Sample viewer

vx.netlux.org/Virus.DOS.NTZ.333.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:20.823329401Z 26 PC: 12ac2 | Set disk transfer address
2018-12-17T22:54:20.824606163Z 78 PC: 12aca | Find first file
2018-12-17T22:54:20.831727127Z 47 PC: 12ad6 | Get disk transfer address
2018-12-17T22:54:20.833564354Z 61 PC: 12ae6 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:54:20.841707403Z 87 PC: 12aec | Get or set file date and time
2018-12-17T22:54:20.844581664Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:54:20.852723022Z 66 PC: 12b1e | Move file pointer
2018-12-17T22:54:20.855906637Z 64 PC: 12b29 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:54:20.860224669Z 66 PC: 12b32 | Move file pointer
2018-12-17T22:54:20.862472462Z 44 PC: 12a6b | Get time 0x12a6b: mov byte ptr [bp + 0x121], cl
0x12a6f: mov cx, 0xde
0x12a72: lea si, word ptr [bp + 0x16f]
0x12a76: lea di, word ptr [bp + 0x235]
0x12a7a: movsb byte ptr es:[di], byte ptr [si]
0x12a7b: mov al, byte ptr [bp + 0x235]
0x12a7f: xor al, byte ptr [bp + 0x121]
0x12a83: mov byte ptr [bp + 0x235], al
0x12a87: lea di, word ptr [si - 1]
0x12a8a: lea si, word ptr [bp + 0x235]
0x12a8e: movsb byte ptr es:[di], byte ptr [si]
0x12a8f: mov si, di
0x12a91: loop 0x12a76
0x12a93: ret
0x12a94: jmp 0x12aaf
0x12a96: nop
0x12a97: call 0x22a67
0x12a9a: mov ah, 0x40
0x12a9c: mov cx, 0x14d
0x12a9f: lea dx, word ptr [bp + 0x100]
2018-12-17T22:54:20.865969224Z 64 PC: 12aa5 | Write file or device (Write 333 bytes on handle 5)
2018-12-17T22:54:20.885478933Z 87 PC: 12b44 | Get or set file date and time
2018-12-17T22:54:20.888312706Z 62 PC: 12b48 | Close file
2018-12-17T22:54:20.897219267Z 79 PC: 12aca | Find next file
2018-12-17T22:54:20.901035263Z 47 PC: 12ad6 | Get disk transfer address
2018-12-17T22:54:20.90298988Z 61 PC: 12ae6 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:54:20.910756583Z 87 PC: 12aec | Get or set file date and time
2018-12-17T22:54:20.912795785Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:54:20.920737735Z 66 PC: 12b1e | Move file pointer
2018-12-17T22:54:20.922943238Z 64 PC: 12b29 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:54:20.926243313Z 66 PC: 12b32 | Move file pointer
2018-12-17T22:54:20.928845652Z 44 PC: 12a6b | Get time 0x12a6b: mov byte ptr [bp + 0x121], cl
0x12a6f: mov cx, 0xde
0x12a72: lea si, word ptr [bp + 0x16f]
0x12a76: lea di, word ptr [bp + 0x235]
0x12a7a: movsb byte ptr es:[di], byte ptr [si]
0x12a7b: mov al, byte ptr [bp + 0x235]
0x12a7f: xor al, byte ptr [bp + 0x121]
0x12a83: mov byte ptr [bp + 0x235], al
0x12a87: lea di, word ptr [si - 1]
0x12a8a: lea si, word ptr [bp + 0x235]
0x12a8e: movsb byte ptr es:[di], byte ptr [si]
0x12a8f: mov si, di
0x12a91: loop 0x12a76
0x12a93: ret
0x12a94: jmp 0x12aaf
0x12a96: nop
0x12a97: call 0x22a67
0x12a9a: mov ah, 0x40
0x12a9c: mov cx, 0x14d
0x12a9f: lea dx, word ptr [bp + 0x100]
2018-12-17T22:54:20.931999206Z 64 PC: 12aa5 | Write file or device (Write 333 bytes on handle 5)
2018-12-17T22:54:20.93571126Z 87 PC: 12b44 | Get or set file date and time
2018-12-17T22:54:20.942996679Z 62 PC: 12b48 | Close file
2018-12-17T22:54:20.9516732Z 79 PC: 12aca | Find next file
2018-12-17T22:54:20.955016337Z 47 PC: 12ad6 | Get disk transfer address
2018-12-17T22:54:20.958139355Z 61 PC: 12ae6 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:54:20.969261261Z 87 PC: 12aec | Get or set file date and time
2018-12-17T22:54:20.971296218Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:54:20.979304603Z 66 PC: 12b1e | Move file pointer
2018-12-17T22:54:20.981079393Z 64 PC: 12b29 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:54:20.984292269Z 66 PC: 12b32 | Move file pointer
2018-12-17T22:54:20.986507363Z 44 PC: 12a6b | Get time 0x12a6b: mov byte ptr [bp + 0x121], cl
0x12a6f: mov cx, 0xde
0x12a72: lea si, word ptr [bp + 0x16f]
0x12a76: lea di, word ptr [bp + 0x235]
0x12a7a: movsb byte ptr es:[di], byte ptr [si]
0x12a7b: mov al, byte ptr [bp + 0x235]
0x12a7f: xor al, byte ptr [bp + 0x121]
0x12a83: mov byte ptr [bp + 0x235], al
0x12a87: lea di, word ptr [si - 1]
0x12a8a: lea si, word ptr [bp + 0x235]
0x12a8e: movsb byte ptr es:[di], byte ptr [si]
0x12a8f: mov si, di
0x12a91: loop 0x12a76
0x12a93: ret
0x12a94: jmp 0x12aaf
0x12a96: nop
0x12a97: call 0x22a67
0x12a9a: mov ah, 0x40
0x12a9c: mov cx, 0x14d
0x12a9f: lea dx, word ptr [bp + 0x100]
2018-12-17T22:54:20.990227183Z 64 PC: 12aa5 | Write file or device (Write 333 bytes on handle 5)
2018-12-17T22:54:20.993964092Z 87 PC: 12b44 | Get or set file date and time
2018-12-17T22:54:20.995809395Z 62 PC: 12b48 | Close file
2018-12-17T22:54:21.004140976Z 26 PC: 12b5c | Set disk transfer address