Sample viewer

vx.netlux.org/Virus.DOS.Amz.682

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:08:39.492149215Z 47 PC: 12c6a | Get disk transfer address
2018-12-17T23:08:39.494514004Z 26 PC: 12c7b | Set disk transfer address
2018-12-17T23:08:39.495609942Z 44 PC: 12c7f | Get time 0x12c7f: and dl, 0xf
0x12c82: mov byte ptr [0x452], dl
0x12c86: and dh, 7
0x12c89: mov byte ptr [0x453], dh
0x12c8d: and cl, 0xf
0x12c90: mov byte ptr [0x454], cl
0x12c94: and cl, 7
0x12c97: xor bx, bx
0x12c99: mov bl, cl
0x12c9b: mov si, 0x397
0x12c9e: mov al, byte ptr [bx + si]
0x12ca0: mov byte ptr [0x10d], al
0x12ca3: xor dl, dl
0x12ca5: mov si, 0x412
0x12ca8: mov ah, 0x47
0x12caa: int 0x21
0x12cac: mov byte ptr [0x411], 0x5c
0x12cb1: nop
0x12cb2: mov dx, 0x371
0x12cb5: mov ah, 0x3b
2018-12-17T23:08:39.497677636Z 71 PC: 12cac | Get current directory
2018-12-17T23:08:39.500453632Z 59 PC: 12cb9 | Change current directory
2018-12-17T23:08:39.504622286Z 78 PC: 12cc9 | Find first file
2018-12-17T23:08:39.510958523Z 79 PC: 12cda | Find next file
2018-12-17T23:08:39.513496989Z 79 PC: 12cda | Find next file
2018-12-17T23:08:39.51688386Z 59 PC: 12ce5 | Change current directory
2018-12-17T23:08:39.523339965Z 78 PC: 12cc9 | Find first file
2018-12-17T23:08:39.534120446Z 79 PC: 12cda | Find next file
2018-12-17T23:08:39.537913498Z 79 PC: 12cda | Find next file
2018-12-17T23:08:39.540624963Z 79 PC: 12cda | Find next file
2018-12-17T23:08:39.543114594Z 59 PC: 12ce5 | Change current directory
2018-12-17T23:08:39.554645344Z 78 PC: 12cfb | Find first file
2018-12-17T23:08:39.56147989Z 79 PC: 12d0f | Find next file
2018-12-17T23:08:39.563891267Z 67 PC: 12d45 | Get or set file attributes
2018-12-17T23:08:39.58425467Z 61 PC: 12d4d | Open file (Filename = 'TEST.EXE')
2018-12-17T23:08:39.591041663Z 66 PC: 12d5d | Move file pointer
2018-12-17T23:08:39.592732814Z 63 PC: 12d6b | Read file or device (Read 24 bytes on handle 5)
2018-12-17T23:08:39.60006896Z 62 PC: 12e4c | Close file
2018-12-17T23:08:39.60193439Z 67 PC: 12e5a | Get or set file attributes
2018-12-17T23:08:39.611794094Z 59 PC: 12e61 | Change current directory
2018-12-17T23:08:39.61575341Z 18 PC: 12e6e | Find next file
2018-12-17T23:08:39.618163187Z 76 PC: 12aa4 | Terminate with return code (Return code = '0')