Sample viewer

vx.netlux.org/Virus.DOS.TheDraw.2267

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:17.015987895Z 42 PC: 12c71 | Get date 0x12c71: xchg ax, cx
0x12c72: ret
0x12c73: mov al, byte ptr [0x2bc]
0x12c76: cwde
0x12c77: ret
0x12c78: or dl, byte ptr [bx + si]
0x12c7a: sbb al, byte ptr [di]
0x12c7c: fstp xword ptr [bp + di + 0x2020]
0x12c80: sbb al, byte ptr [di]
0x12c82: fstp xword ptr [bp + di + 0x2020]
0x12c86: sbb al, byte ptr [0xbbdb]
0x12c8a: sbb bl, bl
0x12c8c: fcmovne st(0), st(1)
0x12c8e: int 0xcd
0x12c90: fcmovnu st(0), st(3)
0x12c92: mov bx, 0xdb20
0x12c95: fcmovne st(0), st(1)
0x12c97: int 0xcd
0x12c99: fcmovnu st(0), st(3)
0x12c9b: mov bx, 0xdb20
2018-12-17T22:54:17.025659839Z 71 PC: 12ac5 | Get current directory
2018-12-17T22:54:17.028431369Z 59 PC: 12acc | Change current directory
2018-12-17T22:54:17.03242835Z 47 PC: 12ae1 | Get disk transfer address
2018-12-17T22:54:17.03382265Z 26 PC: 12aef | Set disk transfer address
2018-12-17T22:54:17.035106468Z 78 PC: 12af9 | Find first file
2018-12-17T22:54:17.045946635Z 79 PC: 12b20 | Find next file
2018-12-17T22:54:17.048983825Z 79 PC: 12b20 | Find next file
2018-12-17T22:54:17.053066922Z 79 PC: 12b20 | Find next file
2018-12-17T22:54:17.055814707Z 79 PC: 12b20 | Find next file
2018-12-17T22:54:17.058580748Z 79 PC: 12b20 | Find next file
2018-12-17T22:54:17.06233489Z 79 PC: 12b20 | Find next file
2018-12-17T22:54:17.06578823Z 79 PC: 12b20 | Find next file
2018-12-17T22:54:17.068501802Z 79 PC: 12b20 | Find next file
2018-12-17T22:54:17.071848213Z 79 PC: 12b20 | Find next file
2018-12-17T22:54:17.074153402Z 47 PC: 12b44 | Get disk transfer address
2018-12-17T22:54:17.075261858Z 26 PC: 12b55 | Set disk transfer address
2018-12-17T22:54:17.076941936Z 78 PC: 12b5d | Find first file
2018-12-17T22:54:17.082559712Z 47 PC: 12b75 | Get disk transfer address
2018-12-17T22:54:17.084017433Z 61 PC: 12b98 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:54:17.092538762Z 63 PC: 12ba3 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:54:17.104601641Z 62 PC: 12ba7 | Close file
2018-12-17T22:54:17.106590264Z 67 PC: 12bc5 | Get or set file attributes
2018-12-17T22:54:17.124496477Z 61 PC: 12bca | Open file (Filename = 'TEST.EXE')
2018-12-17T22:54:17.131345392Z 64 PC: 12bd5 | Write file or device (Write 2267 bytes on handle 5)
2018-12-17T22:54:17.140005151Z 87 PC: 12be1 | Get or set file date and time
2018-12-17T22:54:17.158091637Z 62 PC: 12be5 | Close file
2018-12-17T22:54:17.165463647Z 67 PC: 12bf2 | Get or set file attributes
2018-12-17T22:54:17.175324002Z 26 PC: 12b6f | Set disk transfer address
2018-12-17T22:54:17.181363788Z 26 PC: 12b30 | Set disk transfer address
2018-12-17T22:54:17.182528022Z 59 PC: 12ad6 | Change current directory