Sample viewer

vx.netlux.org/Virus.DOS.Signed.982

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:05:57.107488224Z 53 PC: 13a7d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:05:57.109521785Z 37 PC: 13a8d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:05:57.110961572Z 44 PC: 13aa6 | Get time 0x13aa6: cmp dl, 0x14
0x13aa9: jle 0x13aeb
0x13aab: jmp 0x13be6
0x13aae: adc al, 0x28
0x13ab0: and ax, 0x2532
0x13ab3: add sp, word ptr [bx + di]
0x13ab5: add ah, byte ptr cs:[di]
0x13ab8: ucomiss xmm5, dword ptr [si]
0x13abb: cmp word ptr [bx], cx
0x13abd: and ax, 0xeeee
0x13ac1: out dx, al
0x13ac2: out dx, al
0x13ac3: out dx, al
0x13ac4: adc bp, word ptr [bx + di]
0x13ac6: daa
0x13ac7: and ax, 0xe024
0x13acb: loopne 0x13aad
0x13acd: loopne 0x13abc
0x13acf: adc al, 0x32
0x13ad1: and word ptr [0x2c25], si
2018-12-17T23:05:57.113233094Z 71 PC: 13c19 | Get current directory
2018-12-17T23:05:57.117249999Z 47 PC: 13c1d | Get disk transfer address
2018-12-17T23:05:57.118712349Z 26 PC: 13c2e | Set disk transfer address
2018-12-17T23:05:57.120106254Z 78 PC: 13c38 | Find first file
2018-12-17T23:05:57.127165268Z 67 PC: 13c55 | Get or set file attributes
2018-12-17T23:05:57.142697819Z 61 PC: 13c5a | Open file (Filename = '')
2018-12-17T23:05:57.149562385Z 63 PC: 13c6b | Read file or device (Read 28 bytes on handle 5)
2018-12-17T23:05:57.152928726Z 66 PC: 13cda | Move file pointer
2018-12-17T23:05:57.15482821Z 64 PC: 13ce4 | Write file or device (Write 982 bytes on handle 5)
2018-12-17T23:05:57.163555528Z 66 PC: 13d02 | Move file pointer
2018-12-17T23:05:57.165385812Z 64 PC: 13d0c | Write file or device (Write 28 bytes on handle 5)
2018-12-17T23:05:57.168842618Z 87 PC: 13d29 | Get or set file date and time
2018-12-17T23:05:57.170620051Z 62 PC: 13d2d | Close file
2018-12-17T23:05:57.179650713Z 67 PC: 13d35 | Get or set file attributes
2018-12-17T23:05:57.185087296Z 79 PC: 13d3e | Find next file
2018-12-17T23:05:57.187734141Z 59 PC: 13dba | Change current directory
2018-12-17T23:05:57.19224287Z 37 PC: 13dca | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:05:57.198305057Z 26 PC: 13dd8 | Set disk transfer address
2018-12-17T23:05:57.19940905Z 9 PC: 12a5c | Display string (Could not find end pointer)
2018-12-17T23:05:57.215749108Z 76 PC: 12a61 | Terminate with return code (Return code = '0')