Sample viewer

vx.netlux.org/Virus.DOS.Lion.996

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:26:38.170493993Z 47 PC: 12a5f | Get disk transfer address
2018-12-17T22:26:38.172272439Z 26 PC: 12a70 | Set disk transfer address
2018-12-17T22:26:38.173251057Z 42 PC: 12a84 | Get date 0x12a84: mov si, 0x48c
0x12a87: cmp word ptr [bp + si], cx
0x12a89: jg 0x12aa8
0x12a8b: jl 0x12aa1
0x12a8d: cmp byte ptr [bp + si - 1], dh
0x12a90: jg 0x12aa8
0x12a92: jl 0x12a9c
0x12a94: cmp byte ptr [bp + si - 2], dl
0x12a97: jg 0x12aa8
0x12a99: jmp 0x12aa1
0x12a9b: nop
0x12a9c: cmp byte ptr [bp + si - 2], dl
0x12a9f: jg 0x12aa8
0x12aa1: mov si, 0x534
0x12aa4: mov word ptr [bp + si], 1
0x12aa8: mov ah, 0x4e
0x12aaa: mov cx, 0x11
0x12aad: mov dx, 0x4e2
0x12ab0: add dx, bp
0x12ab2: int 0x21
2018-12-17T22:26:38.175401651Z 78 PC: 12ab4 | Find first file
2018-12-17T22:26:38.181460554Z 78 PC: 12bdc | Find first file
2018-12-17T22:26:38.186981101Z 44 PC: 12d7f | Get time 0x12d7f: mov bx, 0xd
0x12d82: xor ax, ax
0x12d84: mov al, dh
0x12d86: div bl
0x12d88: or ah, ah
0x12d8a: je 0x12d96
0x12d8c: xor ax, ax
0x12d8e: mov al, cl
0x12d90: div bl
0x12d92: or ah, ah
0x12d94: jne 0x12dbf
0x12d96: lea dx, word ptr [bp + 0x495]
0x12d9a: mov si, dx
0x12d9c: mov di, dx
0x12d9e: mov cx, 0x21
0x12da1: lodsw ax, word ptr [si]
0x12da2: xor ax, 0xffff
0x12da5: stosw word ptr es:[di], ax
0x12da6: loop 0x12da1
0x12da8: mov ah, 9
2018-12-17T22:26:38.189371524Z 26 PC: 12bb3 | Set disk transfer address