Sample viewer

vx.netlux.org/Virus.DOS.Ash.860

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:00:29.199656395Z 26 PC: 12a9b | Set disk transfer address
2018-12-17T23:00:29.201403546Z 78 PC: 12aa7 | Find first file
2018-12-17T23:00:29.207239965Z 67 PC: 12ad1 | Get or set file attributes
2018-12-17T23:00:29.223451075Z 61 PC: 12ad8 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:00:29.233481207Z 63 PC: 12ae8 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:00:29.241314039Z 66 PC: 12af8 | Move file pointer
2018-12-17T23:00:29.242928144Z 64 PC: 12b15 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:00:29.245791079Z 44 PC: 12a70 | Get time 0x12a70: mov word ptr [bp + 0x117], dx
0x12a74: call 0x22a59
0x12a77: mov ah, 0x40
0x12a79: mov cx, 0x358
0x12a7c: lea dx, word ptr [bp + 0x109]
0x12a80: int 0x21
0x12a82: call 0x22a59
0x12a85: ret
0x12a86: lea si, word ptr [bp + 0x105]
0x12a8a: mov di, 0x100
0x12a8d: mov cx, 4
0x12a90: cld
0x12a91: rep movsb byte ptr es:[di], byte ptr [si]
0x12a93: mov ah, 0x1a
0x12a95: lea dx, word ptr [bp + 0x461]
0x12a99: int 0x21
0x12a9b: mov ah, 0x4e
0x12a9d: lea dx, word ptr [bp + 0x262]
0x12aa1: lea si, word ptr [bp + 0x47f]
0x12aa5: int 0x21
2018-12-17T23:00:29.249505406Z 64 PC: 12a82 | Write file or device (Write 856 bytes on handle 5)
2018-12-17T23:00:29.258469465Z 66 PC: 12b21 | Move file pointer
2018-12-17T23:00:29.260052787Z 64 PC: 12b3f | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:00:29.267572739Z 87 PC: 12b4c | Get or set file date and time
2018-12-17T23:00:29.270339593Z 62 PC: 12b50 | Close file
2018-12-17T23:00:29.278420441Z 67 PC: 12b5f | Get or set file attributes
2018-12-17T23:00:29.289426867Z 60 PC: 12b7f | Create or truncate file
2018-12-17T23:00:29.297679713Z 64 PC: 12b8d | Write file or device (Write 492 bytes on handle 5)
2018-12-17T23:00:29.301219011Z 62 PC: 12b91 | Close file
2018-12-17T23:00:29.310454121Z 26 PC: 12b98 | Set disk transfer address