Sample viewer

vx.netlux.org/Virus.DOS.Andromeda.217

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:54.980674854Z 44 PC: 12a86 | Get time 0x12a86: mov word ptr cs:[bp + 0x129], dx
0x12a8b: lea si, word ptr [bp + 0x1d8]
0x12a8f: mov di, 0x100
0x12a92: push di
0x12a93: movsw word ptr es:[di], word ptr [si]
0x12a94: movsb byte ptr es:[di], byte ptr [si]
0x12a95: lea dx, word ptr [bp + 0x1de]
0x12a99: call 0x12afb
0x12a9c: mov ax, 0x4d00
0x12a9f: add ax, 0x100
0x12aa2: lea dx, word ptr [bp + 0x1d2]
0x12aa6: xor cx, cx
0x12aa8: int 0x21
0x12aaa: jb 0x12af8
0x12aac: push 0x3d02
0x12aaf: pop ax
0x12ab0: lea dx, word ptr [bp + 0x1fc]
0x12ab4: int 0x21
0x12ab6: xchg ax, bx
0x12ab7: mov ah, 0x3f
2018-12-17T23:02:54.983543514Z 26 PC: 12aff | Set disk transfer address
2018-12-17T23:02:54.985433585Z 78 PC: 12aaa | Find first file
2018-12-17T23:02:54.99260016Z 61 PC: 12ab6 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:02:55.009292011Z 63 PC: 12ac2 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:02:55.018319794Z 66 PC: 12b07 | Move file pointer
2018-12-17T23:02:55.020330332Z 64 PC: 12aec | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:02:55.023747051Z 66 PC: 12b07 | Move file pointer
2018-12-17T23:02:55.032789511Z 64 PC: 12a65 | Write file or device (Write 217 bytes on handle 5)
2018-12-17T23:02:55.214107814Z 62 PC: 12af8 | Close file
2018-12-17T23:02:55.223495442Z 26 PC: 12aff | Set disk transfer address