Sample viewer

vx.netlux.org/Virus.DOS.Leprosy.TheThing.554

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:18:43.449688196Z 48 PC: 12bdc | Get DOS version
2018-12-17T22:18:43.452160747Z 44 PC: 12be4 | Get time 0x12be4: add dh, cl
0x12be6: mov word ptr [0x102], dx
0x12bea: mov dx, 0x1ec
0x12bed: mov ah, 0x1a
0x12bef: int 0x21
0x12bf1: mov ah, 0x19
0x12bf3: int 0x21
0x12bf5: mov dl, al
0x12bf7: inc dl
0x12bf9: mov ah, 0x47
0x12bfb: mov si, 0x24b
0x12bfe: int 0x21
0x12c00: mov dx, 0x1ea
0x12c03: mov ah, 0x3b
0x12c05: int 0x21
0x12c07: mov cx, 0x13
0x12c0a: mov dx, 0x1e2
0x12c0d: mov ah, 0x4e
0x12c0f: int 0x21
0x12c11: cmp ax, 0x12
2018-12-17T22:18:43.454588746Z 26 PC: 12bf1 | Set disk transfer address
2018-12-17T22:18:43.45593304Z 25 PC: 12bf5 | Get default drive
2018-12-17T22:18:43.46537362Z 71 PC: 12c00 | Get current directory
2018-12-17T22:18:43.475975292Z 59 PC: 12c07 | Change current directory
2018-12-17T22:18:43.488332545Z 78 PC: 12c11 | Find first file
2018-12-17T22:18:43.494443558Z 76 PC: 12d32 | Terminate with return code (Return code = '0')