Sample viewer

vx.netlux.org/Virus.DOS.Gobot.2099

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:00:51.010771123Z 53 PC: 12a56 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:00:51.012474742Z 37 PC: 12a66 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:00:51.013741668Z 78 PC: 12a75 | Find first file
2018-12-17T22:00:51.01963868Z 61 PC: 12a7f | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:00:51.027229715Z 63 PC: 12a8a | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:00:51.033495036Z 44 PC: 12ade | Get time 0x12ade: xor dh, dh
0x12ae0: and dl, 7
0x12ae3: cmp dx, 6
0x12ae6: jg 0x12ada
0x12ae8: push dx
0x12ae9: add dx, 0x72f
0x12aed: mov si, dx
0x12aef: mov dl, byte ptr cs:[si]
0x12af2: mov byte ptr [0x103], dl
0x12af6: pop dx
0x12af7: push dx
0x12af8: add dx, 0x744
0x12afc: mov si, dx
0x12afe: mov dl, byte ptr cs:[si]
0x12b01: mov byte ptr [0x100], dl
0x12b05: mov ah, 0x2c
0x12b07: int 0x21
0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
2018-12-17T22:00:51.035558178Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x736
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73d
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:00:51.03763409Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x736
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73d
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:00:51.04070704Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x736
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73d
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:00:51.04291236Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x736
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73d
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:00:51.045142195Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x736
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73d
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:00:51.048914785Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x736
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73d
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:00:51.051371331Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x736
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73d
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:00:51.053792681Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x736
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73d
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:00:51.063478238Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x736
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73d
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:00:51.066508515Z 66 PC: 12b3f | Move file pointer
2018-12-17T22:00:51.067946254Z 44 PC: 12b44 | Get time 0x12b44: mov word ptr [0x92f], dx
0x12b48: mov si, 0x2d8
0x12b4b: mov di, 0x937
0x12b4e: mov cx, 0x1a
0x12b51: rep movsb byte ptr es:[di], byte ptr [si]
0x12b53: call 0x13277
0x12b56: mov ah, 0x3e
0x12b58: int 0x21
0x12b5a: mov ah, 9
0x12b5c: mov dx, 0x74b
0x12b5f: int 0x21
0x12b61: int 0x20
0x12b63: mov ah, 0xf
0x12b65: int 0x10
0x12b67: xor ah, ah
0x12b69: int 0x10
0x12b6b: mov ah, 1
0x12b6d: mov cx, 0x2607
0x12b70: int 0x10
0x12b72: mov ax, 0xb800
2018-12-17T22:00:51.07020405Z 64 PC: 13289 | Write file or device (Write 2099 bytes on handle 5)
2018-12-17T22:00:51.08210913Z 62 PC: 12b5a | Close file
2018-12-17T22:00:51.347918291Z 9 PC: 12b61 | Display string (String= 'Parameter value not in allowed range ')