Sample viewer

vx.netlux.org/Virus.DOS.Logb.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:26.241306161Z 53 PC: 136ea | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:26.24323588Z 53 PC: 136ea | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:26.244523464Z 53 PC: 136ea | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:26.245748763Z 53 PC: 136ea | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:26.247279729Z 53 PC: 136ea | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:26.24921051Z 53 PC: 136ea | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:26.251374756Z 53 PC: 136ea | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:26.252778601Z 53 PC: 136ea | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:26.254852837Z 53 PC: 136ea | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:26.256196801Z 53 PC: 136ea | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:26.257566635Z 53 PC: 136ea | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:26.259852818Z 53 PC: 136ea | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:26.261535931Z 53 PC: 136ea | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:26.262922176Z 53 PC: 136ea | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:26.26557493Z 53 PC: 136ea | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:26.266929152Z 53 PC: 136ea | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:26.268167499Z 53 PC: 136ea | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:26.270408198Z 53 PC: 136ea | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:26.272034797Z 53 PC: 136ea | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:53:26.2738041Z 37 PC: 136ff | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:26.28998958Z 37 PC: 13707 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:26.291179678Z 37 PC: 1370f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:26.2921386Z 37 PC: 13717 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:26.293727769Z 68 PC: 14269 | I/O control for devices (Set for = '')
2018-12-17T22:53:26.396567196Z 37 PC: 12f11 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:26.398468295Z 44 PC: 14b74 | Get time 0x14b74: mov word ptr [0x3e], cx
0x14b78: mov word ptr [0x40], dx
0x14b7c: retf
0x14b7d: mov di, 0x52
0x14b80: push ds
0x14b81: pop es
0x14b82: mov cx, 0x25aa
0x14b85: sub cx, di
0x14b87: shr cx, 1
0x14b89: xor ax, ax
0x14b8b: cld
0x14b8c: rep stosd dword ptr es:[di], eax
0x14b8e: ret
0x14b8f: add byte ptr [bx + si], al
0x14b91: add byte ptr [bx + si], al
0x14b93: add byte ptr [bx + si], al
0x14b95: add byte ptr [bx + si], al
0x14b97: add byte ptr [bx + si], al
0x14b99: add byte ptr [si], dl
0x14b9b: sbb dx, word ptr [si]
2018-12-17T22:53:26.401250087Z 48 PC: 13f8f | Get DOS version
2018-12-17T22:53:26.40415178Z 61 PC: 13e41 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:53:26.413241895Z 63 PC: 13f14 | Read file or device (Read 8001 bytes on handle 5)
2018-12-17T22:53:26.422231207Z 62 PC: 13e91 | Close file
2018-12-17T22:53:26.42455008Z 26 PC: 134f7 | Set disk transfer address
2018-12-17T22:53:26.425727765Z 78 PC: 13503 | Find first file
2018-12-17T22:53:26.433512949Z 26 PC: 134f7 | Set disk transfer address
2018-12-17T22:53:26.440262872Z 78 PC: 13503 | Find first file
2018-12-17T22:53:26.447592731Z 60 PC: 13e41 | Create or truncate file
2018-12-17T22:53:26.468584395Z 64 PC: 13f14 | Write file or device (Write 8001 bytes on handle 5)
2018-12-17T22:53:26.479199232Z 62 PC: 13e91 | Close file
2018-12-17T22:53:26.488648001Z 67 PC: 134c6 | Get or set file attributes
2018-12-17T22:53:26.499432611Z 26 PC: 1351b | Set disk transfer address
2018-12-17T22:53:26.501690049Z 79 PC: 13520 | Find next file
2018-12-17T22:53:26.509240711Z 48 PC: 13f8f | Get DOS version
2018-12-17T22:53:26.511600069Z 53 PC: 1365c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:26.513199979Z 37 PC: 13665 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:26.515667629Z 53 PC: 1365c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:26.517249536Z 37 PC: 13665 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:26.518798975Z 53 PC: 1365c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:26.521322787Z 37 PC: 13665 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:26.522895047Z 53 PC: 1365c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:26.524483438Z 37 PC: 13665 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:26.526790215Z 53 PC: 1365c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:26.528441755Z 37 PC: 13665 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:26.529770892Z 53 PC: 1365c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:26.531766917Z 37 PC: 13665 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:26.533070696Z 53 PC: 1365c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:26.534274436Z 37 PC: 13665 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:26.53542117Z 53 PC: 1365c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:26.537377935Z 37 PC: 13665 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:26.53879749Z 53 PC: 1365c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:26.540118772Z 37 PC: 13665 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:26.542336581Z 53 PC: 1365c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:26.544948623Z 37 PC: 13665 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:26.546343637Z 53 PC: 1365c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:26.54855812Z 37 PC: 13665 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:26.550139154Z 53 PC: 1365c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:26.55171462Z 37 PC: 13665 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:26.553954925Z 53 PC: 1365c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:26.555821912Z 37 PC: 13665 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:26.557374499Z 53 PC: 1365c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:26.55895998Z 37 PC: 13665 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:26.561369242Z 53 PC: 1365c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:26.562966916Z 37 PC: 13665 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:26.56449756Z 53 PC: 1365c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:26.566959108Z 37 PC: 13665 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:26.568516045Z 53 PC: 1365c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:26.570098157Z 37 PC: 13665 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:26.571978164Z 53 PC: 1365c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:26.573262873Z 37 PC: 13665 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:26.574483248Z 53 PC: 1365c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:53:26.5763836Z 37 PC: 13665 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:53:26.577760539Z 77 PC: 1364a | Get program return code
2018-12-17T22:53:26.579310837Z 37 PC: 13841 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:53:26.580577711Z 37 PC: 13841 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:53:26.582355706Z 37 PC: 13841 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:53:26.583608829Z 37 PC: 13841 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:26.584831941Z 37 PC: 13841 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:53:26.586929925Z 37 PC: 13841 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:53:26.588223232Z 37 PC: 13841 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:53:26.589480296Z 37 PC: 13841 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:53:26.591458315Z 37 PC: 13841 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:53:26.592658688Z 37 PC: 13841 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:53:26.593789889Z 37 PC: 13841 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:53:26.595568239Z 37 PC: 13841 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:53:26.596997518Z 37 PC: 13841 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:53:26.598600019Z 37 PC: 13841 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:53:26.601035032Z 37 PC: 13841 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:53:26.602154128Z 37 PC: 13841 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:53:26.603379899Z 37 PC: 13841 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:53:26.6048057Z 37 PC: 13841 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:53:26.60700683Z 37 PC: 13841 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:53:26.608510391Z 76 PC: 13880 | Terminate with return code (Return code = '0')