Sample viewer

vx.netlux.org/Virus.DOS.Dynamics.1400

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:23:38.015221156Z 53 PC: 19c7b | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:23:38.016817473Z 42 PC: 19ccd | Get date 0x19ccd: mov byte ptr [0x2ed], dl
0x19cd1: mov byte ptr [0x2ee], al
0x19cd4: mov ax, 0x3516
0x19cd7: int 0x21
0x19cd9: mov word ptr [0x1bc], bx
0x19cdd: mov word ptr [0x1be], es
0x19ce1: mov ax, word ptr [0x1e4]
0x19ce4: add ax, 0x10
0x19ce7: mov es, ax
0x19ce9: mov word ptr [0x1c6], ax
0x19cec: mov word ptr [0x1c4], 0xd8
0x19cf2: xor si, si
0x19cf4: xor di, di
0x19cf6: mov cx, 0x2bc
0x19cf9: rep movsd dword ptr es:[di], dword ptr [si]
0x19cfb: xor si, si
0x19cfd: xor di, di
0x19cff: mov cx, 0x2bc
0x19d02: repe cmpsd dword ptr [si], dword ptr es:[di]
0x19d04: pushf
2018-12-17T22:23:38.018531876Z 53 PC: 19cd9 | Get interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-17T22:23:38.019654044Z 37 PC: 12b2e | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:23:38.021450329Z 74 PC: 12b42 | Reallocate memory
2018-12-17T22:23:38.022882284Z 67 PC: 12de9 | Get or set file attributes
2018-12-17T22:23:38.027682301Z 67 PC: 12df6 | Get or set file attributes
2018-12-17T22:23:38.042005927Z 61 PC: 12dfd | Open file (Filename = '!5! ')
2018-12-17T22:23:38.048780046Z 87 PC: 12e0b | Get or set file date and time
2018-12-17T22:23:38.050475341Z 63 PC: 12e3e | Read file or device (Read 24 bytes on handle 5)
2018-12-17T22:23:38.053827364Z 62 PC: 12e32 | Close file
2018-12-17T22:23:38.055614005Z 75 PC: 12b7c | Execute program
2018-12-17T22:23:38.063440569Z 49 PC: 12bbe | Terminate and stay resident (Return code = '0' | Memory size = '106')