Sample viewer

vx.netlux.org/Virus.DOS.Devastator.636

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:54:32.506019714Z 44 PC: 12c34 | Get time 0x12c34: in al, 0x40
0x12c36: mov ah, al
0x12c38: in al, 0x40
0x12c3a: xor ax, cx
0x12c3c: xor dx, ax
0x12c3e: jmp 0x12c5c
0x12c40: push dx
0x12c41: push cx
0x12c42: push bx
0x12c43: in al, 0x40
0x12c45: add ax, 0x3cb9
0x12c48: mov dx, 0
0x12c4b: mov cx, 7
0x12c4e: shl ax, 1
0x12c50: shl dx, 1
0x12c52: mov bl, al
0x12c54: xor bl, dh
0x12c56: jns 0x12c5a
0x12c58: inc al
0x12c5a: loop 0x12c4e
2018-12-17T21:54:32.508352139Z 26 PC: 12a8e | Set disk transfer address
2018-12-17T21:54:32.509304808Z 71 PC: 12a98 | Get current directory
2018-12-17T21:54:32.511910396Z 78 PC: 12ab2 | Find first file
2018-12-17T21:54:32.51795296Z 61 PC: 12ac0 | Open file (Filename = 'SLEEP.COM')
2018-12-17T21:54:32.525154505Z 63 PC: 12ba0 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T21:54:32.531373141Z 66 PC: 12c9e | Move file pointer
2018-12-17T21:54:32.532646609Z 64 PC: 12c8d | Write file or device (Write 5 bytes on handle 5)
2018-12-17T21:54:32.535612489Z 66 PC: 12c9e | Move file pointer
2018-12-17T21:54:32.537268076Z 64 PC: 12c8d | Write file or device (Write 26 bytes on handle 5)
2018-12-17T21:54:32.539679557Z 64 PC: 12c8d | Write file or device (Write 610 bytes on handle 5)
2018-12-17T21:54:32.554843171Z 62 PC: 12bd6 | Close file
2018-12-17T21:54:32.56280369Z 79 PC: 12ab2 | Find next file
2018-12-17T21:54:32.565173851Z 61 PC: 12ac0 | Open file (Filename = 'PRINT.S')
2018-12-17T21:54:32.571869218Z 62 PC: 12bd6 | Close file
2018-12-17T21:54:32.573466911Z 79 PC: 12ab2 | Find next file
2018-12-17T21:54:32.575739288Z 61 PC: 12ac0 | Open file (Filename = 'PRINT.COM')
2018-12-17T21:54:32.58319752Z 63 PC: 12ba0 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T21:54:32.589419308Z 66 PC: 12c9e | Move file pointer
2018-12-17T21:54:32.590583458Z 64 PC: 12c8d | Write file or device (Write 5 bytes on handle 5)
2018-12-17T21:54:32.593456767Z 66 PC: 12c9e | Move file pointer
2018-12-17T21:54:32.595097871Z 64 PC: 12c8d | Write file or device (Write 26 bytes on handle 5)
2018-12-17T21:54:32.597616295Z 64 PC: 12c8d | Write file or device (Write 610 bytes on handle 5)
2018-12-17T21:54:32.606856424Z 62 PC: 12bd6 | Close file
2018-12-17T21:54:32.614609115Z 79 PC: 12ab2 | Find next file
2018-12-17T21:54:32.617009448Z 61 PC: 12ac0 | Open file (Filename = 'HELLO.COM')
2018-12-17T21:54:32.624453565Z 63 PC: 12ba0 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T21:54:32.630560325Z 66 PC: 12c9e | Move file pointer
2018-12-17T21:54:32.63169575Z 64 PC: 12c8d | Write file or device (Write 5 bytes on handle 5)
2018-12-17T21:54:32.634711906Z 66 PC: 12c9e | Move file pointer
2018-12-17T21:54:32.636395678Z 64 PC: 12c8d | Write file or device (Write 26 bytes on handle 5)
2018-12-17T21:54:32.649879212Z 64 PC: 12c8d | Write file or device (Write 610 bytes on handle 5)
2018-12-17T21:54:32.662405516Z 62 PC: 12bd6 | Close file
2018-12-17T21:54:32.667551575Z 59 PC: 12bea | Change current directory
2018-12-17T21:54:32.670041011Z 26 PC: 12bf1 | Set disk transfer address