Sample viewer

vx.netlux.org/Virus.DOS.Chameleon.1948

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:32:30.320503719Z 48 PC: 12cae | Get DOS version
2018-12-17T22:32:30.322036356Z 47 PC: 12cbc | Get disk transfer address
2018-12-17T22:32:30.323382355Z 26 PC: 12cd1 | Set disk transfer address
2018-12-17T22:32:30.324340628Z 78 PC: 12d55 | Find first file
2018-12-17T22:32:30.329189243Z 67 PC: 12d95 | Get or set file attributes
2018-12-17T22:32:30.3331523Z 67 PC: 12da6 | Get or set file attributes
2018-12-17T22:32:30.349142489Z 61 PC: 12db1 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:32:30.36050746Z 87 PC: 12dbe | Get or set file date and time
2018-12-17T22:32:30.361891507Z 63 PC: 12dd1 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:30.368308515Z 66 PC: 12ded | Move file pointer
2018-12-17T22:32:30.370623169Z 44 PC: 12e1b | Get time 0x12e1b: xor dx, cx
0x12e1d: int3
0x12e1e: dec si
0x12e1f: lds cx, ptr [si + 0xe2]
0x12e23: int3
0x12e24: xchg ax, di
0x12e25: movsb byte ptr es:[di], byte ptr [si]
0x12e26: retf 0xfecc
0x12e29: ja 0x12dbf
0x12e2b: loop 0x12e2d
0x12e2d: int3
0x12e2e: inc cx
0x12e2f: enter -0x1daa, -0x18
0x12e33: popaw
0x12e34: add cx, word ptr [bp + si - 0x1dba]
0x12e38: and al, 3
0x12e3a: cmp al, 3
0x12e3c: je 0x12e32
0x12e3e: push ax
0x12e3f: ror al, 1
2018-12-17T22:32:30.376063587Z 64 PC: 13504 | Write file or device (Write 2020 bytes on handle 5)
2018-12-17T22:32:30.384932831Z 66 PC: 1311a | Move file pointer
2018-12-17T22:32:30.386962247Z 64 PC: 1312b | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:30.393387185Z 87 PC: 1313c | Get or set file date and time
2018-12-17T22:32:30.394889138Z 62 PC: 13140 | Close file
2018-12-17T22:32:30.403266326Z 67 PC: 1314e | Get or set file attributes
2018-12-17T22:32:30.414373014Z 26 PC: 13159 | Set disk transfer address