Sample viewer

vx.netlux.org/Virus.DOS.Leprosy.TheThing.756

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:26.587511045Z 48 PC: 12bdd | Get DOS version
2018-12-17T23:04:26.589973023Z 44 PC: 12be5 | Get time 0x12be5: add dh, cl
0x12be7: mov word ptr [0x103], dx
0x12beb: mov dx, 0x1ed
0x12bee: mov ah, 0x1a
0x12bf0: int 0x21
0x12bf2: mov ah, 0x19
0x12bf4: int 0x21
0x12bf6: mov dl, al
0x12bf8: inc dl
0x12bfa: mov ah, 0x47
0x12bfc: mov si, 0x24c
0x12bff: int 0x21
0x12c01: mov dx, 0x1eb
0x12c04: mov ah, 0x3b
0x12c06: int 0x21
0x12c08: mov cx, 0x13
0x12c0b: mov dx, 0x1e3
0x12c0e: mov ah, 0x4e
0x12c10: int 0x21
0x12c12: cmp ax, 0x12
2018-12-17T23:04:26.592169795Z 26 PC: 12bf2 | Set disk transfer address
2018-12-17T23:04:26.593177597Z 25 PC: 12bf6 | Get default drive
2018-12-17T23:04:26.594150138Z 71 PC: 12c01 | Get current directory
2018-12-17T23:04:26.597205632Z 59 PC: 12c08 | Change current directory
2018-12-17T23:04:26.600914021Z 78 PC: 12c12 | Find first file
2018-12-17T23:04:26.606389002Z 76 PC: 12d34 | Terminate with return code (Return code = '0')