Sample viewer

vx.netlux.org/Virus.DOS.Dreg.1466

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:34.586332489Z 53 PC: 12a57 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:34.588827872Z 37 PC: 12abd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:34.590533188Z 26 PC: 12b13 | Set disk transfer address
2018-12-17T22:56:34.592260636Z 78 PC: 12b4e | Find first file
2018-12-17T22:56:34.600100457Z 61 PC: 12b5b | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:56:34.607764396Z 63 PC: 12b9f | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:56:34.615386188Z 62 PC: 12c05 | Close file
2018-12-17T22:56:34.618471339Z 67 PC: 12c36 | Get or set file attributes
2018-12-17T22:56:34.637874451Z 61 PC: 12c45 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:56:34.650601992Z 44 PC: 12f78 | Get time 0x12f78: or bh, 0
0x12f7b: pop di
0x12f7c: sub cx, 0
0x12f7f: push dx
0x12f80: push di
0x12f81: add cl, 0xdc
0x12f84: dec dx
0x12f85: inc dx
0x12f86: sub cl, 0xdc
0x12f89: ret
0x12f8a: nop
0x12f8b: lea si, word ptr [bp + 0x10a]
0x12f8f: mov ah, ah
0x12f91: mov cx, 0x27d
0x12f94: mov bx, bx
0x12f96: mov di, si
0x12f98: dec al
0x12f9a: neg bh
0x12f9c: or dx, 0
0x12f9f: neg bh
2018-12-17T22:56:34.653665893Z 44 PC: 12f78 | Get time 0x12f78: or bh, 0
0x12f7b: pop di
0x12f7c: sub cx, 0
0x12f7f: push dx
0x12f80: push di
0x12f81: add cl, 0xdc
0x12f84: dec dx
0x12f85: inc dx
0x12f86: sub cl, 0xdc
0x12f89: ret
0x12f8a: nop
0x12f8b: lea si, word ptr [bp + 0x10a]
0x12f8f: mov ah, ah
0x12f91: mov cx, 0x27d
0x12f94: mov bx, bx
0x12f96: mov di, si
0x12f98: dec al
0x12f9a: neg bh
0x12f9c: or dx, 0
0x12f9f: neg bh
2018-12-17T22:56:34.657223642Z 44 PC: 12f78 | Get time 0x12f78: or bh, 0
0x12f7b: pop di
0x12f7c: sub cx, 0
0x12f7f: push dx
0x12f80: push di
0x12f81: add cl, 0xdc
0x12f84: dec dx
0x12f85: inc dx
0x12f86: sub cl, 0xdc
0x12f89: ret
0x12f8a: nop
0x12f8b: lea si, word ptr [bp + 0x10a]
0x12f8f: mov ah, ah
0x12f91: mov cx, 0x27d
0x12f94: mov bx, bx
0x12f96: mov di, si
0x12f98: dec al
0x12f9a: neg bh
0x12f9c: or dx, 0
0x12f9f: neg bh
2018-12-17T22:56:34.660768888Z 66 PC: 1305f | Move file pointer
2018-12-17T22:56:34.662755143Z 64 PC: 1309d | Write file or device (Write 1466 bytes on handle 5)
2018-12-17T22:56:34.673817863Z 66 PC: 13135 | Move file pointer
2018-12-17T22:56:34.67729468Z 64 PC: 13140 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:56:34.698372422Z 87 PC: 12d01 | Get or set file date and time
2018-12-17T22:56:34.700878464Z 62 PC: 12d16 | Close file
2018-12-17T22:56:34.710199139Z 67 PC: 12d4b | Get or set file attributes
2018-12-17T22:56:34.716501459Z 26 PC: 12da8 | Set disk transfer address
2018-12-17T22:56:34.718650069Z 37 PC: 12df0 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')