Sample viewer

vx.netlux.org/Virus.DOS.Nazgul.290

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:00:28.559211786Z 250 PC: 12a82 | UNKNOWN!
2018-12-17T23:00:28.561048051Z 255 PC: 12ab2 | UNKNOWN!
2018-12-17T23:00:28.562553171Z 65 PC: 12abf | Delete file (Filename = '')
2018-12-17T23:00:28.564496762Z 78 PC: 12ae5 | Find first file
2018-12-17T23:00:28.576092736Z 61 PC: 12aef | Open file (Filename = '')
2018-12-17T23:00:28.584971463Z 44 PC: 12af7 | Get time 0x12af7: xor dh, dh
0x12af9: rcr dl, 1
0x12afb: rcr dl, 1
0x12afd: push dx
0x12afe: sub cx, cx
0x12b00: mov ah, 0x3f
0x12b02: mov cx, 0xffff
0x12b05: mov dx, 0x122
0x12b08: int 0x21
0x12b0a: cmp ax, 0x3e9
0x12b0d: jb 0x12b4b
0x12b0f: cmp ax, 0xfa00
0x12b12: ja 0x12b4b
0x12b14: add ax, 0x122
0x12b17: pop cx
0x12b18: add ax, cx
0x12b1a: mov word ptr cs:[0x115], ax
0x12b1e: cmp word ptr [0x124], 0x614e
0x12b24: je 0x12b4b
0x12b26: mov ax, 0x4200
2018-12-17T23:00:28.587807217Z 63 PC: 12b0a | Read file or device (Read 65535 bytes on handle 5)
2018-12-17T23:00:28.595118147Z 62 PC: 12b4f | Close file
2018-12-17T23:00:28.601669731Z 79 PC: 12b55 | Find next file
2018-12-17T23:00:28.604684504Z 61 PC: 12aef | Open file (Filename = '')
2018-12-17T23:00:28.613310283Z 44 PC: 12af7 | Get time 0x12af7: xor dh, dh
0x12af9: rcr dl, 1
0x12afb: rcr dl, 1
0x12afd: push dx
0x12afe: sub cx, cx
0x12b00: mov ah, 0x3f
0x12b02: mov cx, 0xffff
0x12b05: mov dx, 0x122
0x12b08: int 0x21
0x12b0a: cmp ax, 0x3e9
0x12b0d: jb 0x12b4b
0x12b0f: cmp ax, 0xfa00
0x12b12: ja 0x12b4b
0x12b14: add ax, 0x122
0x12b17: pop cx
0x12b18: add ax, cx
0x12b1a: mov word ptr cs:[0x115], ax
0x12b1e: cmp word ptr [0x124], 0x614e
0x12b24: je 0x12b4b
0x12b26: mov ax, 0x4200
2018-12-17T23:00:28.617694473Z 63 PC: 12b0a | Read file or device (Read 65535 bytes on handle 5)
2018-12-17T23:00:28.625167695Z 62 PC: 12b4f | Close file
2018-12-17T23:00:28.628439764Z 79 PC: 12b55 | Find next file
2018-12-17T23:00:28.632377263Z 61 PC: 12aef | Open file (Filename = '')
2018-12-17T23:00:28.640443025Z 44 PC: 12af7 | Get time 0x12af7: xor dh, dh
0x12af9: rcr dl, 1
0x12afb: rcr dl, 1
0x12afd: push dx
0x12afe: sub cx, cx
0x12b00: mov ah, 0x3f
0x12b02: mov cx, 0xffff
0x12b05: mov dx, 0x122
0x12b08: int 0x21
0x12b0a: cmp ax, 0x3e9
0x12b0d: jb 0x12b4b
0x12b0f: cmp ax, 0xfa00
0x12b12: ja 0x12b4b
0x12b14: add ax, 0x122
0x12b17: pop cx
0x12b18: add ax, cx
0x12b1a: mov word ptr cs:[0x115], ax
0x12b1e: cmp word ptr [0x124], 0x614e
0x12b24: je 0x12b4b
0x12b26: mov ax, 0x4200
2018-12-17T23:00:28.643293499Z 63 PC: 12b0a | Read file or device (Read 65535 bytes on handle 5)
2018-12-17T23:00:28.650535525Z 62 PC: 12b4f | Close file
2018-12-17T23:00:28.652589775Z 79 PC: 12b55 | Find next file
2018-12-17T23:00:28.655388408Z 61 PC: 12aef | Open file (Filename = '')
2018-12-17T23:00:28.662678582Z 44 PC: 12af7 | Get time 0x12af7: xor dh, dh
0x12af9: rcr dl, 1
0x12afb: rcr dl, 1
0x12afd: push dx
0x12afe: sub cx, cx
0x12b00: mov ah, 0x3f
0x12b02: mov cx, 0xffff
0x12b05: mov dx, 0x122
0x12b08: int 0x21
0x12b0a: cmp ax, 0x3e9
0x12b0d: jb 0x12b4b
0x12b0f: cmp ax, 0xfa00
0x12b12: ja 0x12b4b
0x12b14: add ax, 0x122
0x12b17: pop cx
0x12b18: add ax, cx
0x12b1a: mov word ptr cs:[0x115], ax
0x12b1e: cmp word ptr [0x124], 0x614e
0x12b24: je 0x12b4b
0x12b26: mov ax, 0x4200
2018-12-17T23:00:28.666285434Z 63 PC: 12b0a | Read file or device (Read 65535 bytes on handle 5)
2018-12-17T23:00:28.673954475Z 62 PC: 12b4f | Close file
2018-12-17T23:00:28.675943211Z 79 PC: 12b55 | Find next file
2018-12-17T23:00:28.679493866Z 61 PC: 12aef | Open file (Filename = '')
2018-12-17T23:00:28.687014077Z 44 PC: 12af7 | Get time 0x12af7: xor dh, dh
0x12af9: rcr dl, 1
0x12afb: rcr dl, 1
0x12afd: push dx
0x12afe: sub cx, cx
0x12b00: mov ah, 0x3f
0x12b02: mov cx, 0xffff
0x12b05: mov dx, 0x122
0x12b08: int 0x21
0x12b0a: cmp ax, 0x3e9
0x12b0d: jb 0x12b4b
0x12b0f: cmp ax, 0xfa00
0x12b12: ja 0x12b4b
0x12b14: add ax, 0x122
0x12b17: pop cx
0x12b18: add ax, cx
0x12b1a: mov word ptr cs:[0x115], ax
0x12b1e: cmp word ptr [0x124], 0x614e
0x12b24: je 0x12b4b
0x12b26: mov ax, 0x4200
2018-12-17T23:00:28.689792234Z 63 PC: 12b0a | Read file or device (Read 65535 bytes on handle 5)
2018-12-17T23:00:28.699946386Z 62 PC: 12b4f | Close file
2018-12-17T23:00:28.701978736Z 79 PC: 12b55 | Find next file
2018-12-17T23:00:28.704898377Z 61 PC: 12aef | Open file (Filename = '')
2018-12-17T23:00:28.713176077Z 44 PC: 12af7 | Get time 0x12af7: xor dh, dh
0x12af9: rcr dl, 1
0x12afb: rcr dl, 1
0x12afd: push dx
0x12afe: sub cx, cx
0x12b00: mov ah, 0x3f
0x12b02: mov cx, 0xffff
0x12b05: mov dx, 0x122
0x12b08: int 0x21
0x12b0a: cmp ax, 0x3e9
0x12b0d: jb 0x12b4b
0x12b0f: cmp ax, 0xfa00
0x12b12: ja 0x12b4b
0x12b14: add ax, 0x122
0x12b17: pop cx
0x12b18: add ax, cx
0x12b1a: mov word ptr cs:[0x115], ax
0x12b1e: cmp word ptr [0x124], 0x614e
0x12b24: je 0x12b4b
0x12b26: mov ax, 0x4200
2018-12-17T23:00:28.715654837Z 63 PC: 12b0a | Read file or device (Read 65535 bytes on handle 5)
2018-12-17T23:00:28.722765071Z 62 PC: 12b4f | Close file
2018-12-17T23:00:28.725068485Z 79 PC: 12b55 | Find next file
2018-12-17T23:00:28.728597607Z 61 PC: 12aef | Open file (Filename = '')
2018-12-17T23:00:28.736294324Z 44 PC: 12af7 | Get time 0x12af7: xor dh, dh
0x12af9: rcr dl, 1
0x12afb: rcr dl, 1
0x12afd: push dx
0x12afe: sub cx, cx
0x12b00: mov ah, 0x3f
0x12b02: mov cx, 0xffff
0x12b05: mov dx, 0x122
0x12b08: int 0x21
0x12b0a: cmp ax, 0x3e9
0x12b0d: jb 0x12b4b
0x12b0f: cmp ax, 0xfa00
0x12b12: ja 0x12b4b
0x12b14: add ax, 0x122
0x12b17: pop cx
0x12b18: add ax, cx
0x12b1a: mov word ptr cs:[0x115], ax
0x12b1e: cmp word ptr [0x124], 0x614e
0x12b24: je 0x12b4b
0x12b26: mov ax, 0x4200
2018-12-17T23:00:28.739310695Z 63 PC: 12b0a | Read file or device (Read 65535 bytes on handle 5)
2018-12-17T23:00:28.748259378Z 62 PC: 12b4f | Close file
2018-12-17T23:00:28.750874133Z 79 PC: 12b55 | Find next file
2018-12-17T23:00:28.753991099Z 61 PC: 12aef | Open file (Filename = '')
2018-12-17T23:00:28.762124232Z 44 PC: 12af7 | Get time 0x12af7: xor dh, dh
0x12af9: rcr dl, 1
0x12afb: rcr dl, 1
0x12afd: push dx
0x12afe: sub cx, cx
0x12b00: mov ah, 0x3f
0x12b02: mov cx, 0xffff
0x12b05: mov dx, 0x122
0x12b08: int 0x21
0x12b0a: cmp ax, 0x3e9
0x12b0d: jb 0x12b4b
0x12b0f: cmp ax, 0xfa00
0x12b12: ja 0x12b4b
0x12b14: add ax, 0x122
0x12b17: pop cx
0x12b18: add ax, cx
0x12b1a: mov word ptr cs:[0x115], ax
0x12b1e: cmp word ptr [0x124], 0x614e
0x12b24: je 0x12b4b
0x12b26: mov ax, 0x4200
2018-12-17T23:00:28.765624162Z 63 PC: 12b0a | Read file or device (Read 65535 bytes on handle 5)
2018-12-17T23:00:28.768877437Z 62 PC: 12b4f | Close file
2018-12-17T23:00:28.772239035Z 79 PC: 12b55 | Find next file