Sample viewer

vx.netlux.org/Virus.DOS.Slovakia.Silvia5

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:41:06.535234729Z 42 PC: 140cb | Get date 0x140cb: ret
0x140cc: lea si, word ptr [di]
0x140ce: jle 0x1414b
0x140d0: xor byte ptr [di + 0x7cb7], bl
0x140d4: neg dh
0x140d6: sub byte ptr [bx + di + 0x2e04], ch
0x140da: leave
0x140db: inc si
0x140dc: retf 0x9e3
0x140df: mov ch, al
0x140e1: dec ax
0x140e2: mov ax, word ptr [0xaa20]
0x140e5: mov sp, word ptr [bx + si + 0xa61]
0x140e9: mov ah, byte ptr [0xa62]
0x140ed: add al, ah
0x140ef: mov byte ptr [0xa61], al
0x140f2: inc byte ptr [0xa62]
0x140f6: xor ah, ah
0x140f8: ret
0x140f9: jns 0x1416e
2018-12-17T22:41:06.538247438Z 37 PC: 140cb | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:06.54125687Z 47 PC: 140cb | Get disk transfer address
2018-12-17T22:41:06.546420198Z 26 PC: 140cb | Set disk transfer address
2018-12-17T22:41:06.548921346Z 71 PC: 140cb | Get current directory
2018-12-17T22:41:06.556066586Z 78 PC: 140cb | Find first file
2018-12-17T22:41:06.571438588Z 86 PC: 140cb | Rename file
2018-12-17T22:41:06.916587712Z 67 PC: 140cb | Get or set file attributes
2018-12-17T22:41:06.928961653Z 67 PC: 140cb | Get or set file attributes
2018-12-17T22:41:06.942517644Z 61 PC: 140cb | Open file (Filename = 'C:\DOS\ATTRIB.EX@')
2018-12-17T22:41:06.955683231Z 87 PC: 140cb | Get or set file date and time
2018-12-17T22:41:06.959834168Z 63 PC: 140cb | Read file or device (Read 24 bytes on handle 5)
2018-12-17T22:41:06.969246286Z 66 PC: 140cb | Move file pointer
2018-12-17T22:41:06.974506765Z 64 PC: 140cb | Write file or device (Write 40 bytes on handle 5)
2018-12-17T22:41:06.991141119Z 64 PC: 140cb | Write file or device (Write 2494 bytes on handle 5)
2018-12-17T22:41:07.013980907Z 66 PC: 140cb | Move file pointer
2018-12-17T22:41:07.016077494Z 64 PC: 140cb | Write file or device (Write 24 bytes on handle 5)
2018-12-17T22:41:07.020547119Z 87 PC: 140cb | Get or set file date and time
2018-12-17T22:41:07.024301461Z 62 PC: 140cb | Close file
2018-12-17T22:41:07.034585236Z 86 PC: 140cb | Rename file
2018-12-17T22:41:07.046685974Z 67 PC: 140cb | Get or set file attributes
2018-12-17T22:41:07.05500036Z 26 PC: 140cb | Set disk transfer address
2018-12-17T22:41:07.056612719Z 37 PC: 140cb | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:41:07.05881766Z 42 PC: 140cb | Get date 0x140cb: ret
0x140cc: mov si, word ptr [di]
0x140ce: js 0x1414b
0x140d0: popf
0x140d2: mov cl, 0x7c