Sample viewer

vx.netlux.org/Virus.DOS.Drepo.2470

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:59:04.318617697Z 98 PC: 5137a | Get current PSP
2018-12-17T22:59:04.319946104Z 62 PC: 51386 | Close file
2018-12-17T22:59:04.322594992Z 72 PC: 513e0 | Allocate memory
2018-12-17T22:59:04.32476432Z 74 PC: 513f0 | Reallocate memory
2018-12-17T22:59:04.326976758Z 72 PC: 513e0 | Allocate memory
2018-12-17T22:59:04.343633112Z 50 PC: 51402 | Get disk parameter block for specified drive
2018-12-17T22:59:04.688207465Z 42 PC: 5148c | Get date 0x5148c: mov byte ptr [0x8d7], dh
0x51490: mov word ptr [0x8d8], cx
0x51494: mov ax, 0x3d22
0x51497: mov dx, 0x856
0x5149a: int 0x21
0x5149c: mov bx, ax
0x5149e: call 0x51632
0x514a1: mov byte ptr [0x861], 0x43
0x514a6: nop
0x514a7: mov byte ptr [0x860], 0x20
0x514ac: nop
0x514ad: mov ax, word ptr [0x892]
0x514b0: add ax, 3
0x514b3: mov word ptr [0x8c1], ax
0x514b6: call 0x51a80
0x514b9: call 0x51632
0x514bc: mov ax, 0x4202
0x514bf: mov cx, 0xffff
0x514c2: mov dx, 0xf65a
0x514c5: int 0x21
2018-12-17T22:59:04.691568902Z 61 PC: 5149c | Open file (Filename = 'C:\COMMAND.LOM')
2018-12-17T22:59:04.701993265Z 63 PC: 5163c | Read file or device (Read 46 bytes on handle 5)
2018-12-17T22:59:04.718292137Z 66 PC: 51a8b | Move file pointer
2018-12-17T22:59:04.720772379Z 63 PC: 5163c | Read file or device (Read 46 bytes on handle 5)
2018-12-17T22:59:04.746268067Z 66 PC: 514c7 | Move file pointer
2018-12-17T22:59:04.749022384Z 66 PC: 514ec | Move file pointer
2018-12-17T22:59:04.755999637Z 64 PC: 51c86 | Write file or device (Write 2485 bytes on handle 5)
2018-12-17T22:59:04.783707753Z 66 PC: 51a8b | Move file pointer
2018-12-17T22:59:04.785735074Z 64 PC: 51a93 | Write file or device (Write 46 bytes on handle 5)
2018-12-17T22:59:04.790050475Z 62 PC: 514ff | Close file
2018-12-17T22:59:04.799266685Z 73 PC: 51518 | Release memory
2018-12-17T22:59:04.801153953Z 74 PC: 51526 | Reallocate memory
2018-12-17T22:59:04.803964685Z 48 PC: 12a75 | Get DOS version
2018-12-17T22:59:04.805963352Z 67 PC: 12afd | Get or set file attributes
2018-12-17T22:59:04.812409958Z 9 PC: 12a6d | Display string (String= 't2����G\.\.D� E%F%#s%t%�%e-f-k(���(��^*a')
2018-12-17T22:59:04.819090384Z 76 PC: 12a70 | Terminate with return code (Return code = '1')