Sample viewer

vx.netlux.org/Virus.DOS.Cobra.400

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:03:03.350464674Z 26 PC: 12a6e | Set disk transfer address
2018-12-17T23:03:03.352188535Z 61 PC: 134dd | Open file (Filename = 'Ã<€r,€SŇƒÃ×[ë:‡!r:ˆ!w, ÃÄV‹òÇD')
2018-12-17T23:03:03.359165512Z 78 PC: 13445 | Find first file
2018-12-17T23:03:03.365467218Z 61 PC: 1344f | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:03:03.372611606Z 63 PC: 13471 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T23:03:03.380832071Z 66 PC: 13436 | Move file pointer
2018-12-17T23:03:03.382758616Z 63 PC: 13517 | Read file or device (Read 407 bytes on handle 5)
2018-12-17T23:03:03.385924467Z 42 PC: 1351d | Get date 0x1351d: mov word ptr [0x107], cx
0x13521: mov word ptr [0x109], dx
0x13525: mov ah, 0x2c
0x13527: int 0x21
0x13529: mov word ptr [0x10b], cx
0x1352d: mov word ptr [0x10d], dx
0x13531: cmp word ptr [0x111], -1
0x13536: jne 0x13542
0x13538: mov word ptr [0x111], 0
0x1353e: inc byte ptr [0x10f]
0x13542: inc word ptr [0x111]
0x13546: call 0x2342d
0x13549: mov cx, 0x190
0x1354c: add cx, word ptr [0x11b]
0x13550: mov dx, 0x100
0x13553: mov ah, 0x40
0x13555: int 0x21
0x13557: jb 0x13563
0x13559: mov ax, 0x5700
0x1355c: int 0x21
2018-12-17T23:03:03.402506552Z 44 PC: 13529 | Get time 0x13529: mov word ptr [0x10b], cx
0x1352d: mov word ptr [0x10d], dx
0x13531: cmp word ptr [0x111], -1
0x13536: jne 0x13542
0x13538: mov word ptr [0x111], 0
0x1353e: inc byte ptr [0x10f]
0x13542: inc word ptr [0x111]
0x13546: call 0x2342d
0x13549: mov cx, 0x190
0x1354c: add cx, word ptr [0x11b]
0x13550: mov dx, 0x100
0x13553: mov ah, 0x40
0x13555: int 0x21
0x13557: jb 0x13563
0x13559: mov ax, 0x5700
0x1355c: int 0x21
0x1355e: mov ax, 0x5701
0x13561: int 0x21
0x13563: mov ah, 0x3e
0x13565: int 0x21
2018-12-17T23:03:03.404884733Z 66 PC: 13436 | Move file pointer
2018-12-17T23:03:03.40708943Z 64 PC: 13557 | Write file or device (Write 807 bytes on handle 5)
2018-12-17T23:03:03.423188213Z 87 PC: 1355e | Get or set file date and time
2018-12-17T23:03:03.424781601Z 87 PC: 13563 | Get or set file date and time
2018-12-17T23:03:03.426729308Z 62 PC: 13567 | Close file
2018-12-17T23:03:03.435208226Z 26 PC: 1343e | Set disk transfer address
2018-12-17T23:03:03.43627612Z 48 PC: 12e7c | Get DOS version
2018-12-17T23:03:03.437302467Z 101 PC: 12e9d | Get extended country info
2018-12-17T23:03:03.438817192Z 2 PC: 1304a | Character output (Char = '5b')
2018-12-17T23:03:03.443623227Z 2 PC: 13050 | Character output (Char = '59')
2018-12-17T23:03:03.446004519Z 2 PC: 1305c | Character output (Char = '2c')
2018-12-17T23:03:03.448376193Z 2 PC: 13050 | Character output (Char = '4e')
2018-12-17T23:03:03.451142724Z 2 PC: 13064 | Character output (Char = '5d')
2018-12-17T23:03:03.453464696Z 2 PC: 1306a | Character output (Char = '3f')
2018-12-17T23:03:03.455896791Z 8 PC: 130a2 | Console input without echo