Sample viewer

vx.netlux.org/Virus.DOS.Serbu.3322.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:39.639575505Z 98 PC: 14a5b | Get current PSP
2018-12-17T22:52:39.645260011Z 88 PC: 14c9c | case 0xGet or set allocation strateg:
2018-12-17T22:52:39.647470139Z 88 PC: 14ca8 | case 0xGet or set allocation strateg:
2018-12-17T22:52:39.649182042Z 72 PC: 14cae | Allocate memory
2018-12-17T22:52:39.651454438Z 74 PC: 14cc0 | Reallocate memory
2018-12-17T22:52:39.662594982Z 88 PC: 14ca8 | case 0xGet or set allocation strateg:
2018-12-17T22:52:39.664098488Z 72 PC: 14cae | Allocate memory
2018-12-17T22:52:39.66595317Z 88 PC: 14cdd | case 0xGet or set allocation strateg:
2018-12-17T22:52:39.668812529Z 88 PC: 14ce2 | case 0xGet or set allocation strateg:
2018-12-17T22:52:39.67071635Z 42 PC: 155e9 | Get date 0x155e9: sti
0x155ea: ret
0x155eb: cli
0x155ec: pushf
0x155ed: lcall 0x19:0x44bd
0x155f2: sti
0x155f3: ret
0x155f4: add al, 5
0x155f6: and byte ptr ds:[bp + si + 0x4c], al
0x155fb: sub ax, 0x3339
0x155fe: xor word ptr [bx + di], si
0x15600: xor ax, 0x3c20
0x15603: cmp al, 0
0x15605: pushaw
0x15606: inc byte ptr [di]
0x15608: aad 0xc1
0x1560a: jb 0x155a1
0x1560c: test word ptr [bx - 0x6e6a], dx
0x15610: mov al, 0x93
0x15612: fmul qword ptr [di + 0x7073]
2018-12-17T22:52:39.676790237Z 99 PC: 12aff | Get DBCS lead byte table pointer
2018-12-17T22:52:39.67935087Z 68 PC: 12b19 | I/O control for devices (Set for = '')
2018-12-17T22:52:39.681372304Z 68 PC: 12b24 | I/O control for devices (Set for = '')
2018-12-17T22:52:39.683662618Z 68 PC: 12b2f | I/O control for devices (Set for = '')
2018-12-17T22:52:39.686160061Z 68 PC: 12b37 | I/O control for devices (Set for = '��b���g�t�S3����[r�2��W�<t�<u�6�u����>��>W')
2018-12-17T22:52:39.689272019Z 48 PC: 12b3c | Get DOS version
2018-12-17T22:52:39.691996168Z 108 PC: 9fa71 | Extended open/create file
2018-12-17T22:52:39.700033258Z 68 PC: 9fa71 | I/O control for devices (Set for = ' ��')
2018-12-17T22:52:39.702178185Z 53 PC: 9f874 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:39.703472324Z 37 PC: 9fa4b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:39.704700343Z 69 PC: 9f899 | Duplicate handle
2018-12-17T22:52:39.706952408Z 63 PC: 9f6a1 | Read file or device (Read 26 bytes on handle 6)
2018-12-17T22:52:39.710036006Z 66 PC: 9f6d1 | Move file pointer
2018-12-17T22:52:39.711746151Z 87 PC: 9f789 | Get or set file date and time
2018-12-17T22:52:39.718880952Z 64 PC: 9fa5f | Write file or device (Write 3322 bytes on handle 6)
2018-12-17T22:52:40.064475632Z 66 PC: 9f79b | Move file pointer
2018-12-17T22:52:40.066669957Z 64 PC: 9f7a4 | Write file or device (Write 26 bytes on handle 6)
2018-12-17T22:52:40.071275906Z 62 PC: 9f8a8 | Close file
2018-12-17T22:52:40.080624682Z 37 PC: 9f8d0 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:40.082603278Z 62 PC: 9f485 | Close file
2018-12-17T22:52:40.100990487Z 108 PC: 9fa71 | Extended open/create file
2018-12-17T22:52:40.113351605Z 68 PC: 9fa71 | I/O control for devices (Set for = ' ��')
2018-12-17T22:52:40.115902583Z 63 PC: 9fa71 | Read file or device (Read 29 bytes on handle 5)
2018-12-17T22:52:40.124009891Z 66 PC: 12770 | Move file pointer
2018-12-17T22:52:40.128083059Z 63 PC: 1277c | Read file or device (Read 64 bytes on handle 5)
2018-12-17T22:52:40.143599521Z 66 PC: 12770 | Move file pointer
2018-12-17T22:52:40.154583699Z 63 PC: 1277c | Read file or device (Read 64 bytes on handle 5)
2018-12-17T22:52:40.161618712Z 62 PC: 12791 | Close file
2018-12-17T22:52:40.1649977Z 64 PC: 12c71 | Write file or device (Write 26 bytes on handle 2)
2018-12-17T22:52:40.18246535Z 64 PC: 12c71 | Write file or device (Write 3 bytes on handle 2)
2018-12-17T22:52:40.187208064Z 64 PC: 12c41 | Write file or device (Write 1 bytes on handle 2)
2018-12-17T22:52:40.192143912Z 64 PC: 12c71 | Write file or device (Write 2 bytes on handle 2)
2018-12-17T22:52:40.197408446Z 76 PC: 133b6 | Terminate with return code (Return code = '0')
2018-12-17T22:52:40.214267297Z 37 PC: 9f268 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:52:40.216085894Z 88 PC: 9f270 | case 0xGet or set allocation strateg:
2018-12-17T22:52:40.217786077Z 72 PC: 9f277 | Allocate memory
2018-12-17T22:52:40.221192185Z 73 PC: 9f287 | Release memory
2018-12-17T22:52:40.222978726Z 88 PC: 9f28e | case 0xGet or set allocation strateg:
2018-12-17T22:52:40.224774584Z 73 PC: 9f294 | Release memory
2018-12-17T22:52:40.227282185Z 72 PC: 9f2b9 | Allocate memory
2018-12-17T22:52:40.238584661Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:52:40.247791601Z 72 PC: 12174 | Allocate memory
2018-12-17T22:52:40.251063677Z 72 PC: 1218d | Allocate memory
2018-12-17T22:52:40.256868063Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:52:40.259545007Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:52:40.261537127Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:40.264516692Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:40.266742493Z 62 PC: 122ab | Close file
2018-12-17T22:52:40.269205183Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:40.272374233Z 62 PC: 122ab | Close file
2018-12-17T22:52:40.274861397Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:40.276993277Z 62 PC: 122ab | Close file
2018-12-17T22:52:40.28030774Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:40.282798761Z 62 PC: 122ab | Close file
2018-12-17T22:52:40.285243162Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:40.288156345Z 62 PC: 122ab | Close file
2018-12-17T22:52:40.290907607Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:40.293054263Z 62 PC: 122ab | Close file
2018-12-17T22:52:40.295704706Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:40.298437924Z 62 PC: 122ab | Close file
2018-12-17T22:52:40.305072191Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:40.307359303Z 62 PC: 122ab | Close file
2018-12-17T22:52:40.311042282Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:40.313193767Z 62 PC: 122ab | Close file
2018-12-17T22:52:40.315659787Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:40.318628698Z 62 PC: 122ab | Close file
2018-12-17T22:52:40.32140471Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:40.323540505Z 62 PC: 122ab | Close file
2018-12-17T22:52:40.32677753Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:40.329233587Z 62 PC: 122ab | Close file
2018-12-17T22:52:40.33169466Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:40.334054555Z 62 PC: 122ab | Close file
2018-12-17T22:52:40.337333755Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:40.339487651Z 62 PC: 122ab | Close file
2018-12-17T22:52:40.342790692Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:40.345353083Z 62 PC: 122ab | Close file
2018-12-17T22:52:40.348874545Z 61 PC: 13601 | Open file (Filename = '')
2018-12-17T22:52:40.356490707Z 68 PC: 13601 | I/O control for devices (Set for = '')
2018-12-17T22:52:40.359368352Z 63 PC: 13601 | Read file or device (Read 29 bytes on handle 5)
2018-12-17T22:52:40.363298616Z 66 PC: 12372 | Move file pointer
2018-12-17T22:52:40.365623334Z 63 PC: 12383 | Read file or device (Read 44693 bytes on handle 5)
2018-12-17T22:52:40.381955255Z 62 PC: 1238a | Close file
2018-12-17T22:52:40.38599427Z 99 PC: 9a5d7 | Get DBCS lead byte table pointer
2018-12-17T22:52:40.387894639Z 56 PC: 94df9 | Get or set country info
2018-12-17T22:52:40.391653058Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:52:40.397449507Z 25 PC: 94e62 | Get default drive
2018-12-17T22:52:40.399694287Z 71 PC: 970dd | Get current directory
2018-12-17T22:52:40.405687382Z 64 PC: 9a848 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:52:40.410929207Z 2 PC: 970b2 | Character output (Char = '3e')
2018-12-17T22:52:40.413865083Z 93 PC: 94f20 | File sharing functions
2018-12-17T22:52:40.416468791Z 93 PC: 94f27 | File sharing functions
2018-12-17T22:52:40.420568598Z 10 PC: 94f39 | Buffered keyboard input
2018-12-17T22:52:54.569093412Z 0 PC: 0 | Program terminate
2018-12-17T22:52:55.923797316Z 0 PC: 0 | Program terminate
2018-12-17T22:52:56.026838374Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:52:56.033709484Z 41 PC: 94fae | Parse filename
2018-12-17T22:52:56.035850599Z 41 PC: 9502f | Parse filename
2018-12-17T22:52:56.038970268Z 41 PC: 9504c | Parse filename
2018-12-17T22:52:56.041303512Z 26 PC: 984f7 | Set disk transfer address
2018-12-17T22:52:56.04332366Z 71 PC: 986f3 | Get current directory
2018-12-17T22:52:56.053402475Z 47 PC: 13601 | Get disk transfer address
2018-12-17T22:52:56.054913821Z 78 PC: 13601 | Find first file
2018-12-17T22:52:56.067057168Z 71 PC: 9856c | Get current directory
2018-12-17T22:52:56.071294114Z 73 PC: 97c09 | Release memory
2018-12-17T22:52:56.074671554Z 61 PC: 13601 | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T22:52:56.083367322Z 87 PC: 13601 | Get or set file date and time
2018-12-17T22:52:56.085342813Z 62 PC: 13601 | Close file
2018-12-17T22:52:56.087627005Z 53 PC: 13601 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:56.090218308Z 37 PC: 135db | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:56.091929504Z 67 PC: 13354 | Get or set file attributes
2018-12-17T22:52:56.098915166Z 67 PC: 1335d | Get or set file attributes
2018-12-17T22:52:56.131570174Z 61 PC: 13364 | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T22:52:56.140574638Z 63 PC: 13231 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:52:56.148863231Z 66 PC: 13261 | Move file pointer
2018-12-17T22:52:56.152064396Z 62 PC: 1337e | Close file
2018-12-17T22:52:56.158766706Z 67 PC: 1338a | Get or set file attributes
2018-12-17T22:52:56.170830994Z 37 PC: 13391 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:56.172302629Z 75 PC: 11821 | Execute program
2018-12-17T22:52:56.185141279Z 9 PC: 138a7 | Display string (String= 'Hello, World! ')
2018-12-17T22:52:56.19135617Z 76 PC: 138ab | Terminate with return code (Return code = '36')
2018-12-17T22:52:56.194973387Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:52:56.197574602Z 72 PC: 12174 | Allocate memory
2018-12-17T22:52:56.199987967Z 72 PC: 1218d | Allocate memory
2018-12-17T22:52:56.202239356Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:52:56.204527755Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:52:56.206480996Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:56.20826547Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:56.210677062Z 62 PC: 122ab | Close file
2018-12-17T22:52:56.213054626Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:56.215134495Z 62 PC: 122ab | Close file
2018-12-17T22:52:56.218047456Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:56.219619609Z 62 PC: 122ab | Close file
2018-12-17T22:52:56.235623167Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:56.245476859Z 62 PC: 122ab | Close file
2018-12-17T22:52:56.248098958Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:56.250529417Z 62 PC: 122ab | Close file
2018-12-17T22:52:56.254440722Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:56.256770685Z 62 PC: 122ab | Close file
2018-12-17T22:52:56.259447125Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:56.26305607Z 62 PC: 122ab | Close file
2018-12-17T22:52:56.265593367Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:56.267867787Z 62 PC: 122ab | Close file
2018-12-17T22:52:56.271116319Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:56.273432066Z 62 PC: 122ab | Close file
2018-12-17T22:52:56.276114831Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:56.278731006Z 62 PC: 122ab | Close file
2018-12-17T22:52:56.280902175Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:56.282748041Z 62 PC: 122ab | Close file
2018-12-17T22:52:56.285865948Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:56.287674366Z 62 PC: 122ab | Close file
2018-12-17T22:52:56.289728936Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:56.292503405Z 62 PC: 122ab | Close file
2018-12-17T22:52:56.294740895Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:56.296755338Z 62 PC: 122ab | Close file
2018-12-17T22:52:56.299899465Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:52:56.303039111Z 62 PC: 122ab | Close file
2018-12-17T22:52:56.307003487Z 99 PC: 9a5d7 | Get DBCS lead byte table pointer
2018-12-17T22:52:56.309502514Z 56 PC: 94df9 | Get or set country info
2018-12-17T22:52:56.312365929Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:52:56.318402893Z 25 PC: 94e62 | Get default drive
2018-12-17T22:52:56.321451716Z 71 PC: 970dd | Get current directory
2018-12-17T22:52:56.326332124Z 64 PC: 9a848 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:52:56.330290163Z 2 PC: 970b2 | Character output (Char = '3e')
2018-12-17T22:52:56.334204495Z 93 PC: 94f20 | File sharing functions
2018-12-17T22:52:56.336633554Z 93 PC: 94f27 | File sharing functions
2018-12-17T22:52:56.33985609Z 10 PC: 94f39 | Buffered keyboard input