Sample viewer

vx.netlux.org/Virus.DOS.Rajaat.RTFM.871

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:35:35.593920515Z 26 PC: 12a75 | Set disk transfer address
2018-12-17T22:35:35.596213004Z 78 PC: 12a7f | Find first file
2018-12-17T22:35:35.602959788Z 61 PC: 12a93 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:35:35.609815195Z 63 PC: 12aa1 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:35:35.620404154Z 66 PC: 12abe | Move file pointer
2018-12-17T22:35:35.623125928Z 87 PC: 12acc | Get or set file date and time
2018-12-17T22:35:35.626089777Z 44 PC: 12d66 | Get time 0x12d66: xor cx, dx
0x12d68: mov word ptr cs:[bp], cx
0x12d6d: mov ah, 0x2a
0x12d6f: int 0x21
0x12d71: mov cl, al
0x12d73: rcr dx, cl
0x12d75: not dx
0x12d77: sbb word ptr cs:[bp], dx
0x12d7c: ret
0x12d7d: push bx
0x12d7e: mov bx, word ptr cs:[bp]
0x12d83: in al, 0x40
0x12d85: xchg al, ah
0x12d87: in al, 0x40
0x12d89: xor ax, bx
0x12d8b: sbb ax, bx
0x12d8d: ror ax, 1
0x12d8f: mov word ptr cs:[bp], ax
0x12d94: pop bx
0x12d95: ret
2018-12-17T22:35:35.632400853Z 42 PC: 12d71 | Get date 0x12d71: mov cl, al
0x12d73: rcr dx, cl
0x12d75: not dx
0x12d77: sbb word ptr cs:[bp], dx
0x12d7c: ret
0x12d7d: push bx
0x12d7e: mov bx, word ptr cs:[bp]
0x12d83: in al, 0x40
0x12d85: xchg al, ah
0x12d87: in al, 0x40
0x12d89: xor ax, bx
0x12d8b: sbb ax, bx
0x12d8d: ror ax, 1
0x12d8f: mov word ptr cs:[bp], ax
0x12d94: pop bx
0x12d95: ret
0x12d96: pop bx
0x12d97: push dx
0x12d98: push sp
0x12d99: inc si
2018-12-17T22:35:35.637874519Z 64 PC: 12aec | Write file or device (Write 1101 bytes on handle 5)
2018-12-17T22:35:35.652817293Z 66 PC: 12af4 | Move file pointer
2018-12-17T22:35:35.654492936Z 64 PC: 12aff | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:35:35.662030292Z 87 PC: 12b05 | Get or set file date and time
2018-12-17T22:35:35.667884461Z 62 PC: 12b09 | Close file
2018-12-17T22:35:35.676345028Z 26 PC: 12a88 | Set disk transfer address