Sample viewer

vx.netlux.org/Virus.DOS.Ripper.641

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:59.866072522Z 47 PC: 12a6d | Get disk transfer address
2018-12-17T22:43:59.867987799Z 26 PC: 12a75 | Set disk transfer address
2018-12-17T22:43:59.87599121Z 42 PC: 12c1b | Get date 0x12c1b: mov al, dh
0x12c1d: cwde
0x12c1e: ret
0x12c1f: mov ah, 0x2a
0x12c21: int 0x21
0x12c23: xchg ax, cx
0x12c24: ret
0x12c25: push bp
0x12c26: mov bp, di
0x12c28: lea si, word ptr [bp + 0x372]
0x12c2c: xor ah, ah
0x12c2e: int 0x1a
0x12c30: mov word ptr [bp + 0x37a], dx
0x12c34: lea di, word ptr [bp + 0x384]
0x12c38: mov cx, 0x11
0x12c3b: push si
0x12c3c: push cx
0x12c3d: rep movsb byte ptr es:[di], byte ptr [si]
0x12c3f: lea si, word ptr [bp + 0x31d]
0x12c43: mov cx, 5
2018-12-17T22:43:59.878318365Z 71 PC: 12ad4 | Get current directory
2018-12-17T22:43:59.885743003Z 59 PC: 12adc | Change current directory
2018-12-17T22:43:59.89060911Z 47 PC: 12aef | Get disk transfer address
2018-12-17T22:43:59.891820827Z 26 PC: 12afd | Set disk transfer address
2018-12-17T22:43:59.893018944Z 78 PC: 12b08 | Find first file
2018-12-17T22:43:59.910447365Z 79 PC: 12b30 | Find next file
2018-12-17T22:43:59.91812124Z 79 PC: 12b30 | Find next file
2018-12-17T22:43:59.920910823Z 79 PC: 12b30 | Find next file
2018-12-17T22:43:59.92620615Z 79 PC: 12b30 | Find next file
2018-12-17T22:43:59.929019332Z 79 PC: 12b30 | Find next file
2018-12-17T22:43:59.931170217Z 79 PC: 12b30 | Find next file
2018-12-17T22:43:59.933738476Z 79 PC: 12b30 | Find next file
2018-12-17T22:43:59.935670157Z 79 PC: 12b30 | Find next file
2018-12-17T22:43:59.937948252Z 79 PC: 12b30 | Find next file
2018-12-17T22:43:59.940949126Z 47 PC: 12b47 | Get disk transfer address
2018-12-17T22:43:59.942653113Z 26 PC: 12b56 | Set disk transfer address
2018-12-17T22:43:59.944302891Z 78 PC: 12b5e | Find first file
2018-12-17T22:43:59.948911124Z 47 PC: 12b76 | Get disk transfer address
2018-12-17T22:43:59.950481466Z 61 PC: 12b8f | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:43:59.955034937Z 63 PC: 12b9b | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:43:59.959885801Z 66 PC: 12ba3 | Move file pointer
2018-12-17T22:43:59.96098986Z 62 PC: 12ba8 | Close file
2018-12-17T22:43:59.962391441Z 67 PC: 12bc8 | Get or set file attributes
2018-12-17T22:43:59.978783711Z 61 PC: 12bcd | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:43:59.987446522Z 64 PC: 12bd9 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:43:59.99120118Z 66 PC: 12be1 | Move file pointer
2018-12-17T22:43:59.995568772Z 246 PC: 12cda | UNKNOWN!
2018-12-17T22:43:59.997542277Z 87 PC: 12bf1 | Get or set file date and time
2018-12-17T22:43:59.999826767Z 62 PC: 12bf5 | Close file
2018-12-17T22:44:00.009424949Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T22:44:00.021773561Z 26 PC: 12b70 | Set disk transfer address
2018-12-17T22:44:00.023186807Z 26 PC: 12b40 | Set disk transfer address
2018-12-17T22:44:00.025016536Z 59 PC: 12ae6 | Change current directory
2018-12-17T22:44:00.0392856Z 26 PC: 12ab4 | Set disk transfer address