Sample viewer

vx.netlux.org/Virus.DOS.VCL.Vegeta.555

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:08.401845423Z 47 PC: 18460 | Get disk transfer address
2018-12-17T22:54:08.403605795Z 42 PC: 18585 | Get date 0x18585: mov al, dl
0x18587: cwde
0x18588: ret
0x18589: mov ah, 0x2f
0x1858b: int 0x21
0x1858d: mov si, bx
0x1858f: mov byte ptr [di + 0x300], 0
0x18594: cmp word ptr [si + 0x1a], 0xfcd4
0x18599: jbe 0x1859e
0x1859b: jmp 0x1862e
0x1859e: mov ax, 0x3d00
0x185a1: lea dx, word ptr [si + 0x1e]
0x185a4: int 0x21
0x185a6: xchg ax, bx
0x185a7: mov ah, 0x3e
0x185a9: lea dx, word ptr [di + 0x301]
0x185ad: add ah, 1
0x185b0: mov cx, 3
0x185b3: int 0x21
0x185b5: mov ax, 0x4202
2018-12-17T22:54:08.40589375Z 26 PC: 1847d | Set disk transfer address
2018-12-17T22:54:08.407164587Z 71 PC: 184b1 | Get current directory
2018-12-17T22:54:08.411343225Z 59 PC: 184d1 | Change current directory
2018-12-17T22:54:08.41726285Z 47 PC: 18550 | Get disk transfer address
2018-12-17T22:54:08.418733664Z 26 PC: 18562 | Set disk transfer address
2018-12-17T22:54:08.420836831Z 78 PC: 1856a | Find first file
2018-12-17T22:54:08.426745966Z 47 PC: 1858d | Get disk transfer address
2018-12-17T22:54:08.427804732Z 61 PC: 185a6 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:54:08.435199171Z 63 PC: 185b5 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:54:08.441605684Z 66 PC: 185bd | Move file pointer
2018-12-17T22:54:08.442968906Z 62 PC: 185c2 | Close file
2018-12-17T22:54:08.444923734Z 67 PC: 185e5 | Get or set file attributes
2018-12-17T22:54:08.46407493Z 61 PC: 185ea | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:54:08.475646302Z 64 PC: 185f9 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:54:08.48204116Z 66 PC: 18601 | Move file pointer
2018-12-17T22:54:08.483705842Z 64 PC: 1860c | Write file or device (Write 555 bytes on handle 5)
2018-12-17T22:54:08.491653237Z 87 PC: 1861a | Get or set file date and time
2018-12-17T22:54:08.493192798Z 62 PC: 1861e | Close file
2018-12-17T22:54:08.50248378Z 67 PC: 1862e | Get or set file attributes
2018-12-17T22:54:08.51254162Z 26 PC: 1857c | Set disk transfer address
2018-12-17T22:54:08.513695317Z 59 PC: 184ea | Change current directory
2018-12-17T22:54:08.518628793Z 26 PC: 18485 | Set disk transfer address
2018-12-17T22:54:08.520225863Z 74 PC: 13861 | Reallocate memory
2018-12-17T22:54:08.521997325Z 67 PC: 12c66 | Get or set file attributes
2018-12-17T22:54:08.529413578Z 81 PC: 15eb3 | Get current PSP
2018-12-17T22:54:08.530551387Z 61 PC: 15f0c | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:54:08.542150526Z 66 PC: 15f77 | Move file pointer
2018-12-17T22:54:08.544605291Z 63 PC: 15f8f | Read file or device (Read 7 bytes on handle 5)
2018-12-17T22:54:08.551357023Z 66 PC: 15fb4 | Move file pointer
2018-12-17T22:54:08.552954404Z 63 PC: 15fc0 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:54:08.560601294Z 62 PC: 15f22 | Close file
2018-12-17T22:54:08.562816791Z 48 PC: 16142 | Get DOS version
2018-12-17T22:54:08.56430407Z 48 PC: 140f5 | Get DOS version
2018-12-17T22:54:08.566666518Z 9 PC: 13c4e | Display string (String= 'ck�� �!j�W�!/%���')
2018-12-17T22:54:08.581650989Z 76 PC: 13c42 | Terminate with return code (Return code = '255')