Sample viewer

vx.netlux.org/Worm.DOS.Super.393

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:01:47.504543607Z 44 PC: 12b89 | Get time 0x12b89: add dx, cx
0x12b8b: ret
0x12b8c: mov ax, cs
0x12b8e: mul dx
0x12b90: add dx, ax
0x12b92: ret
0x12b93: mov cx, 0xae
0x12b96: mov dx, 0x2010
0x12b99: mov si, 0x11f
0x12b9c: cmp ax, 0
0x12b9f: xor cx, 0
0x12ba3: xor si, 0
0x12ba7: inc ax
0x12ba8: inc bp
0x12ba9: clc
0x12baa: xor word ptr [si], dx
0x12bac: inc si
0x12bad: inc si
0x12bae: dec ax
0x12baf: dec bp
2018-12-17T23:01:47.508086715Z 60 PC: 12a91 | Create or truncate file
2018-12-17T23:01:47.528145686Z 64 PC: 12aa3 | Write file or device (Write 393 bytes on handle 5)
2018-12-17T23:01:47.537716269Z 62 PC: 12aa9 | Close file
2018-12-17T23:01:47.55630161Z 76 PC: 12a6b | Terminate with return code (Return code = '0')