Sample viewer

vx.netlux.org/Virus.DOS.Tricky.236

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:24:57.204915253Z 26 PC: 1a5b2 | Set disk transfer address
2018-12-17T22:24:57.208910384Z 71 PC: 1a5be | Get current directory
2018-12-17T22:24:57.211798004Z 78 PC: 1a5da | Find first file
2018-12-17T22:24:57.217677353Z 61 PC: 1a5f5 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:24:57.230117722Z 63 PC: 1a606 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:24:57.236277044Z 66 PC: 1a625 | Move file pointer
2018-12-17T22:24:57.237555019Z 64 PC: 1a637 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:24:57.251641203Z 66 PC: 1a640 | Move file pointer
2018-12-17T22:24:57.253959723Z 64 PC: 1a64d | Write file or device (Write 236 bytes on handle 5)
2018-12-17T22:24:57.268842288Z 62 PC: 1a651 | Close file
2018-12-17T22:24:57.27797762Z 59 PC: 1a65b | Change current directory
2018-12-17T22:24:57.282297752Z 59 PC: 1a665 | Change current directory
2018-12-17T22:24:57.284256601Z 26 PC: 1a66e | Set disk transfer address
2018-12-17T22:24:57.285862948Z 48 PC: 1a0e4 | Get DOS version
2018-12-17T22:24:57.288470788Z 44 PC: 17144 | Get time 0x17144: pop bp
0x17145: pop di
0x17146: pop si
0x17147: pop bx
0x17148: ret
0x17149: mov bx, 1
0x1714c: mov ah, 0x40
0x1714e: call 0x2711d
0x17151: jb 0x17157
0x17153: cmp ax, cx
0x17155: je 0x17148
0x17157: mov ax, 0x468c
0x1715a: jmp 0x1322d
0x1715d: mov bx, 2
0x17160: jmp 0x1714c
0x17162: sub si, si
0x17164: mov dx, bx
0x17166: call 0x27107
0x17169: jb 0x17157
0x1716b: xchg ax, bx
2018-12-17T22:24:57.290615482Z 42 PC: 17144 | Get date 0x17144: pop bp
0x17145: pop di
0x17146: pop si
0x17147: pop bx
0x17148: ret
0x17149: mov bx, 1
0x1714c: mov ah, 0x40
0x1714e: call 0x2711d
0x17151: jb 0x17157
0x17153: cmp ax, cx
0x17155: je 0x17148
0x17157: mov ax, 0x468c
0x1715a: jmp 0x1322d
0x1715d: mov bx, 2
0x17160: jmp 0x1714c
0x17162: sub si, si
0x17164: mov dx, bx
0x17166: call 0x27107
0x17169: jb 0x17157
0x1716b: xchg ax, bx
2018-12-17T22:24:57.292646648Z 25 PC: 17144 | Get default drive
2018-12-17T22:24:57.294508751Z 71 PC: 17144 | Get current directory
2018-12-17T22:24:57.300318696Z 64 PC: 17144 | Write file or device (Write 57 bytes on handle 1)
2018-12-17T22:24:57.306597583Z 64 PC: 17144 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:24:57.309885996Z 64 PC: 17144 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:24:57.314477418Z 64 PC: 17144 | Write file or device (Write 77 bytes on handle 1)
2018-12-17T22:24:57.321541342Z 64 PC: 17144 | Write file or device (Write 54 bytes on handle 1)
2018-12-17T22:24:57.333127418Z 64 PC: 17144 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:24:57.339337895Z 64 PC: 17144 | Write file or device (Write 81 bytes on handle 1)
2018-12-17T22:24:57.346017351Z 64 PC: 17144 | Write file or device (Write 75 bytes on handle 1)
2018-12-17T22:24:57.354190466Z 64 PC: 17144 | Write file or device (Write 52 bytes on handle 1)
2018-12-17T22:24:57.361652241Z 64 PC: 17144 | Write file or device (Write 54 bytes on handle 1)
2018-12-17T22:24:57.368128952Z 64 PC: 17144 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:24:57.377304427Z 64 PC: 17144 | Write file or device (Write 74 bytes on handle 1)
2018-12-17T22:24:57.388334997Z 64 PC: 17144 | Write file or device (Write 13 bytes on handle 1)
2018-12-17T22:24:57.393000995Z 64 PC: 17144 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:24:57.396615628Z 64 PC: 17144 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:24:57.398633429Z 64 PC: 17144 | Write file or device (Write 70 bytes on handle 1)
2018-12-17T22:24:57.403005954Z 64 PC: 17144 | Write file or device (Write 61 bytes on handle 1)
2018-12-17T22:24:57.408088871Z 64 PC: 17144 | Write file or device (Write 34 bytes on handle 1)
2018-12-17T22:24:57.41208638Z 64 PC: 17144 | Write file or device (Write 34 bytes on handle 1)
2018-12-17T22:24:57.415157888Z 64 PC: 17144 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:24:57.41753922Z 76 PC: 17144 | Terminate with return code (Return code = '1')