Sample viewer

vx.netlux.org/Virus.DOS.Scitzo.1264

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:05:30.369092057Z 171 PC: 12d80 | UNKNOWN!
2018-12-17T23:05:30.370869934Z 74 PC: 12d8e | Reallocate memory
2018-12-17T23:05:30.372379066Z 74 PC: 12d96 | Reallocate memory
2018-12-17T23:05:30.373909527Z 72 PC: 12d9d | Allocate memory
2018-12-17T23:05:30.375936003Z 53 PC: 12dbc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:05:30.377065255Z 37 PC: 12dcc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:05:30.378128731Z 61 PC: 9f8b1 | Open file (Filename = '')
2018-12-17T23:05:30.385632382Z 87 PC: 9f8c1 | Get or set file date and time
2018-12-17T23:05:30.387252059Z 63 PC: 9f8dd | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:05:30.391884133Z 66 PC: 9f9df | Move file pointer
2018-12-17T23:05:30.393267658Z 44 PC: 9fb46 | Get time 0x9fb46: push ds
0x9fb47: pop es
0x9fb48: mov ax, dx
0x9fb4a: and ax, 3
0x9fb4d: cmp al, 3
0x9fb4f: jne 0x9fb55
0x9fb51: nop
0x9fb52: nop
0x9fb53: dec al
0x9fb55: mov cl, 3
0x9fb57: mul cl
0x9fb59: mov si, 0x38d
0x9fb5c: add si, ax
0x9fb5e: mov di, 0xd
0x9fb61: movsb byte ptr es:[di], byte ptr [si]
0x9fb62: inc di
0x9fb63: inc di
0x9fb64: movsw word ptr es:[di], word ptr [si]
0x9fb65: mov ax, dx
0x9fb67: shr ax, 2
2018-12-17T23:05:30.395671817Z 44 PC: 9fba9 | Get time 0x9fba9: mov ax, dx
0x9fbab: shr ax, 3
0x9fbae: and ax, 3
0x9fbb1: cmp al, 3
0x9fbb3: jne 0x9fbb9
0x9fbb5: nop
0x9fbb6: nop
0x9fbb7: dec al
0x9fbb9: mov cl, 9
0x9fbbb: mul cl
0x9fbbd: mov si, 0x3c3
0x9fbc0: add si, ax
0x9fbc2: mov di, 0
0x9fbc5: movsw word ptr es:[di], word ptr [si]
0x9fbc6: movsw word ptr es:[di], word ptr [si]
0x9fbc7: movsw word ptr es:[di], word ptr [si]
0x9fbc8: movsw word ptr es:[di], word ptr [si]
0x9fbc9: movsb byte ptr es:[di], byte ptr [si]
0x9fbca: mov ax, dx
0x9fbcc: shr ax, 1
2018-12-17T23:05:30.397519548Z 44 PC: 9fb10 | Get time 0x9fb10: mov word ptr [0x1d], dx
0x9fb14: mov word ptr [0x45], dx
0x9fb18: mov word ptr [0x3f2], dx
0x9fb1c: call 0xafafa
0x9fb1f: mov ah, 0x40
0x9fb21: mov cx, 0x62
0x9fb24: xor dx, dx
0x9fb26: int 0x21
0x9fb28: call 0xafafa
0x9fb2b: call 0x9fb2f
0x9fb2e: ret
0x9fb2f: mov ax, word ptr [0x14d]
0x9fb32: mov word ptr [0x35], ax
0x9fb35: mov ax, word ptr [0x14f]
0x9fb38: mov word ptr [0x37], ax
0x9fb3b: call 0xaf738
0x9fb3e: call 0xafafa
0x9fb41: ret
0x9fb42: mov ah, 0x2c
0x9fb44: int 0x21
2018-12-17T23:05:30.39920897Z 64 PC: 9fb28 | Write file or device (Write 98 bytes on handle 5)
2018-12-17T23:05:30.409602136Z 64 PC: 9f749 | Write file or device (Write 1166 bytes on handle 5)
2018-12-17T23:05:30.761411955Z 66 PC: 9f9fe | Move file pointer
2018-12-17T23:05:30.762897028Z 64 PC: 9fa08 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:05:30.766215238Z 87 PC: 9fa6a | Get or set file date and time
2018-12-17T23:05:30.770014929Z 62 PC: 9fa6e | Close file
2018-12-17T23:05:30.776170111Z 61 PC: 12de7 | Open file (Filename = '')
2018-12-17T23:05:30.787672528Z 62 PC: 12dec | Close file