Sample viewer

vx.netlux.org/Virus.DOS.BlackJec.374

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:31:37.396816342Z 42 PC: 12a7c | Get date 0x12a7c: mov word ptr [0xf2], dx
0x12a80: mov word ptr [0xf4], cx
0x12a84: stc
0x12a85: lea dx, word ptr [0x26d]
0x12a89: mov ah, 0x4e
0x12a8b: mov cx, 0x20
0x12a8e: int 0x21
0x12a90: or ax, ax
0x12a92: je 0x12a97
0x12a94: jmp 0x12b6c
0x12a97: mov ah, 0x2f
0x12a99: int 0x21
0x12a9b: mov ax, word ptr es:[bx + 0x1a]
0x12a9f: mov word ptr [0xfc], ax
0x12aa2: add bx, 0x1e
0x12aa5: mov word ptr [0xfe], bx
0x12aa9: mov ax, 0x4f43
0x12aac: sub ax, word ptr [0x9e]
0x12ab0: jne 0x12ab5
0x12ab2: jmp 0x12b60
2018-12-17T22:31:37.40041062Z 78 PC: 12a90 | Find first file
2018-12-17T22:31:37.406560896Z 47 PC: 12a9b | Get disk transfer address
2018-12-17T22:31:37.407970125Z 43 PC: 12af1 | Set date
2018-12-17T22:31:37.412027009Z 61 PC: 12af9 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:31:37.430394453Z 63 PC: 12b07 | Read file or device (Read 407 bytes on handle 5)
2018-12-17T22:31:37.436931286Z 60 PC: 12b44 | Create or truncate file
2018-12-17T22:31:37.457091584Z 64 PC: 12b56 | Write file or device (Write 781 bytes on handle 6)
2018-12-17T22:31:37.466197206Z 62 PC: 12b5a | Close file
2018-12-17T22:31:37.474755844Z 79 PC: 12b65 | Find next file
2018-12-17T22:31:37.478068509Z 47 PC: 12a9b | Get disk transfer address
2018-12-17T22:31:37.479751583Z 43 PC: 12af1 | Set date
2018-12-17T22:31:37.483544107Z 61 PC: 12af9 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:31:37.494766665Z 63 PC: 12b07 | Read file or device (Read 27 bytes on handle 6)
2018-12-17T22:31:37.501593951Z 60 PC: 12b44 | Create or truncate file
2018-12-17T22:31:37.514343757Z 64 PC: 12b56 | Write file or device (Write 401 bytes on handle 7)
2018-12-17T22:31:37.518325261Z 62 PC: 12b5a | Close file
2018-12-17T22:31:37.527296751Z 79 PC: 12b65 | Find next file
2018-12-17T22:31:37.530099089Z 47 PC: 12a9b | Get disk transfer address
2018-12-17T22:31:37.531465675Z 43 PC: 12af1 | Set date
2018-12-17T22:31:37.53885731Z 61 PC: 12af9 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:31:37.550139183Z 63 PC: 12b07 | Read file or device (Read 92 bytes on handle 7)
2018-12-17T22:31:37.556685726Z 60 PC: 12b44 | Create or truncate file
2018-12-17T22:31:37.569479333Z 64 PC: 12b56 | Write file or device (Write 466 bytes on handle 8)
2018-12-17T22:31:37.573766038Z 62 PC: 12b5a | Close file
2018-12-17T22:31:37.581812367Z 43 PC: 12b78 | Set date
2018-12-17T22:31:37.586926113Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')