Sample viewer

vx.netlux.org/Virus.DOS.MemLapse.297

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:43.92870611Z 26 PC: 12a72 | Set disk transfer address
2018-12-17T22:46:43.9343731Z 78 PC: 12a7b | Find first file
2018-12-17T22:46:43.945799593Z 47 PC: 12a87 | Get disk transfer address
2018-12-17T22:46:43.947292982Z 79 PC: 12a7b | Find next file
2018-12-17T22:46:43.951093477Z 47 PC: 12a87 | Get disk transfer address
2018-12-17T22:46:43.95258664Z 67 PC: 12aaf | Get or set file attributes
2018-12-17T22:46:43.981772444Z 61 PC: 12abd | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:46:43.990385001Z 63 PC: 12ad6 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:46:43.997321819Z 66 PC: 12ae8 | Move file pointer
2018-12-17T22:46:43.999131626Z 87 PC: 12aed | Get or set file date and time
2018-12-17T22:46:44.000827256Z 64 PC: 12b00 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:46:44.004395198Z 66 PC: 12b09 | Move file pointer
2018-12-17T22:46:44.006136993Z 64 PC: 12b14 | Write file or device (Write 297 bytes on handle 5)
2018-12-17T22:46:44.01424609Z 44 PC: 12b19 | Get time 0x12b19: mov cl, dl
0x12b1b: add cl, al
0x12b1d: ror cl, 1
0x12b1f: xor ch, ch
0x12b21: xor dx, dx
0x12b23: mov ah, 0x40
0x12b25: int 0x21
0x12b27: mov cx, word ptr [0x22d]
0x12b2b: mov dx, word ptr [0x22b]
0x12b2f: mov ax, 0x5701
0x12b32: int 0x21
0x12b34: mov ah, 0x3e
0x12b36: int 0x21
0x12b38: mov ah, 0x4f
0x12b3a: jmp 0x12a75
0x12b3d: mov ah, 0x1a
0x12b3f: mov dx, 0x80
0x12b42: int 0x21
0x12b44: mov bx, 0x102
0x12b47: pop word ptr [bx]
2018-12-17T22:46:44.017762576Z 64 PC: 12b27 | Write file or device (Write 35 bytes on handle 5)
2018-12-17T22:46:44.021151937Z 87 PC: 12b34 | Get or set file date and time
2018-12-17T22:46:44.022939238Z 62 PC: 12b38 | Close file
2018-12-17T22:46:44.032018448Z 79 PC: 12a7b | Find next file
2018-12-17T22:46:44.035412216Z 26 PC: 12b44 | Set disk transfer address