Sample viewer

vx.netlux.org/Virus.DOS.Gandalf.444

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:24:23.527185152Z 26 PC: 22716 | Set disk transfer address
2018-12-17T22:24:23.529336315Z 78 PC: 22730 | Find first file
2018-12-17T22:24:23.535213485Z 67 PC: 22744 | Get or set file attributes
2018-12-17T22:24:23.540709374Z 67 PC: 22750 | Get or set file attributes
2018-12-17T22:24:23.560972915Z 61 PC: 22757 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:24:23.567804249Z 63 PC: 22765 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:24:23.574053114Z 66 PC: 22777 | Move file pointer
2018-12-17T22:24:23.576726845Z 44 PC: 22832 | Get time 0x22832: xor dx, cx
0x22834: pop ax
0x22835: xor dx, ax
0x22837: shr cl, 1
0x22839: jb 0x22841
0x2283b: xor word ptr [0xfdc2], 0x2d02
0x22841: ror cl, 1
0x22843: jb 0x2284b
0x22845: xor word ptr [0xfef2], 0x1b02
0x2284b: rcr cl, 1
0x2284d: jb 0x22855
0x2284f: xor word ptr [0xfef5], 0x1202
0x22855: shr cl, 1
0x22857: jb 0x2285e
0x22859: xor byte ptr [0xff66], 0x28
0x2285e: mov si, 0xfeb2
0x22861: lodsw ax, word ptr [si]
0x22862: ror dx, 1
0x22864: xchg ax, di
0x22865: jb 0x22872
2018-12-17T22:24:23.579223627Z 64 PC: 2289e | Write file or device (Write 444 bytes on handle 5)
2018-12-17T22:24:23.587914534Z 66 PC: 22788 | Move file pointer
2018-12-17T22:24:23.589612968Z 64 PC: 22792 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:24:23.596553763Z 87 PC: 227a0 | Get or set file date and time
2018-12-17T22:24:23.598075124Z 62 PC: 227a4 | Close file
2018-12-17T22:24:23.60569427Z 67 PC: 227a9 | Get or set file attributes
2018-12-17T22:24:23.615937502Z 26 PC: 227b0 | Set disk transfer address
2018-12-17T22:24:23.617198718Z 76 PC: 12a45 | Terminate with return code (Return code = '76')