Sample viewer

vx.netlux.org/Virus.DOS.TPE.CivilWar.1997

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:03:15.103140753Z 26 PC: 12e72 | Set disk transfer address
2018-12-17T23:03:15.10517186Z 44 PC: 135af | Get time 0x135af: in al, 0x40
0x135b1: mov ah, al
0x135b3: in al, 0x40
0x135b5: xor ax, cx
0x135b7: xor dx, ax
0x135b9: jmp 0x135e0
0x135bb: call 0x135c3
0x135be: or ax, ax
0x135c0: je 0x135bb
0x135c2: ret
0x135c3: push dx
0x135c4: push cx
0x135c5: push bx
0x135c6: in al, 0x40
0x135c8: add ax, 0x8d77
0x135cb: mov dx, 0xfc33
0x135ce: mov cx, 7
0x135d1: shl ax, 1
0x135d3: rcl dx, 1
0x135d5: mov bl, al
2018-12-17T23:03:15.113373799Z 78 PC: 12e8b | Find first file
2018-12-17T23:03:15.123780522Z 61 PC: 12e96 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:03:15.133143954Z 87 PC: 12ea0 | Get or set file date and time
2018-12-17T23:03:15.142226449Z 63 PC: 12eb7 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T23:03:15.153412476Z 66 PC: 12f5c | Move file pointer
2018-12-17T23:03:15.156535974Z 64 PC: 12ef2 | Write file or device (Write 1 bytes on handle 5)
2018-12-17T23:03:15.160899252Z 64 PC: 12efd | Write file or device (Write 2 bytes on handle 5)
2018-12-17T23:03:15.164037067Z 64 PC: 12f08 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T23:03:15.168038486Z 66 PC: 12f5c | Move file pointer
2018-12-17T23:03:15.183802073Z 64 PC: 12f36 | Write file or device (Write 2070 bytes on handle 5)
2018-12-17T23:03:15.201567562Z 87 PC: 12f47 | Get or set file date and time