Sample viewer

vx.netlux.org/Virus.DOS.Monster.c.638

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:42:12.71150982Z 37 PC: 151bb | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:42:12.71540681Z 71 PC: 151cd | Get current directory
2018-12-17T22:42:12.718899804Z 26 PC: 1521f | Set disk transfer address
2018-12-17T22:42:12.720302705Z 78 PC: 1522b | Find first file
2018-12-17T22:42:12.726757172Z 67 PC: 15368 | Get or set file attributes
2018-12-17T22:42:12.733155392Z 67 PC: 15368 | Get or set file attributes
2018-12-17T22:42:12.749222305Z 61 PC: 15248 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:42:12.771280291Z 66 PC: 15255 | Move file pointer
2018-12-17T22:42:12.777625399Z 63 PC: 15368 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:42:12.783228641Z 87 PC: 1528b | Get or set file date and time
2018-12-17T22:42:12.784393171Z 66 PC: 15296 | Move file pointer
2018-12-17T22:42:12.786174491Z 63 PC: 15368 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:42:12.789023172Z 44 PC: 15337 | Get time 0x15337: xor ch, dh
0x15339: mov word ptr [si + 0x20], cx
0x1533c: xor byte ptr [si + 0x19], cl
0x1533f: xor word ptr [si + 0x1a], cx
0x15342: ret
0x15343: mov cx, word ptr [si + 0x20]
0x15346: jmp 0x1533c
0x15348: mov ah, 0x3e
0x1534a: int 0x21
0x1534c: mov al, 1
0x1534e: mov ah, 0x43
0x15350: mov dx, 0x349
0x15353: jmp 0x15364
0x15355: mov ah, 0x3f
0x15357: mov cx, 3
0x1535a: mov dx, 0x19
0x1535d: jmp 0x15364
0x1535f: mov ah, 0x3b
0x15361: mov dx, 0xd
0x15364: add dx, si
2018-12-17T22:42:12.791539923Z 66 PC: 152a5 | Move file pointer
2018-12-17T22:42:12.79387545Z 64 PC: 152b1 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:42:12.796791708Z 66 PC: 152ba | Move file pointer
2018-12-17T22:42:12.79880517Z 64 PC: 152ed | Write file or device (Write 19 bytes on handle 5)
2018-12-17T22:42:12.802364527Z 64 PC: 152f9 | Write file or device (Write 619 bytes on handle 5)
2018-12-17T22:42:12.817823363Z 87 PC: 15300 | Get or set file date and time
2018-12-17T22:42:12.819605577Z 62 PC: 1534c | Close file
2018-12-17T22:42:12.82821208Z 67 PC: 15368 | Get or set file attributes
2018-12-17T22:42:12.838770447Z 59 PC: 15368 | Change current directory
2018-12-17T22:42:12.843236083Z 59 PC: 15310 | Change current directory
2018-12-17T22:42:12.847066835Z 26 PC: 15317 | Set disk transfer address
2018-12-17T22:42:12.84887107Z 37 PC: 15320 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:42:12.850571166Z 9 PC: 12a51 | Display string (String= 'This is a sample! (10.000 bytes)')
2018-12-17T22:42:12.854241288Z 76 PC: 12a56 | Terminate with return code (Return code = '0')