Sample viewer

vx.netlux.org/Virus.DOS.Amz.801

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:38:34.344862732Z 26 PC: 15094 | Set disk transfer address
2018-12-17T22:38:34.347255968Z 71 PC: 150af | Get current directory
2018-12-17T22:38:34.35032071Z 59 PC: 150b6 | Change current directory
2018-12-17T22:38:34.354608815Z 78 PC: 150d4 | Find first file
2018-12-17T22:38:34.367468771Z 79 PC: 150f6 | Find next file
2018-12-17T22:38:34.372160606Z 79 PC: 150f6 | Find next file
2018-12-17T22:38:34.375512017Z 79 PC: 150f6 | Find next file
2018-12-17T22:38:34.380190537Z 79 PC: 150f6 | Find next file
2018-12-17T22:38:34.3845361Z 79 PC: 150f6 | Find next file
2018-12-17T22:38:34.387598557Z 79 PC: 150f6 | Find next file
2018-12-17T22:38:34.390655805Z 79 PC: 150f6 | Find next file
2018-12-17T22:38:34.394468694Z 79 PC: 150f6 | Find next file
2018-12-17T22:38:34.397172195Z 79 PC: 150f6 | Find next file
2018-12-17T22:38:34.399726816Z 78 PC: 15166 | Find first file
2018-12-17T22:38:34.410541751Z 78 PC: 15166 | Find first file
2018-12-17T22:38:34.421228365Z 67 PC: 1537e | Get or set file attributes
2018-12-17T22:38:34.439126288Z 61 PC: 151ad | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:38:34.447710002Z 63 PC: 151bc | Read file or device (Read 24 bytes on handle 5)
2018-12-17T22:38:34.455107402Z 66 PC: 15288 | Move file pointer
2018-12-17T22:38:34.45685877Z 64 PC: 152a3 | Write file or device (Write 19 bytes on handle 5)
2018-12-17T22:38:34.460227985Z 66 PC: 152ac | Move file pointer
2018-12-17T22:38:34.462741167Z 64 PC: 152bd | Write file or device (Write 810 bytes on handle 5)
2018-12-17T22:38:34.471762535Z 87 PC: 152ca | Get or set file date and time
2018-12-17T22:38:34.473644408Z 62 PC: 152ce | Close file
2018-12-17T22:38:34.48241274Z 67 PC: 1537e | Get or set file attributes
2018-12-17T22:38:34.493188091Z 59 PC: 152e0 | Change current directory
2018-12-17T22:38:34.497606912Z 42 PC: 152e4 | Get date 0x152e4: cmp dx, word ptr [0x3dd]
0x152e8: jne 0x15318
0x152ea: mov ah, 0x2c
0x152ec: int 0x21
0x152ee: cmp ch, byte ptr [0x3df]
0x152f2: jb 0x15318
0x152f4: mov cx, 0xc8
0x152f7: xor dx, dx
0x152f9: mov al, 0x19
0x152fb: cmp al, 1
0x152fd: jne 0x15301
0x152ff: xor al, al
0x15301: cmp al, 0xff
0x15303: jne 0x15307
0x15305: mov al, 1
0x15307: push ax
0x15308: push cx
0x15309: int 0x26
0x1530b: add sp, 2
0x1530e: pop cx
2018-12-17T22:38:34.501371872Z 43 PC: 13469 | Set date
2018-12-17T22:38:34.502962026Z 53 PC: 14b5a | Get interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:38:34.50482287Z 53 PC: 14004 | Get interrupt vector (Interrupt = '103' AKA 'Set handle count')
2018-12-17T22:38:34.507910324Z 74 PC: 99097 | Reallocate memory
2018-12-17T22:38:34.509532619Z 72 PC: 990a0 | Allocate memory
2018-12-17T22:38:34.514013426Z 72 PC: 990a7 | Allocate memory
2018-12-17T22:38:34.516294041Z 85 PC: 990b5 | Create program PSP
2018-12-17T22:38:34.518593471Z 61 PC: 990f5 | Open file (Filename = '_'\.:SQ���C��tQW�[%�')
2018-12-17T22:38:34.524989636Z 9 PC: 98efe | Display string (Could not find end pointer)
2018-12-17T22:38:34.53499125Z 9 PC: 98f16 | Display string (String= 'DV.EXE')
2018-12-17T22:38:34.537547804Z 9 PC: 98f1d | Display string (String= ' Exiting ... ')
2018-12-17T22:38:34.54299448Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')
2018-12-17T22:38:34.546466819Z 76 PC: 12ae3 | Terminate with return code (Return code = '0')