Sample viewer

vx.netlux.org/Virus.DOS.Deicide.Comment.2569

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:57:04.8260832Z 26 PC: 12a63 | Set disk transfer address
2018-12-17T21:57:04.827883249Z 78 PC: 12a6d | Find first file
2018-12-17T21:57:04.840975875Z 79 PC: 12aac | Find next file
2018-12-17T21:57:04.851381528Z 79 PC: 12aac | Find next file
2018-12-17T21:57:04.85463492Z 79 PC: 12aac | Find next file
2018-12-17T21:57:04.85831684Z 79 PC: 12aac | Find next file
2018-12-17T21:57:04.861459764Z 79 PC: 12aac | Find next file
2018-12-17T21:57:04.864259049Z 79 PC: 12aac | Find next file
2018-12-17T21:57:04.867287511Z 79 PC: 12aac | Find next file
2018-12-17T21:57:04.883938349Z 61 PC: 12a8c | Open file (Filename = 'TEST.COM')
2018-12-17T21:57:04.891240676Z 63 PC: 12a9b | Read file or device (Read 4 bytes on handle 5)
2018-12-17T21:57:04.894085563Z 62 PC: 12a9f | Close file
2018-12-17T21:57:04.89667416Z 79 PC: 12aac | Find next file
2018-12-17T21:57:04.899302349Z 26 PC: 12b3d | Set disk transfer address
2018-12-17T21:57:04.900498954Z 44 PC: 12b41 | Get time 0x12b41: xor dl, dl
0x12b43: xchg dl, dh
0x12b45: add dx, dx
0x12b47: add dx, 0x219
0x12b4b: mov si, dx
0x12b4d: mov dx, word ptr cs:[si]
0x12b50: mov ah, 9
0x12b52: int 0x21
0x12b54: jmp word ptr cs:[0xacf]
0x12b59: xchg ax, cx
0x12b5a: add ch, byte ptr [bp + di - 0x41fe]
0x12b5e: add bl, dh
0x12b60: add al, byte ptr [si]
0x12b62: add bp, word ptr [bx + si]
0x12b64: add ax, word ptr [di + 3]
0x12b67: outsb dx, byte ptr [si]
0x12b68: add cx, word ptr [bp + di - 0x51fd]
0x12b6c: add cx, dx
0x12b6e: add sp, dx
0x12b70: add di, dx
2018-12-17T21:57:04.903257848Z 9 PC: 12b54 | Display string (String= ' Swimming holiday in Bangladesh! ')