Sample viewer

vx.netlux.org/Virus.DOS.Radyum.448

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:14:17.389840796Z 44 PC: 12c96 | Get time 0x12c96: mov word ptr [bp + 0x112], dx
0x12c9a: mov ah, 0x1a
0x12c9c: lea dx, word ptr [bp + 0x2d0]
0x12ca0: int 0x21
0x12ca2: mov ah, 0x4e
0x12ca4: mov cx, 3
0x12ca7: lea dx, word ptr [bp + 0x2ba]
0x12cab: int 0x21
0x12cad: jae 0x12cb2
0x12caf: jmp 0x12d7d
0x12cb2: mov ax, word ptr [bp + 0x2e6]
0x12cb6: mov word ptr [bp + 0x2fc], ax
0x12cba: mov ax, word ptr [bp + 0x2e8]
0x12cbe: mov word ptr [bp + 0x2fe], ax
0x12cc2: mov ax, 0x4300
0x12cc5: lea dx, word ptr [bp + 0x2ee]
0x12cc9: int 0x21
0x12ccb: mov byte ptr [bp + 0x2fb], cl
0x12ccf: cmp word ptr [bp + 0x2ee], 0x434f
0x12cd5: jne 0x12ceb
2018-12-17T22:14:17.392081425Z 26 PC: 12ca2 | Set disk transfer address
2018-12-17T22:14:17.393085751Z 78 PC: 12cad | Find first file
2018-12-17T22:14:17.399064823Z 67 PC: 12ccb | Get or set file attributes
2018-12-17T22:14:17.404729044Z 67 PC: 12cf6 | Get or set file attributes
2018-12-17T22:14:17.421633999Z 61 PC: 12cff | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:14:17.428267442Z 63 PC: 12d10 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:14:17.434473626Z 66 PC: 12d25 | Move file pointer
2018-12-17T22:14:17.436569672Z 64 PC: 12e9c | Write file or device (Write 448 bytes on handle 5)
2018-12-17T22:14:17.444385731Z 66 PC: 12d46 | Move file pointer
2018-12-17T22:14:17.445619131Z 64 PC: 12d51 | Write file or device (Write 5 bytes on handle 5)
2018-12-17T22:14:17.452789173Z 87 PC: 12d61 | Get or set file date and time
2018-12-17T22:14:17.454154688Z 62 PC: 12d65 | Close file
2018-12-17T22:14:17.461968038Z 67 PC: 12d74 | Get or set file attributes
2018-12-17T22:14:17.472622418Z 26 PC: 12d84 | Set disk transfer address
2018-12-17T22:14:17.48060265Z 9 PC: 12a5f | Display string (Could not find end pointer)
2018-12-17T22:14:17.486029827Z 8 PC: 12a64 | Console input without echo