Sample viewer

vx.netlux.org/Virus.DOS.Slowly.1249

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:16:36.192193432Z 37 PC: 23678 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:16:36.193909871Z 25 PC: 2367c | Get default drive
2018-12-17T22:16:36.195127089Z 71 PC: 2368c | Get current directory
2018-12-17T22:16:36.197294431Z 26 PC: 23695 | Set disk transfer address
2018-12-17T22:16:36.199339913Z 14 PC: 236da | Set default drive (Drive = 'C')
2018-12-17T22:16:36.200450457Z 59 PC: 236e1 | Change current directory
2018-12-17T22:16:36.204370759Z 42 PC: 236e8 | Get date 0x236e8: cmp byte ptr [0xfe95], dl
0x236ec: mov byte ptr [0xfe95], dl
0x236f0: pop dx
0x236f1: jbe 0x2370d
0x236f3: mov ah, 0x5a
0x236f5: xor cx, cx
0x236f7: int 0x21
0x236f9: jb 0x23695
0x236fb: xchg ax, bx
0x236fc: mov byte ptr [si + 0x15], 0x27
0x23700: mov ah, 0x40
0x23702: mov dx, 0xfeb0
0x23705: mov cx, 0x20
0x23708: int 0x21
0x2370a: call 0x23a17
0x2370d: mov ah, 0x4e
0x2370f: mov cx, 0x27
0x23712: mov dx, 0xfe85
0x23715: int 0x21
0x23717: jb 0x23695
2018-12-17T22:16:36.206254053Z 90 PC: 236f9 | Create unique file
2018-12-17T22:16:37.214590688Z 64 PC: 2370a | Write file or device (Write 32 bytes on handle 5)
2018-12-17T22:16:37.223100659Z 87 PC: 23a24 | Get or set file date and time
2018-12-17T22:16:37.225041406Z 62 PC: 23a28 | Close file
2018-12-17T22:16:37.242824662Z 67 PC: 23a35 | Get or set file attributes
2018-12-17T22:16:37.248947819Z 78 PC: 23717 | Find first file