Sample viewer

vx.netlux.org/Virus.DOS.Vole.495

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:44.941833929Z 26 PC: 12a94 | Set disk transfer address
2018-12-17T22:52:44.943600335Z 37 PC: 12aa2 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:52:44.945166932Z 37 PC: 12aa6 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:52:44.946731121Z 78 PC: 12af2 | Find first file
2018-12-17T22:52:44.953846768Z 61 PC: 12bc3 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:52:44.960254107Z 63 PC: 12bd2 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:52:44.964888437Z 66 PC: 12be1 | Move file pointer
2018-12-17T22:52:44.966964225Z 66 PC: 12bf0 | Move file pointer
2018-12-17T22:52:44.968261238Z 64 PC: 12bfc | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:52:44.970954427Z 66 PC: 12c08 | Move file pointer
2018-12-17T22:52:44.972375773Z 44 PC: 12c0c | Get time 0x12c0c: mov byte ptr [bp + 0x1ef], dl
0x12c10: call 0x12c26
0x12c13: mov ah, 0x40
0x12c15: mov cx, 0x1ef
0x12c18: lea dx, word ptr [bp + 6]
0x12c1c: int 0x21
0x12c1e: call 0x12c26
0x12c21: mov ah, 0x3e
0x12c23: int 0x21
0x12c25: ret
0x12c26: lea si, word ptr [bp + 0x33]
0x12c2a: mov cx, 0x19d
0x12c2d: xor byte ptr [si], 0
0x12c30: inc si
0x12c31: dec cx
0x12c32: jne 0x12c2d
0x12c34: ret
0x12c35: add word ptr [bx], di
0x12c37: aas
0x12c38: aas
2018-12-17T22:52:44.985628382Z 64 PC: 12c1e | Write file or device (Write 495 bytes on handle 5)
2018-12-17T22:52:44.997792906Z 62 PC: 12c25 | Close file
2018-12-17T22:52:45.003545221Z 79 PC: 12af2 | Find next file
2018-12-17T22:52:45.006794984Z 61 PC: 12bc3 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:52:45.016819897Z 63 PC: 12bd2 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:52:45.028683365Z 66 PC: 12be1 | Move file pointer
2018-12-17T22:52:45.039014566Z 66 PC: 12bf0 | Move file pointer
2018-12-17T22:52:45.040788913Z 64 PC: 12bfc | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:52:45.043915159Z 66 PC: 12c08 | Move file pointer
2018-12-17T22:52:45.047227973Z 44 PC: 12c0c | Get time 0x12c0c: mov byte ptr [bp + 0x1ef], dl
0x12c10: call 0x12c26
0x12c13: mov ah, 0x40
0x12c15: mov cx, 0x1ef
0x12c18: lea dx, word ptr [bp + 6]
0x12c1c: int 0x21
0x12c1e: call 0x12c26
0x12c21: mov ah, 0x3e
0x12c23: int 0x21
0x12c25: ret
0x12c26: lea si, word ptr [bp + 0x33]
0x12c2a: mov cx, 0x19d
0x12c2d: xor byte ptr [si], 0x43
0x12c30: inc si
0x12c31: dec cx
0x12c32: jne 0x12c2d
0x12c34: ret
0x12c35: add word ptr [bx], di
0x12c37: aas
0x12c38: aas
2018-12-17T22:52:45.050171271Z 64 PC: 12c1e | Write file or device (Write 495 bytes on handle 5)
2018-12-17T22:52:45.058379598Z 62 PC: 12c25 | Close file
2018-12-17T22:52:45.067985958Z 26 PC: 12b0c | Set disk transfer address
2018-12-17T22:52:45.069571339Z 9 PC: 12b18 | Display string (Could not find end pointer)
2018-12-17T22:52:45.08088632Z 9 PC: 12b2d | Display string (String= ' Inherit the Wind !!! ')