Sample viewer

vx.netlux.org/Virus.DOS.Vole.491

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:23.657688614Z 26 PC: 12a90 | Set disk transfer address
2018-12-17T22:55:23.6592019Z 37 PC: 12a9e | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:55:23.661889435Z 37 PC: 12aa2 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:55:23.663446934Z 78 PC: 12aee | Find first file
2018-12-17T22:55:23.670250911Z 61 PC: 12bbf | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:55:23.678323604Z 63 PC: 12bce | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:23.685630898Z 66 PC: 12bdd | Move file pointer
2018-12-17T22:55:23.687375569Z 66 PC: 12bec | Move file pointer
2018-12-17T22:55:23.693920148Z 64 PC: 12bf8 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:55:23.699984775Z 66 PC: 12c04 | Move file pointer
2018-12-17T22:55:23.702089633Z 44 PC: 12c08 | Get time 0x12c08: mov byte ptr [bp + 0x1eb], dl
0x12c0c: call 0x12c22
0x12c0f: mov ah, 0x40
0x12c11: mov cx, 0x1eb
0x12c14: lea dx, word ptr [bp + 6]
0x12c18: int 0x21
0x12c1a: call 0x12c22
0x12c1d: mov ah, 0x3e
0x12c1f: int 0x21
0x12c21: ret
0x12c22: lea si, word ptr [bp + 0x33]
0x12c26: mov cx, 0x199
0x12c29: xor byte ptr [si], 0
0x12c2c: inc si
0x12c2d: dec cx
0x12c2e: jne 0x12c29
0x12c30: ret
0x12c31: add word ptr [bx], di
0x12c33: aas
0x12c34: aas
2018-12-17T22:55:23.705357781Z 64 PC: 12c1a | Write file or device (Write 491 bytes on handle 5)
2018-12-17T22:55:23.718364815Z 62 PC: 12c21 | Close file
2018-12-17T22:55:23.739378878Z 79 PC: 12aee | Find next file
2018-12-17T22:55:23.742919577Z 61 PC: 12bbf | Open file (Filename = 'PRINT.COM')
2018-12-17T22:55:23.751414174Z 63 PC: 12bce | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:23.758428396Z 66 PC: 12bdd | Move file pointer
2018-12-17T22:55:23.760121551Z 66 PC: 12bec | Move file pointer
2018-12-17T22:55:23.785785279Z 64 PC: 12bf8 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:55:23.788783409Z 66 PC: 12c04 | Move file pointer
2018-12-17T22:55:23.790380242Z 44 PC: 12c08 | Get time 0x12c08: mov byte ptr [bp + 0x1eb], dl
0x12c0c: call 0x12c22
0x12c0f: mov ah, 0x40
0x12c11: mov cx, 0x1eb
0x12c14: lea dx, word ptr [bp + 6]
0x12c18: int 0x21
0x12c1a: call 0x12c22
0x12c1d: mov ah, 0x3e
0x12c1f: int 0x21
0x12c21: ret
0x12c22: lea si, word ptr [bp + 0x33]
0x12c26: mov cx, 0x199
0x12c29: xor byte ptr [si], 0x3e
0x12c2c: inc si
0x12c2d: dec cx
0x12c2e: jne 0x12c29
0x12c30: ret
0x12c31: add word ptr [bx], di
0x12c33: aas
0x12c34: aas
2018-12-17T22:55:23.793944966Z 64 PC: 12c1a | Write file or device (Write 491 bytes on handle 5)
2018-12-17T22:55:23.804392987Z 62 PC: 12c21 | Close file
2018-12-17T22:55:23.81389046Z 26 PC: 12b08 | Set disk transfer address
2018-12-17T22:55:23.816797508Z 9 PC: 12b14 | Display string (Could not find end pointer)
2018-12-17T22:55:23.827381173Z 9 PC: 12b29 | Display string (String= ' Inherit the Wind !!! ')