ec5: jmp 0x12ed3
0x12ec7: mov ah, 9
0x12ec9: lea dx, word ptr [bp + 0x15c]
0x12ecd: int 0x21
0x12ecf: mov ah, 0x4c
0x12ed1: int 0x21
0x12ed3: push es
0x12ed4: mov ax, 0x3524
0x12ed7: int 0x21
0x12ed9: mov word ptr cs:[0xff1a], bx
0x12ede: mov word ptr cs:[0xff1c], es
0x12ee3: pop es
0x12ee4: mov ax, 0x2524
0x12ee7: lea dx, word ptr [bp + 0x132]
2018-12-17T22:53:38.075493427Z 53 PC: 12ed9 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:38.077682149Z 37 PC: 12eed | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:38.079710843Z 26 PC: 12f15 | Set disk transfer address
2018-12-17T22:53:38.081467209Z 59 PC: 12efc | Change current directory
2018-12-17T22:53:38.087901609Z 78 PC: 12f36 | Find first file
2018-12-17T22:53:38.094074527Z 26 PC: 13040 | Set disk transfer address
2018-12-17T22:53:38.096091189Z 37 PC: 1304e | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:38.097504756Z 59 PC: 13056 | Change current directory
2018-12-17T22:53:38.102020665Z 59 PC: 1305d | Change current directory