Sample viewer

vx.netlux.org/Virus.DOS.Nobody.402

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:30:29.176209311Z 44 PC: 224b8 | Get time 0x224b8: mov al, dh
0x224ba: add al, dl
0x224bc: stosb byte ptr es:[di], al
0x224bd: mov si, 0xfb26
0x224c0: mov di, 0x100
0x224c3: movsw word ptr es:[di], word ptr [si]
0x224c4: movsb byte ptr es:[di], byte ptr [si]
0x224c5: mov ah, 0x1a
0x224c7: mov dx, 0xff00
0x224ca: int 0x21
0x224cc: mov ah, 0x4e
0x224ce: mov dx, si
0x224d0: mov cx, 0x27
0x224d3: int 0x21
0x224d5: jae 0x224da
0x224d7: jmp 0x225c6
0x224da: mov ax, word ptr [0xff1c]
0x224dd: or ax, ax
0x224df: jne 0x2252f
0x224e1: mov ax, word ptr [0xff1a]
2018-12-17T22:30:29.178940629Z 26 PC: 224cc | Set disk transfer address
2018-12-17T22:30:29.180053805Z 78 PC: 224d5 | Find first file
2018-12-17T22:30:29.185849635Z 61 PC: 22502 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:30:29.192682434Z 63 PC: 22510 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:30:29.198873474Z 62 PC: 22514 | Close file
2018-12-17T22:30:29.20046416Z 61 PC: 2253e | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:30:29.206934736Z 63 PC: 2254f | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:30:29.209678501Z 62 PC: 22553 | Close file
2018-12-17T22:30:29.211614508Z 67 PC: 2257e | Get or set file attributes
2018-12-17T22:30:29.227334826Z 61 PC: 22586 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:30:29.234215812Z 64 PC: 22594 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:30:29.236775881Z 66 PC: 2259d | Move file pointer
2018-12-17T22:30:29.238043439Z 64 PC: 225a7 | Write file or device (Write 402 bytes on handle 5)
2018-12-17T22:30:29.245858804Z 87 PC: 225b4 | Get or set file date and time
2018-12-17T22:30:29.247829707Z 62 PC: 225b8 | Close file
2018-12-17T22:30:29.255077241Z 67 PC: 225c6 | Get or set file attributes
2018-12-17T22:30:29.265280912Z 26 PC: 225cd | Set disk transfer address