Sample viewer

vx.netlux.org/Virus.DOS.T_Power.Sodo.4590

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:21.397231934Z 74 PC: 12b37 | Reallocate memory
2018-12-17T22:51:21.399420776Z 53 PC: 13174 | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T22:51:21.400570387Z 53 PC: 13174 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:21.402133582Z 74 PC: 12bc4 | Reallocate memory
2018-12-17T22:51:21.403759502Z 88 PC: 12bcc | case 0xGet or set allocation strateg:
2018-12-17T22:51:21.404989919Z 88 PC: 12bd5 | case 0xGet or set allocation strateg:
2018-12-17T22:51:21.406055109Z 72 PC: 12be0 | Allocate memory
2018-12-17T22:51:21.421673546Z 88 PC: 12bf9 | case 0xGet or set allocation strateg:
2018-12-17T22:51:21.423217301Z 42 PC: 12c17 | Get date 0x12c17: test dh, 1
0x12c1a: jne 0x12c25
0x12c1c: test al, 1
0x12c1e: je 0x12c25
0x12c20: or byte ptr [bp + 0x1295], 0x80
0x12c25: push cs
0x12c26: pop ds
0x12c27: pop ax
0x12c28: push ax
0x12c29: mov si, bp
0x12c2b: mov es, ax
0x12c2d: xor di, di
0x12c2f: mov cx, 0x138d
0x12c32: rep movsb byte ptr es:[di], byte ptr [si]
0x12c34: mov al, 0x1c
0x12c36: call 0x13170
0x12c39: pop ds
0x12c3a: mov word ptr [0x79b], bx
0x12c3e: mov word ptr [0x79d], es
0x12c42: mov word ptr [0x56c], 0x9df
2018-12-17T22:51:21.425436917Z 53 PC: 13174 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:51:21.42650972Z 37 PC: 13179 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:21.428228547Z 37 PC: 13179 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:51:21.431238481Z 37 PC: 13179 | Set interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T22:51:21.436099523Z 37 PC: 13179 | Set interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-17T22:51:21.438281519Z 74 PC: 12c78 | Reallocate memory
2018-12-17T22:51:21.439627417Z 88 PC: 12c84 | case 0xGet or set allocation strateg:
2018-12-17T22:51:21.441352787Z 88 PC: 14034 | case 0xGet or set allocation strateg:
2018-12-17T22:51:21.443306215Z 47 PC: 14056 | Get disk transfer address
2018-12-17T22:51:21.445218958Z 26 PC: 14065 | Set disk transfer address
2018-12-17T22:51:21.446607173Z 71 PC: 1406e | Get current directory
2018-12-17T22:51:21.450474614Z 53 PC: 146f4 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:21.451846958Z 37 PC: 14529 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:21.452977284Z 59 PC: 1452e | Change current directory
2018-12-17T22:51:21.455208502Z 67 PC: 14537 | Get or set file attributes
2018-12-17T22:51:21.804475918Z 61 PC: 140f6 | Open file (Filename = '')
2018-12-17T22:51:21.810020421Z 87 PC: 1415c | Get or set file date and time
2018-12-17T22:51:21.812524455Z 63 PC: 1416f | Read file or device (Read 24 bytes on handle 5)
2018-12-17T22:51:21.814773434Z 66 PC: 14512 | Move file pointer
2018-12-17T22:51:21.821577062Z 64 PC: 1503d | Write file or device (Write 4590 bytes on handle 5)
2018-12-17T22:51:21.83294603Z 66 PC: 14512 | Move file pointer
2018-12-17T22:51:21.834634436Z 64 PC: 1451f | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:51:21.837702171Z 87 PC: 1429d | Get or set file date and time
2018-12-17T22:51:21.839637291Z 87 PC: 142a8 | Get or set file date and time
2018-12-17T22:51:21.842184298Z 62 PC: 142b0 | Close file
2018-12-17T22:51:21.853467004Z 78 PC: 142ca | Find first file
2018-12-17T22:51:21.859436547Z 78 PC: 142ca | Find first file
2018-12-17T22:51:21.865656612Z 78 PC: 142ca | Find first file
2018-12-17T22:51:21.871487661Z 78 PC: 142ca | Find first file
2018-12-17T22:51:21.877578386Z 78 PC: 142ca | Find first file
2018-12-17T22:51:21.885199854Z 78 PC: 142ca | Find first file
2018-12-17T22:51:21.890856323Z 78 PC: 142ca | Find first file
2018-12-17T22:51:21.896430302Z 78 PC: 142ca | Find first file
2018-12-17T22:51:21.900814968Z 78 PC: 142ca | Find first file
2018-12-17T22:51:21.904707241Z 78 PC: 142ca | Find first file
2018-12-17T22:51:21.908312166Z 59 PC: 1452e | Change current directory
2018-12-17T22:51:21.912125892Z 59 PC: 1452e | Change current directory
2018-12-17T22:51:21.913588563Z 37 PC: 14529 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:21.914498551Z 26 PC: 14306 | Set disk transfer address
2018-12-17T22:51:21.916941729Z 61 PC: 146f4 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:51:21.920877765Z 62 PC: 146f4 | Close file
2018-12-17T22:51:21.922349279Z 0 PC: 12942 | Program terminate