Sample viewer

vx.netlux.org/Virus.DOS.Gandalf.240

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:10:04.038740744Z 26 PC: 22715 | Set disk transfer address
2018-12-17T23:10:04.040047149Z 78 PC: 2271c | Find first file
2018-12-17T23:10:04.047051072Z 67 PC: 22730 | Get or set file attributes
2018-12-17T23:10:04.05158337Z 67 PC: 2273c | Get or set file attributes
2018-12-17T23:10:04.076325939Z 61 PC: 22743 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:10:04.088625364Z 63 PC: 22751 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:10:04.096783806Z 66 PC: 22763 | Move file pointer
2018-12-17T23:10:04.098723251Z 44 PC: 227bb | Get time 0x227bb: shr dh, 1
0x227bd: jb 0x227c5
0x227bf: xor word ptr [0xfdc0], 0x2d02
0x227c5: mov dx, 0xfdae
0x227c8: mov ah, 0x40
0x227ca: call 0x227d1
0x227cd: mov cl, 0xf0
0x227cf: int 0x21
0x227d1: mov si, 0xfe8d
0x227d4: mov cx, 0xc3
0x227d7: dec si
0x227d8: xor byte ptr [si], 0x40
0x227db: loop 0x227d7
0x227dd: ret
0x227de: rol word ptr [bp + di], -0x42
0x227e1: loope 0x22783
0x227e3: mov di, 0xa164
0x227e6: rep movsb byte ptr es:[di], byte ptr [si]
0x227e8: call 0x2515f
0x227eb: xor ax, ax
2018-12-17T23:10:04.106106476Z 64 PC: 227d1 | Write file or device (Write 240 bytes on handle 5)
2018-12-17T23:10:04.116674728Z 66 PC: 22774 | Move file pointer
2018-12-17T23:10:04.118632667Z 64 PC: 2277e | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:10:04.127542662Z 87 PC: 2278c | Get or set file date and time
2018-12-17T23:10:04.129496674Z 62 PC: 22790 | Close file
2018-12-17T23:10:04.13902437Z 67 PC: 22795 | Get or set file attributes
2018-12-17T23:10:04.151632605Z 26 PC: 2279c | Set disk transfer address
2018-12-17T23:10:04.154081688Z 9 PC: 12a85 | Display string (String= ' ')
2018-12-17T23:10:04.160680309Z 0 PC: 12a89 | Program terminate