Sample viewer

vx.netlux.org/Virus.DOS.Scitzo.1285

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:42:28.150581509Z 171 PC: 12abf | UNKNOWN!
2018-12-17T22:42:28.152246036Z 74 PC: 12acb | Reallocate memory
2018-12-17T22:42:28.154671762Z 74 PC: 12ad2 | Reallocate memory
2018-12-17T22:42:28.156543567Z 72 PC: 12ad9 | Allocate memory
2018-12-17T22:42:28.158916444Z 53 PC: 12af6 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:42:28.161169035Z 37 PC: 12b06 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:42:28.16314728Z 61 PC: 9f89b | Open file (Filename = '�?��')
2018-12-17T22:42:28.173696704Z 87 PC: 9f8a9 | Get or set file date and time
2018-12-17T22:42:28.176380204Z 63 PC: 9f8c5 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:42:28.182558197Z 66 PC: 9f9c1 | Move file pointer
2018-12-17T22:42:28.18446541Z 44 PC: 9fb21 | Get time 0x9fb21: push ds
0x9fb22: pop es
0x9fb23: mov ax, dx
0x9fb25: and ax, 3
0x9fb28: cmp al, 3
0x9fb2a: jne 0x9fb2e
0x9fb2c: dec al
0x9fb2e: mov cl, 3
0x9fb30: mul cl
0x9fb32: mov si, 0x388
0x9fb35: add si, ax
0x9fb37: mov di, 0xd
0x9fb3a: movsb byte ptr es:[di], byte ptr [si]
0x9fb3b: inc di
0x9fb3c: inc di
0x9fb3d: movsw word ptr es:[di], word ptr [si]
0x9fb3e: mov ax, dx
0x9fb40: shr ax, 2
0x9fb43: and ax, 3
0x9fb46: cmp al, 3
2018-12-17T22:42:28.189043748Z 44 PC: 9fb7e | Get time 0x9fb7e: mov ax, dx
0x9fb80: shr ax, 3
0x9fb83: and ax, 3
0x9fb86: cmp al, 3
0x9fb88: jne 0x9fb8c
0x9fb8a: dec al
0x9fb8c: mov cl, 9
0x9fb8e: mul cl
0x9fb90: mov si, 0x3be
0x9fb93: add si, ax
0x9fb95: mov di, 0
0x9fb98: movsw word ptr es:[di], word ptr [si]
0x9fb99: movsw word ptr es:[di], word ptr [si]
0x9fb9a: movsw word ptr es:[di], word ptr [si]
0x9fb9b: movsw word ptr es:[di], word ptr [si]
0x9fb9c: movsb byte ptr es:[di], byte ptr [si]
0x9fb9d: mov ax, dx
0x9fb9f: shr ax, 1
0x9fba1: and ax, 3
0x9fba4: cmp al, 3
2018-12-17T22:42:28.192066927Z 44 PC: 9faeb | Get time 0x9faeb: mov word ptr [0x1d], dx
0x9faef: mov word ptr [0x44], dx
0x9faf3: mov word ptr [0x3ed], dx
0x9faf7: call 0xafad5
0x9fafa: mov ah, 0x40
0x9fafc: mov cx, 0x69
0x9faff: xor dx, dx
0x9fb01: int 0x21
0x9fb03: call 0xafad5
0x9fb06: call 0x9fb0a
0x9fb09: ret
0x9fb0a: mov ax, word ptr [0x146]
0x9fb0d: mov word ptr [0x34], ax
0x9fb10: mov ax, word ptr [0x148]
0x9fb13: mov word ptr [0x36], ax
0x9fb16: call 0xaf717
0x9fb19: call 0xafad5
0x9fb1c: ret
0x9fb1d: mov ah, 0x2c
0x9fb1f: int 0x21
2018-12-17T22:42:28.194792776Z 64 PC: 9fb03 | Write file or device (Write 105 bytes on handle 5)
2018-12-17T22:42:28.536297305Z 64 PC: 9f728 | Write file or device (Write 1180 bytes on handle 5)
2018-12-17T22:42:28.547268982Z 66 PC: 9f9e0 | Move file pointer
2018-12-17T22:42:28.550176031Z 64 PC: 9f9ea | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:42:28.559843449Z 87 PC: 9fa45 | Get or set file date and time
2018-12-17T22:42:28.562588655Z 62 PC: 9fa49 | Close file
2018-12-17T22:42:28.57032732Z 61 PC: 12b21 | Open file (Filename = '�S�')
2018-12-17T22:42:28.579105907Z 62 PC: 12b26 | Close file