Sample viewer

vx.netlux.org/Virus.DOS.CivilWar.213

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:12:29.985921688Z 26 PC: 12ad4 | Set disk transfer address
2018-12-17T23:12:29.987857852Z 78 PC: 12a66 | Find first file
2018-12-17T23:12:29.992483884Z 61 PC: 12a71 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:12:29.998656341Z 63 PC: 12a7e | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:12:30.005473848Z 66 PC: 12af0 | Move file pointer
2018-12-17T23:12:30.006958123Z 64 PC: 12aa5 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:12:30.009488142Z 66 PC: 12af0 | Move file pointer
2018-12-17T23:12:30.011149655Z 64 PC: 12ab5 | Write file or device (Write 213 bytes on handle 5)
2018-12-17T23:12:30.024933591Z 62 PC: 12ac4 | Close file
2018-12-17T23:12:30.032782593Z 44 PC: 12ac8 | Get time 0x12ac8: cmp dl, 0xa
0x12acb: jb 0x12ad5
0x12acd: mov dx, 0x80
0x12ad0: mov ah, 0x1a
0x12ad2: int 0x21
0x12ad4: ret
0x12ad5: mov ax, 0x1100
0x12ad8: mov bx, 0xe00
0x12adb: mov cx, 1
0x12ade: mov dx, 0x20
0x12ae1: lea bp, word ptr [bp + 0x1b1]
0x12ae5: int 0x10
0x12ae7: jmp 0x12acd
0x12ae9: xor cx, cx
0x12aeb: cdq
0x12aec: mov ah, 0x42
0x12aee: int 0x21
0x12af0: ret
0x12af1: sbb al, 0x14
0x12af3: adc al, 0x77
2018-12-17T23:12:30.034839512Z 26 PC: 12ad4 | Set disk transfer address