Sample viewer

vx.netlux.org/Virus.DOS.Bolek.1326

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:23:30.562953009Z 26 PC: 1376c | Set disk transfer address
2018-12-17T22:23:30.564891139Z 188 PC: 135b9 | UNKNOWN!
2018-12-17T22:23:30.566993243Z 42 PC: 9f8c9 | Get date 0x9f8c9: mov byte ptr cs:[0x439], dh
0x9f8ce: mov byte ptr cs:[0x43a], dl
0x9f8d3: mov byte ptr cs:[0x43b], al
0x9f8d7: cli
0x9f8d8: mov cx, cs
0x9f8da: xor ax, ax
0x9f8dc: mov ds, ax
0x9f8de: mov ax, word ptr [6]
0x9f8e1: mov word ptr cs:[0x44a], ax
0x9f8e5: mov ax, word ptr [0xe]
0x9f8e8: mov word ptr cs:[0x44c], ax
0x9f8ec: mov ax, word ptr [0x26]
0x9f8ef: mov word ptr cs:[0x4c1], ax
0x9f8f3: mov ax, word ptr [0x24]
0x9f8f6: mov word ptr cs:[0x4bf], ax
0x9f8fa: mov ax, word ptr [0x56]
0x9f8fd: mov word ptr cs:[0x4d3], ax
0x9f901: mov ax, word ptr [0x54]
0x9f904: mov word ptr cs:[0x4d1], ax
0x9f908: mov ax, word ptr [0x86]
2018-12-17T22:23:30.570169418Z 78 PC: 9f85d | Find first file
2018-12-17T22:23:30.577576152Z 47 PC: 9f863 | Get disk transfer address
2018-12-17T22:23:30.580353701Z 67 PC: 9f702 | Get or set file attributes
2018-12-17T22:23:30.586971189Z 67 PC: 9f70a | Get or set file attributes
2018-12-17T22:23:30.605157535Z 61 PC: 9f71a | Open file (Filename = 'TEST.EXE')
2018-12-17T22:23:30.622313171Z 87 PC: 9f728 | Get or set file date and time
2018-12-17T22:23:30.624367828Z 66 PC: 9fa1d | Move file pointer
2018-12-17T22:23:30.626261087Z 66 PC: 9f768 | Move file pointer
2018-12-17T22:23:30.62941012Z 63 PC: 9fa25 | Read file or device (Read 16 bytes on handle 5)
2018-12-17T22:23:30.633333464Z 87 PC: 9f82a | Get or set file date and time
2018-12-17T22:23:30.635563333Z 62 PC: 9f82e | Close file
2018-12-17T22:23:30.647842503Z 67 PC: 9f836 | Get or set file attributes
2018-12-17T22:23:30.659483873Z 79 PC: 9f85d | Find next file
2018-12-17T22:23:30.662822743Z 26 PC: 9fa4a | Set disk transfer address
2018-12-17T22:23:30.665081727Z 9 PC: 133f2 | Display string (Could not find end pointer)
2018-12-17T22:23:30.670213726Z 76 PC: 133f8 | Terminate with return code (Return code = '0')