Sample viewer

vx.netlux.org/Virus.DOS.WpcBats.3072

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:12.232695175Z 48 PC: 12f85 | Get DOS version
2018-12-17T22:51:12.233885604Z 88 PC: 12f92 | case 0xGet or set allocation strateg:
2018-12-17T22:51:12.235708613Z 72 PC: 12f9c | Allocate memory
2018-12-17T22:51:12.237334063Z 74 PC: 12fae | Reallocate memory
2018-12-17T22:51:12.238965605Z 74 PC: 12fef | Reallocate memory
2018-12-17T22:51:12.241200856Z 88 PC: 1300e | case 0xGet or set allocation strateg:
2018-12-17T22:51:12.242369595Z 72 PC: 13015 | Allocate memory
2018-12-17T22:51:12.243746259Z 88 PC: 13020 | case 0xGet or set allocation strateg:
2018-12-17T22:51:12.260665263Z 53 PC: 9eecf | Get interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-17T22:51:12.262071663Z 53 PC: 9eedb | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:51:12.263702608Z 37 PC: 9eef8 | Set interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-17T22:51:12.265393908Z 37 PC: 9eeff | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:51:12.267401699Z 53 PC: 9f5fd | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:12.268523215Z 47 PC: 9f5fd | Get disk transfer address
2018-12-17T22:51:12.269781817Z 37 PC: 9f5fd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:12.271700029Z 26 PC: 9f5fd | Set disk transfer address
2018-12-17T22:51:12.273138821Z 46 PC: 9f5fd | Set verify flag
2018-12-17T22:51:12.274446898Z 78 PC: 9f5fd | Find first file
2018-12-17T22:51:12.282054746Z 44 PC: 9f5fd | Get time 0x9f5fd: ret
0x9f5fe: mov bx, 0x23
0x9f601: call 0x9f614
0x9f604: inc dx
0x9f605: dec bx
0x9f606: jne 0x9f601
0x9f608: ret
0x9f609: mov bx, 0x23
0x9f60c: call 0x9f614
0x9f60f: inc cx
0x9f610: dec bx
0x9f611: jne 0x9f60c
0x9f613: ret
0x9f614: mov ax, 0xc0f
0x9f617: int 0x10
0x9f619: ret
0x9f61a: call 0xaf01e
0x9f61d: push cs
0x9f61e: pop ds
0x9f61f: mov ax, 0xe
2018-12-17T22:51:12.284402067Z 26 PC: 9f5fd | Set disk transfer address
2018-12-17T22:51:12.285810422Z 37 PC: 9f5fd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:12.288829151Z 9 PC: 12ad3 | Display string (String= ' Mabuhay! This program came from Bahay Kawayan at http://come.to/hexfiles Putoksa Kawayan [email protected] ')
2018-12-17T22:51:12.302473817Z 76 PC: 12ad7 | Terminate with return code (Return code = '36')