Sample viewer

vx.netlux.org/Virus.DOS.Corea.444

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:38.605536512Z 42 PC: 12b54 | Get date 0x12b54: ret
0x12b55: dec bp
0x12b56: inc bp
0x12b57: dec bp
0x12b58: inc bx
0x12b5a: dec di
0x12b5b: dec bp
0x12b5c: add byte ptr [bx + di + 0x6e], cl
0x12b5f: arpl word ptr [bx + 0x72], bp
0x12b62: jb 0x12bc9
0x12b64: arpl word ptr [si + 0x20], si
0x12b67: inc sp
0x12b68: dec di
0x12b69: push bx
0x12b6a: and byte ptr [bp + 0x65], dh
0x12b6d: jb 0x12be2
0x12b6f: imul bp, word ptr [bx + 0x6e], 0xd0a
0x12b74: and al, 0
0x12b76: add byte ptr [bx + si], al
0x12b78: add byte ptr [bp + si], ch
2018-12-17T22:52:38.611140897Z 78 PC: 12b54 | Find first file
2018-12-17T22:52:38.617538252Z 67 PC: 12b54 | Get or set file attributes
2018-12-17T22:52:38.633436133Z 61 PC: 12b54 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:52:38.641465209Z 63 PC: 12b54 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:52:38.649143599Z 66 PC: 12b54 | Move file pointer
2018-12-17T22:52:38.651093063Z 64 PC: 12be4 | Write file or device (Write 444 bytes on handle 5)
2018-12-17T22:52:38.655658803Z 62 PC: 12b54 | Close file
2018-12-17T22:52:38.665138606Z 79 PC: 12b54 | Find next file
2018-12-17T22:52:38.682842154Z 67 PC: 12b54 | Get or set file attributes
2018-12-17T22:52:38.720095212Z 61 PC: 12b54 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:52:38.728327804Z 63 PC: 12b54 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:52:38.734946672Z 66 PC: 12b54 | Move file pointer
2018-12-17T22:52:38.737841099Z 64 PC: 12be4 | Write file or device (Write 444 bytes on handle 5)
2018-12-17T22:52:38.741458442Z 62 PC: 12b54 | Close file
2018-12-17T22:52:38.74946185Z 79 PC: 12b54 | Find next file
2018-12-17T22:52:38.753495823Z 67 PC: 12b54 | Get or set file attributes
2018-12-17T22:52:38.763653522Z 61 PC: 12b54 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:52:38.770047351Z 63 PC: 12b54 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:52:38.7771341Z 66 PC: 12b54 | Move file pointer
2018-12-17T22:52:38.780556662Z 64 PC: 12be4 | Write file or device (Write 444 bytes on handle 5)
2018-12-17T22:52:38.783425061Z 62 PC: 12b54 | Close file
2018-12-17T22:52:38.790783688Z 79 PC: 12b54 | Find next file
2018-12-17T22:52:38.795495214Z 67 PC: 12b54 | Get or set file attributes
2018-12-17T22:52:38.805254025Z 61 PC: 12b54 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:52:38.818499493Z 63 PC: 12b54 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:52:38.82867513Z 66 PC: 12b54 | Move file pointer
2018-12-17T22:52:38.830300146Z 64 PC: 12be4 | Write file or device (Write 444 bytes on handle 5)
2018-12-17T22:52:38.833208756Z 62 PC: 12b54 | Close file
2018-12-17T22:52:38.84195881Z 79 PC: 12b54 | Find next file
2018-12-17T22:52:38.845121779Z 67 PC: 12b54 | Get or set file attributes
2018-12-17T22:52:38.855135191Z 61 PC: 12b54 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:52:38.863777062Z 63 PC: 12b54 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:52:38.871672708Z 66 PC: 12b54 | Move file pointer
2018-12-17T22:52:38.873579002Z 64 PC: 12be4 | Write file or device (Write 444 bytes on handle 5)
2018-12-17T22:52:38.876597473Z 62 PC: 12b54 | Close file
2018-12-17T22:52:38.884778752Z 79 PC: 12b54 | Find next file
2018-12-17T22:52:38.887685701Z 67 PC: 12b54 | Get or set file attributes
2018-12-17T22:52:38.897781271Z 61 PC: 12b54 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:52:38.905491027Z 63 PC: 12b54 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:52:38.91190959Z 66 PC: 12b54 | Move file pointer
2018-12-17T22:52:38.913281414Z 64 PC: 12be4 | Write file or device (Write 444 bytes on handle 5)
2018-12-17T22:52:38.91628636Z 62 PC: 12b54 | Close file
2018-12-17T22:52:38.923342408Z 79 PC: 12b54 | Find next file
2018-12-17T22:52:38.925503421Z 67 PC: 12b54 | Get or set file attributes
2018-12-17T22:52:38.932437771Z 61 PC: 12b54 | Open file (Filename = 'PAH.COM')
2018-12-17T22:52:38.936562373Z 63 PC: 12b54 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:52:38.940511413Z 66 PC: 12b54 | Move file pointer
2018-12-17T22:52:38.94228665Z 64 PC: 12be4 | Write file or device (Write 444 bytes on handle 5)
2018-12-17T22:52:38.944192102Z 62 PC: 12b54 | Close file
2018-12-17T22:52:38.950281314Z 79 PC: 12b54 | Find next file
2018-12-17T22:52:38.953478213Z 67 PC: 12b54 | Get or set file attributes
2018-12-17T22:52:38.963986838Z 61 PC: 12b54 | Open file (Filename = 'TEST.COM')
2018-12-17T22:52:38.971271038Z 63 PC: 12b54 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:52:38.975557637Z 79 PC: 12b54 | Find next file
2018-12-17T22:52:38.97805484Z 53 PC: 12b54 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:38.979268936Z 37 PC: 12b54 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:38.981154309Z 9 PC: 12b54 | Display string (Could not find end pointer)
2018-12-17T22:52:38.985201309Z 49 PC: 12b54 | Terminate and stay resident (Return code = '36' | Memory size = '44')