Sample viewer

vx.netlux.org/Virus.DOS.CivilWar.212

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:10:05.91680885Z 26 PC: 12ad3 | Set disk transfer address
2018-12-17T23:10:05.918455675Z 78 PC: 12a66 | Find first file
2018-12-17T23:10:05.925959758Z 61 PC: 12a71 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:10:05.938753511Z 63 PC: 12a7e | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:10:05.945918306Z 66 PC: 12aef | Move file pointer
2018-12-17T23:10:05.948771448Z 64 PC: 12aa5 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:10:05.952018911Z 66 PC: 12aef | Move file pointer
2018-12-17T23:10:05.953911037Z 64 PC: 12ab5 | Write file or device (Write 212 bytes on handle 5)
2018-12-17T23:10:05.973905584Z 62 PC: 12ac3 | Close file
2018-12-17T23:10:05.992784032Z 44 PC: 12ac7 | Get time 0x12ac7: cmp dl, 0xa
0x12aca: jb 0x12ad4
0x12acc: mov dx, 0x80
0x12acf: mov ah, 0x1a
0x12ad1: int 0x21
0x12ad3: ret
0x12ad4: mov ax, 0x1100
0x12ad7: mov bx, 0xe00
0x12ada: mov cx, 1
0x12add: mov dx, 0x20
0x12ae0: lea bp, word ptr [bp + 0x1b0]
0x12ae4: int 0x10
0x12ae6: jmp 0x12acc
0x12ae8: xor cx, cx
0x12aea: cdq
0x12aeb: mov ah, 0x42
0x12aed: int 0x21
0x12aef: ret
0x12af0: sbb al, 0x14
0x12af2: adc al, 0x77
2018-12-17T23:10:05.995915778Z 26 PC: 12ad3 | Set disk transfer address