Sample viewer

vx.netlux.org/Virus.DOS.Spartak_II.2000

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:59:32.856881572Z 44 PC: 13030 | Get time 0x13030: mov word ptr [0x828], dx
0x13034: mov word ptr [0x831], dx
0x13038: mov di, 0x100
0x1303b: mov cx, 0x36
0x1303e: cld
0x1303f: mov si, 0x85e
0x13042: call 0x1311f
0x13045: mov ax, word ptr [0x828]
0x13048: and ax, 7
0x1304b: add si, ax
0x1304d: movsb byte ptr es:[di], byte ptr [si]
0x1304e: loop 0x1303f
0x13050: call 0x1311f
0x13053: mov ax, word ptr [0x828]
0x13056: test ax, 1
0x13059: je 0x1307d
0x1305b: push word ptr [0x84e]
0x1305f: push word ptr [0x83e]
0x13063: push word ptr [0x850]
0x13067: push word ptr [0x840]
2018-12-17T21:59:32.860289394Z 26 PC: 12a8f | Set disk transfer address
2018-12-17T21:59:32.86151857Z 25 PC: 12a98 | Get default drive
2018-12-17T21:59:32.862600163Z 78 PC: 12bcc | Find first file
2018-12-17T21:59:32.869340725Z 86 PC: 12d24 | Rename file
2018-12-17T21:59:32.886675798Z 60 PC: 12d33 | Create or truncate file
2018-12-17T21:59:32.899023836Z 64 PC: 13214 | Write file or device (Write 2000 bytes on handle 5)
2018-12-17T21:59:32.908688441Z 62 PC: 12d47 | Close file
2018-12-17T21:59:32.917296863Z 60 PC: 12d51 | Create or truncate file
2018-12-17T21:59:32.930287123Z 64 PC: 12d5e | Write file or device (Write 86 bytes on handle 5)
2018-12-17T21:59:32.933927952Z 62 PC: 12d63 | Close file
2018-12-17T21:59:32.942097081Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:32.94471591Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:32.947362495Z 86 PC: 12d24 | Rename file
2018-12-17T21:59:32.959265489Z 60 PC: 12d33 | Create or truncate file
2018-12-17T21:59:32.975017816Z 64 PC: 13214 | Write file or device (Write 2000 bytes on handle 5)
2018-12-17T21:59:32.984290282Z 62 PC: 12d47 | Close file
2018-12-17T21:59:32.993707875Z 60 PC: 12d51 | Create or truncate file
2018-12-17T21:59:33.006802604Z 64 PC: 12d5e | Write file or device (Write 86 bytes on handle 5)
2018-12-17T21:59:33.010756274Z 62 PC: 12d63 | Close file
2018-12-17T21:59:33.267918966Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:33.270953655Z 86 PC: 12d24 | Rename file
2018-12-17T21:59:33.345515899Z 60 PC: 12d33 | Create or truncate file
2018-12-17T21:59:33.358188691Z 64 PC: 13214 | Write file or device (Write 2000 bytes on handle 5)
2018-12-17T21:59:33.368153093Z 62 PC: 12d47 | Close file
2018-12-17T21:59:33.376215061Z 60 PC: 12d51 | Create or truncate file
2018-12-17T21:59:33.388319167Z 64 PC: 12d5e | Write file or device (Write 86 bytes on handle 5)
2018-12-17T21:59:33.39324125Z 62 PC: 12d63 | Close file
2018-12-17T21:59:33.401875912Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:33.405807999Z 86 PC: 12d24 | Rename file
2018-12-17T21:59:33.418514845Z 60 PC: 12d33 | Create or truncate file
2018-12-17T21:59:33.430481093Z 64 PC: 13214 | Write file or device (Write 2000 bytes on handle 5)
2018-12-17T21:59:33.43972939Z 62 PC: 12d47 | Close file
2018-12-17T21:59:33.449581201Z 60 PC: 12d51 | Create or truncate file
2018-12-17T21:59:33.462103176Z 64 PC: 12d5e | Write file or device (Write 86 bytes on handle 5)
2018-12-17T21:59:33.466441071Z 62 PC: 12d63 | Close file
2018-12-17T21:59:33.474747188Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:33.478252317Z 86 PC: 12d24 | Rename file
2018-12-17T21:59:33.490129906Z 60 PC: 12d33 | Create or truncate file
2018-12-17T21:59:33.518023366Z 64 PC: 13214 | Write file or device (Write 2000 bytes on handle 5)
2018-12-17T21:59:33.524782855Z 62 PC: 12d47 | Close file
2018-12-17T21:59:33.530511386Z 60 PC: 12d51 | Create or truncate file
2018-12-17T21:59:33.538971096Z 64 PC: 12d5e | Write file or device (Write 86 bytes on handle 5)
2018-12-17T21:59:33.541420788Z 62 PC: 12d63 | Close file
2018-12-17T21:59:33.54757605Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:33.549768923Z 86 PC: 12d24 | Rename file
2018-12-17T21:59:33.557753475Z 60 PC: 12d33 | Create or truncate file
2018-12-17T21:59:33.572015465Z 64 PC: 13214 | Write file or device (Write 2000 bytes on handle 5)
2018-12-17T21:59:33.581226213Z 62 PC: 12d47 | Close file
2018-12-17T21:59:33.590755041Z 60 PC: 12d51 | Create or truncate file
2018-12-17T21:59:33.612942492Z 64 PC: 12d5e | Write file or device (Write 86 bytes on handle 5)
2018-12-17T21:59:33.617246797Z 62 PC: 12d63 | Close file
2018-12-17T21:59:33.626372081Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:33.629585922Z 86 PC: 12d24 | Rename file
2018-12-17T21:59:33.640938137Z 60 PC: 12d33 | Create or truncate file
2018-12-17T21:59:33.657192952Z 64 PC: 13214 | Write file or device (Write 2000 bytes on handle 5)
2018-12-17T21:59:33.666951851Z 62 PC: 12d47 | Close file
2018-12-17T21:59:33.675168419Z 60 PC: 12d51 | Create or truncate file
2018-12-17T21:59:33.688547763Z 64 PC: 12d5e | Write file or device (Write 86 bytes on handle 5)
2018-12-17T21:59:33.692948818Z 62 PC: 12d63 | Close file
2018-12-17T21:59:33.701232681Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:33.704904523Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:33.708144741Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:33.711183183Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:33.715026266Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:33.717913522Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:33.720731384Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:33.725126831Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:33.728059713Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:33.730667709Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:33.733028125Z 28 PC: 12ab3 | Get allocation info for specified drive
2018-12-17T21:59:33.770221916Z 78 PC: 12bcc | Find first file
2018-12-17T21:59:33.778062655Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:33.780724223Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:33.785149253Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:33.787965614Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:33.791511428Z 79 PC: 12bcc | Find next file
2018-12-17T21:59:33.794409575Z 28 PC: 12ab3 | Get allocation info for specified drive
2018-12-17T21:59:33.796022458Z 86 PC: 12b38 | Rename file
2018-12-17T21:59:33.807746577Z 86 PC: 12b4d | Rename file
2018-12-17T21:59:33.814752558Z 86 PC: 12b9f | Rename file
2018-12-17T21:59:33.825985557Z 76 PC: 12ba7 | Terminate with return code (Return code = '18')