Sample viewer

vx.netlux.org/Virus.DOS.Burger.441

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:58:22.844411613Z 25 PC: 12a56 | Get default drive
2018-12-17T22:58:22.846421755Z 71 PC: 12a67 | Get current directory
2018-12-17T22:58:22.852976929Z 14 PC: 12a6d | Set default drive (Drive = 'A')
2018-12-17T22:58:22.854276404Z 14 PC: 12a9f | Set default drive (Drive = 'A')
2018-12-17T22:58:22.855810894Z 59 PC: 12aa6 | Change current directory
2018-12-17T22:58:22.861099698Z 78 PC: 12afc | Find first file
2018-12-17T22:58:22.874361719Z 61 PC: 12b10 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:58:22.891650684Z 63 PC: 12b1e | Read file or device (Read 441 bytes on handle 5)
2018-12-17T22:58:22.900323957Z 62 PC: 12b22 | Close file
2018-12-17T22:58:22.902452387Z 67 PC: 12b36 | Get or set file attributes
2018-12-17T22:58:22.90976809Z 67 PC: 12b40 | Get or set file attributes
2018-12-17T22:58:22.930381471Z 61 PC: 12b49 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:58:22.939947086Z 87 PC: 12b51 | Get or set file date and time
2018-12-17T22:58:22.942002644Z 64 PC: 12b77 | Write file or device (Write 441 bytes on handle 5)
2018-12-17T22:58:22.946957791Z 87 PC: 12b7f | Get or set file date and time
2018-12-17T22:58:22.949078683Z 62 PC: 12b83 | Close file
2018-12-17T22:58:22.957654411Z 62 PC: 12b87 | Close file
2018-12-17T22:58:22.960793412Z 42 PC: 12ba5 | Get date 0x12ba5: mov byte ptr cs:[0x25f], dh
0x12baa: mov byte ptr cs:[0x260], dl
0x12baf: mov al, byte ptr cs:[0x25f]
0x12bb3: cmp al, 6
0x12bb5: jne 0x12b8b
0x12bb7: mov al, byte ptr cs:[0x260]
0x12bbb: cmp al, 9
0x12bbd: jne 0x12b8b
0x12bbf: mov ah, 5
0x12bc1: mov dl, 0
0x12bc3: mov dh, 0
0x12bc5: mov ch, 0
0x12bc7: mov cl, 1
0x12bc9: mov al, 8
0x12bcb: int 0x13
0x12bcd: int 0x19
0x12bcf: mov ah, 0xe
0x12bd1: mov dl, byte ptr cs:[0x2b7]
0x12bd6: int 0x21
0x12bd8: mov ah, 0x3b
2018-12-17T22:58:22.963659401Z 14 PC: 12bd8 | Set default drive (Drive = 'A')
2018-12-17T22:58:22.965454854Z 59 PC: 12bdf | Change current directory
2018-12-17T22:58:22.974141763Z 0 PC: 12b9f | Program terminate