Sample viewer

vx.netlux.org/Virus.DOS.MemLapse.296

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:30:10.747144662Z 26 PC: 12a72 | Set disk transfer address
2018-12-17T22:30:10.749462065Z 78 PC: 12a7b | Find first file
2018-12-17T22:30:10.755811475Z 47 PC: 12a86 | Get disk transfer address
2018-12-17T22:30:10.757295569Z 79 PC: 12a7b | Find next file
2018-12-17T22:30:10.760083099Z 47 PC: 12a86 | Get disk transfer address
2018-12-17T22:30:10.762619116Z 67 PC: 12aae | Get or set file attributes
2018-12-17T22:30:10.78242525Z 61 PC: 12abc | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:30:10.789764391Z 63 PC: 12ad5 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:30:10.797021135Z 66 PC: 12ae7 | Move file pointer
2018-12-17T22:30:10.798492075Z 87 PC: 12aec | Get or set file date and time
2018-12-17T22:30:10.799748029Z 64 PC: 12aff | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:30:10.805736845Z 66 PC: 12b08 | Move file pointer
2018-12-17T22:30:10.808102134Z 64 PC: 12b13 | Write file or device (Write 296 bytes on handle 5)
2018-12-17T22:30:10.823357621Z 44 PC: 12b18 | Get time 0x12b18: mov cl, dl
0x12b1a: add cl, al
0x12b1c: ror cl, 1
0x12b1e: xor ch, ch
0x12b20: xor dx, dx
0x12b22: mov ah, 0x40
0x12b24: int 0x21
0x12b26: mov cx, word ptr [0x22c]
0x12b2a: mov dx, word ptr [0x22a]
0x12b2e: mov ax, 0x5701
0x12b31: int 0x21
0x12b33: mov ah, 0x3e
0x12b35: int 0x21
0x12b37: mov ah, 0x4f
0x12b39: jmp 0x12a75
0x12b3c: mov ah, 0x1a
0x12b3e: mov dx, 0x80
0x12b41: int 0x21
0x12b43: mov bx, 0x102
0x12b46: pop word ptr [bx]
2018-12-17T22:30:10.826718161Z 64 PC: 12b26 | Write file or device (Write 35 bytes on handle 5)
2018-12-17T22:30:10.82989664Z 87 PC: 12b33 | Get or set file date and time
2018-12-17T22:30:10.831869533Z 62 PC: 12b37 | Close file
2018-12-17T22:30:10.847417328Z 79 PC: 12a7b | Find next file
2018-12-17T22:30:10.850606995Z 26 PC: 12b43 | Set disk transfer address