Sample viewer

vx.netlux.org/Virus.DOS.Mecdon.1470

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:03:31.216325367Z 44 PC: 21ccb | Get time 0x21ccb: ret
0x21ccc: clc
0x21ccd: inc ax
0x21cce: sbb word ptr [bx + si], ax
0x21cd0: mov word ptr cs:[bp + 0x12f], ds
0x21cd5: xor ax, ax
0x21cd7: mov es, ax
0x21cd9: mov di, 4
0x21cdc: cli
0x21cdd: cld
0x21cde: stosw word ptr es:[di], ax
0x21cdf: stosw word ptr es:[di], ax
0x21ce0: add di, 4
0x21ce3: stosw word ptr es:[di], ax
0x21ce4: stosw word ptr es:[di], ax
0x21ce5: sti
0x21ce6: sub word ptr cs:[bp + 0x1b8], 0x7182
0x21ced: call 0x21cf8
0x21cf0: add word ptr cs:[bp + 0x1b8], 0x7182
0x21cf7: ret
2018-12-17T23:03:31.218617169Z 25 PC: 21ccb | Get default drive
2018-12-17T23:03:31.219925848Z 71 PC: 21ccb | Get current directory
2018-12-17T23:03:31.223607479Z 53 PC: 21ccb | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:31.229614571Z 37 PC: 21ccb | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:31.233663461Z 26 PC: 21ccb | Set disk transfer address
2018-12-17T23:03:31.243012604Z 78 PC: 21ccb | Find first file
2018-12-17T23:03:31.248521985Z 47 PC: 21ccb | Get disk transfer address
2018-12-17T23:03:31.249959832Z 67 PC: 21ccb | Get or set file attributes
2018-12-17T23:03:31.256340854Z 67 PC: 21ccb | Get or set file attributes
2018-12-17T23:03:31.272484722Z 61 PC: 21ccb | Open file (Filename = 'TEST.EXE')
2018-12-17T23:03:31.279297023Z 63 PC: 21ccb | Read file or device (Read 24 bytes on handle 5)
2018-12-17T23:03:31.28293208Z 66 PC: 21ccb | Move file pointer
2018-12-17T23:03:31.284419391Z 64 PC: 21ccb | Write file or device (Write 24 bytes on handle 5)
2018-12-17T23:03:31.287011395Z 66 PC: 21ccb | Move file pointer
2018-12-17T23:03:31.28919885Z 64 PC: 21ccb | Write file or device (Write 1470 bytes on handle 5)