Sample viewer

vx.netlux.org/Virus.DOS.Chameleon.1256.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:54.642512192Z 44 PC: 12f3a | Get time 0x12f3a: xor dx, cx
0x12f3c: mov word ptr [bp - 0x10], dx
0x12f3f: call 0x22d4e
0x12f42: mov di, 0x100
0x12f45: push ds
0x12f46: pop es
0x12f47: mov cx, 0x8000
0x12f4a: mov si, 0x5ef
0x12f4d: lodsb al, byte ptr [si]
0x12f4e: repne scasb al, byte ptr es:[di]
0x12f50: cmp cx, 0
0x12f53: je 0x12f6e
0x12f55: cmp di, 0x5ef
0x12f59: jge 0x12f6e
0x12f5b: lodsb al, byte ptr [si]
0x12f5c: scasb al, byte ptr es:[di]
0x12f5d: jne 0x12f47
0x12f5f: call 0x22d4e
0x12f62: mov ax, word ptr [bp - 0x10]
0x12f65: dec di
2018-12-17T22:56:54.646912616Z 48 PC: 12ab3 | Get DOS version
2018-12-17T22:56:54.649005398Z 47 PC: 12ac1 | Get disk transfer address
2018-12-17T22:56:54.651617774Z 26 PC: 12ad6 | Set disk transfer address
2018-12-17T22:56:54.65339504Z 78 PC: 12b5a | Find first file
2018-12-17T22:56:54.66065616Z 67 PC: 12b9a | Get or set file attributes
2018-12-17T22:56:54.668644305Z 67 PC: 12bab | Get or set file attributes
2018-12-17T22:56:54.687489331Z 61 PC: 12bb6 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:56:54.696595446Z 87 PC: 12bc3 | Get or set file date and time
2018-12-17T22:56:54.700708693Z 63 PC: 12bd6 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:56:54.710558061Z 66 PC: 12bf2 | Move file pointer
2018-12-17T22:56:54.717428415Z 44 PC: 12c20 | Get time 0x12c20: xor dx, cx
0x12c22: int3
0x12c23: aas
0x12c24: mov dh, 0x56
2018-12-17T22:56:54.723706394Z 64 PC: 1304a | Write file or device (Write 1256 bytes on handle 5)
2018-12-17T22:56:54.734751841Z 66 PC: 12cfb | Move file pointer
2018-12-17T22:56:54.73687767Z 64 PC: 12d0c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:56:54.744630337Z 87 PC: 12d1d | Get or set file date and time
2018-12-17T22:56:54.747261771Z 62 PC: 12d21 | Close file
2018-12-17T22:56:54.756159903Z 67 PC: 12d2f | Get or set file attributes
2018-12-17T22:56:54.767124086Z 26 PC: 12d3a | Set disk transfer address
2018-12-17T22:56:54.768995725Z 0 PC: 12a47 | Program terminate