Sample viewer

vx.netlux.org/Virus.DOS.Dreg.510

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:58.454520706Z 53 PC: 12a5a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:58.460514024Z 37 PC: 12a75 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:58.461973398Z 26 PC: 12a8b | Set disk transfer address
2018-12-17T23:06:58.463116642Z 78 PC: 12a9c | Find first file
2018-12-17T23:06:58.470973364Z 61 PC: 12aaa | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:06:58.477793025Z 63 PC: 12ab8 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:06:58.484053631Z 62 PC: 12ae9 | Close file
2018-12-17T23:06:58.487289927Z 67 PC: 12af4 | Get or set file attributes
2018-12-17T23:06:58.504754559Z 61 PC: 12afd | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:06:58.511373515Z 44 PC: 12c02 | Get time 0x12c02: pop di
0x12c03: push dx
0x12c04: push di
0x12c05: ret
0x12c06: inc cx
0x12c07: neg ax
0x12c09: neg ax
0x12c0b: dec cx
0x12c0c: lea si, word ptr [bp + 0x111]
0x12c10: mov di, si
0x12c12: mov cx, 0xd0
0x12c15: lodsw ax, word ptr [si]
0x12c16: jmp 0x12c20
0x12c18: inc bh
0x12c1a: dec bh
0x12c1c: stosw word ptr es:[di], ax
0x12c1d: loop 0x12c15
0x12c1f: ret
0x12c20: xor ax, word ptr [bp + 0x2b8]
0x12c24: xor ah, byte ptr [bp + 0x2b7]
2018-12-17T23:06:58.520090497Z 44 PC: 12c02 | Get time 0x12c02: pop di
0x12c03: push dx
0x12c04: push di
0x12c05: ret
0x12c06: inc cx
0x12c07: neg ax
0x12c09: neg ax
0x12c0b: dec cx
0x12c0c: lea si, word ptr [bp + 0x111]
0x12c10: mov di, si
0x12c12: mov cx, 0xd0
0x12c15: lodsw ax, word ptr [si]
0x12c16: jmp 0x12c20
0x12c18: inc bh
0x12c1a: dec bh
0x12c1c: stosw word ptr es:[di], ax
0x12c1d: loop 0x12c15
0x12c1f: ret
0x12c20: xor ax, word ptr [bp + 0x2b8]
0x12c24: xor ah, byte ptr [bp + 0x2b7]
2018-12-17T23:06:58.522497553Z 66 PC: 12c83 | Move file pointer
2018-12-17T23:06:58.523933282Z 64 PC: 12c99 | Write file or device (Write 510 bytes on handle 5)
2018-12-17T23:06:58.532556331Z 66 PC: 12ca2 | Move file pointer
2018-12-17T23:06:58.533934411Z 64 PC: 12cad | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:06:58.540567121Z 87 PC: 12b39 | Get or set file date and time
2018-12-17T23:06:58.54210438Z 62 PC: 12b3d | Close file
2018-12-17T23:06:58.549889474Z 67 PC: 12b4c | Get or set file attributes
2018-12-17T23:06:58.559690622Z 26 PC: 12b5e | Set disk transfer address
2018-12-17T23:06:58.560813849Z 37 PC: 12b71 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')