Sample viewer

vx.netlux.org/Virus.DOS.Deicide.Comment.2403.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:42:00.149014465Z 26 PC: 12a63 | Set disk transfer address
2018-12-17T22:42:00.150538294Z 78 PC: 12a6d | Find first file
2018-12-17T22:42:00.157466786Z 79 PC: 12aac | Find next file
2018-12-17T22:42:00.160441882Z 79 PC: 12aac | Find next file
2018-12-17T22:42:00.163263178Z 79 PC: 12aac | Find next file
2018-12-17T22:42:00.166881279Z 79 PC: 12aac | Find next file
2018-12-17T22:42:00.170152326Z 79 PC: 12aac | Find next file
2018-12-17T22:42:00.172948226Z 79 PC: 12aac | Find next file
2018-12-17T22:42:00.177205969Z 79 PC: 12aac | Find next file
2018-12-17T22:42:00.180333695Z 61 PC: 12a8c | Open file (Filename = 'TEST.COM')
2018-12-17T22:42:00.187629791Z 63 PC: 12a9b | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:42:00.191420209Z 62 PC: 12a9f | Close file
2018-12-17T22:42:00.193621414Z 79 PC: 12aac | Find next file
2018-12-17T22:42:00.196379066Z 26 PC: 12b3d | Set disk transfer address
2018-12-17T22:42:00.1985869Z 44 PC: 12b41 | Get time 0x12b41: xor dl, dl
0x12b43: xchg dl, dh
0x12b45: add dx, dx
0x12b47: add dx, 0x219
0x12b4b: mov si, dx
0x12b4d: mov dx, word ptr cs:[si]
0x12b50: mov ah, 9
0x12b52: int 0x21
0x12b54: jmp word ptr cs:[0xa29]
0x12b59: xchg ax, cx
0x12b5a: add ch, byte ptr [bp + si - 0x34fe]
0x12b5e: add ch, cl
0x12b60: add al, byte ptr [bx + si]
0x12b62: add sp, word ptr [bx + di]
0x12b64: add ax, word ptr [di + 3]
0x12b67: insb byte ptr es:[di], dx
0x12b68: add dx, word ptr [bp + si - 0x40fd]
0x12b6c: add bx, sp
0x12b6e: add di, ax
0x12b70: add bx, word ptr [si]
2018-12-17T22:42:00.201008706Z 9 PC: 12b54 | Display string (String= ' Why dont you play with something else? ')