Sample viewer

vx.netlux.org/Virus.DOS.Barrotes.1447

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:33:10.465041435Z 238 PC: 222cb | UNKNOWN!
2018-12-17T22:33:10.467132653Z 53 PC: 222d9 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:33:10.469070547Z 54 PC: 9f73c | Get free disk space
2018-12-17T22:33:10.518526725Z 53 PC: 9f75e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:33:10.520720085Z 67 PC: 9f789 | Get or set file attributes
2018-12-17T22:33:10.531875542Z 67 PC: 9f795 | Get or set file attributes
2018-12-17T22:33:10.950604751Z 61 PC: 9f79f | Open file (Filename = '')
2018-12-17T22:33:10.959030426Z 87 PC: 9f7af | Get or set file date and time
2018-12-17T22:33:10.961257054Z 66 PC: 9fa28 | Move file pointer
2018-12-17T22:33:10.963160005Z 63 PC: 9fa19 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:33:10.970869443Z 66 PC: 9f934 | Move file pointer
2018-12-17T22:33:10.972998686Z 63 PC: 9fa19 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:33:10.979847812Z 66 PC: 9fa28 | Move file pointer
2018-12-17T22:33:10.982017682Z 63 PC: 9f970 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:33:10.996834604Z 66 PC: 9fa37 | Move file pointer
2018-12-17T22:33:10.998279838Z 64 PC: 9f993 | Write file or device (Write 1447 bytes on handle 5)
2018-12-17T22:33:11.009323043Z 66 PC: 9fa28 | Move file pointer
2018-12-17T22:33:11.011294144Z 64 PC: 9f9b9 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:33:11.014941858Z 87 PC: 9f9cd | Get or set file date and time
2018-12-17T22:33:11.017156542Z 62 PC: 9f9d1 | Close file
2018-12-17T22:33:11.025843408Z 67 PC: 9f9e5 | Get or set file attributes
2018-12-17T22:33:11.03747872Z 42 PC: 2238b | Get date 0x2238b: cmp dl, 0x22
0x2238e: jne 0x223b0
0x22390: xor ax, ax
0x22392: mov es, ax
0x22394: lea dx, word ptr [0x4ec]
0x22398: mov word ptr es:[0x70], dx
0x2239d: mov word ptr es:[0x72], ds
0x223a2: mov dx, 0x80
0x223a5: mov cx, 1
0x223a8: mov ax, 0x301
0x223ab: mov bx, 0x100
0x223ae: int 0x13
0x223b0: cmp byte ptr cs:[si + 0x73], 1
0x223b5: je 0x223c9
0x223b7: push cs
0x223b8: push cs
0x223b9: pop ds
0x223ba: pop es
0x223bb: add si, 4
0x223be: mov di, 0x100
2018-12-17T22:33:11.040409507Z 9 PC: 12a85 | Display string (String= ' ')
2018-12-17T22:33:11.047515731Z 0 PC: 12a89 | Program terminate