Sample viewer

vx.netlux.org/Virus.DOS.Whale

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:45.219811513Z 82 PC: 12b1d | Get DOS internal pointers (SYSVARS)
2018-12-17T22:56:45.222132145Z 97 PC: 12b58 | Reserved
2018-12-17T22:56:45.233911251Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:56:45.238863449Z 72 PC: 12174 | Allocate memory
2018-12-17T22:56:45.245514999Z 72 PC: 1218d | Allocate memory
2018-12-17T22:56:45.252152353Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:56:45.256682073Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:56:45.261743917Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:45.26647336Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:56:45.268486773Z 62 PC: 122ab | Close file
2018-12-17T22:56:45.273977671Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:56:45.275555221Z 62 PC: 122ab | Close file
2018-12-17T22:56:45.280882362Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:56:45.283213964Z 62 PC: 122ab | Close file
2018-12-17T22:56:45.287904713Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:56:45.289609215Z 62 PC: 122ab | Close file
2018-12-17T22:56:45.29449394Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:56:45.296605629Z 62 PC: 122ab | Close file
2018-12-17T22:56:45.301437463Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:56:45.303364054Z 62 PC: 122ab | Close file
2018-12-17T22:56:45.308486897Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:56:45.310405504Z 62 PC: 122ab | Close file
2018-12-17T22:56:45.315321783Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:56:45.317823626Z 62 PC: 122ab | Close file
2018-12-17T22:56:45.322707136Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:56:45.324571394Z 62 PC: 122ab | Close file
2018-12-17T22:56:45.32848853Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:56:45.330195319Z 62 PC: 122ab | Close file
2018-12-17T22:56:45.335193277Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:56:45.337562954Z 62 PC: 122ab | Close file
2018-12-17T22:56:45.341985184Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:56:45.343359006Z 62 PC: 122ab | Close file
2018-12-17T22:56:45.348261627Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:56:45.349655994Z 62 PC: 122ab | Close file
2018-12-17T22:56:45.354689572Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:56:45.356639186Z 62 PC: 122ab | Close file
2018-12-17T22:56:45.361511199Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:56:45.363344796Z 62 PC: 122ab | Close file
2018-12-17T22:56:45.375786471Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:56:45.378829083Z 54 PC: 9fa6e | Get free disk space
2018-12-17T22:56:45.419272033Z 67 PC: 9fa6e | Get or set file attributes
2018-12-17T22:56:45.428210271Z 67 PC: 9fa6e | Get or set file attributes
2018-12-17T22:56:45.771965985Z 61 PC: 9fa6e | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:56:45.776090365Z 50 PC: 9fa6e | Get disk parameter block for specified drive
2018-12-17T22:56:45.78247074Z 66 PC: 12372 | Move file pointer
2018-12-17T22:56:45.786715059Z 68 PC: 9fa6e | I/O control for devices (Set for = '�mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T22:56:45.788034833Z 87 PC: 9fa6e | Get or set file date and time
2018-12-17T22:56:45.790625315Z 63 PC: 12383 | Read file or device (Read 44693 bytes on handle 5)
2018-12-17T22:56:45.805926085Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:56:45.808293194Z 87 PC: 9fa6e | Get or set file date and time
2018-12-17T22:56:45.810620355Z 66 PC: 9fa6e | Move file pointer
2018-12-17T22:56:45.811905008Z 63 PC: 9fa6e | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:56:45.818198263Z 66 PC: 9fa6e | Move file pointer
2018-12-17T22:56:45.819994258Z 63 PC: 9fa6e | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:56:45.82235095Z 66 PC: 9fa6e | Move file pointer
2018-12-17T22:56:45.824125803Z 42 PC: 9fa6e | Get date 0x9fa6e: ret
0x9fa6f: add bl, ch
0x9fa71: add dl, byte ptr [bx + si - 0x1800]
0x9fa75: push dx
0x9fa76: sahf
0x9fa77: xchg ax, bp
0x9fa78: scasw ax, word ptr es:[di]
0x9fa79: xchg ax, bp
0x9fa7a: push di
0x9fa7c: adc word ptr [bx + 0x11], dx
0x9fa7f: xchg ax, bp
0x9fa80: scasb al, byte ptr es:[di]
0x9fa81: add ax, 0x4500
0x9fa84: add byte ptr [bp + si + 0x10], bl
0x9fa88: mov word ptr [bx + 0xe], si
0x9fa8b: or ax, word ptr [bx + si]
0x9fa8d: js 0x9fad5
0x9fa8f: jo 0x9fa91
0x9fa91: add word ptr [0x9a00], dx
0x9fa95: adc dh, al
2018-12-17T22:56:45.827369439Z 62 PC: 9fa6e | Close file
2018-12-17T22:56:45.829362837Z 67 PC: 9fa6e | Get or set file attributes
2018-12-17T22:56:45.842833208Z 99 PC: 97ed7 | Get DBCS lead byte table pointer
2018-12-17T22:56:45.848501617Z 56 PC: 926f9 | Get or set country info
2018-12-17T22:56:45.853772208Z 64 PC: 98148 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:56:45.861469556Z 25 PC: 92762 | Get default drive
2018-12-17T22:56:45.867491409Z 71 PC: 949dd | Get current directory
2018-12-17T22:56:45.875132983Z 64 PC: 98148 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:56:45.8829877Z 2 PC: 949b2 | Character output (Char = '3e')
2018-12-17T22:56:45.892811278Z 93 PC: 92820 | File sharing functions
2018-12-17T22:56:45.898275704Z 93 PC: 92827 | File sharing functions
2018-12-17T22:56:45.903846897Z 10 PC: 92839 | Buffered keyboard input
2018-12-17T22:57:00.20138246Z 0 PC: 0 | Program terminate
2018-12-17T22:57:01.555916129Z 0 PC: 0 | Program terminate
2018-12-17T22:57:01.661549874Z 64 PC: 98148 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:57:01.67271496Z 41 PC: 928ae | Parse filename
2018-12-17T22:57:01.677725061Z 41 PC: 9292f | Parse filename
2018-12-17T22:57:01.683308826Z 41 PC: 9294c | Parse filename
2018-12-17T22:57:01.688786725Z 26 PC: 95df7 | Set disk transfer address
2018-12-17T22:57:01.69390243Z 71 PC: 95ff3 | Get current directory
2018-12-17T22:57:01.705249052Z 78 PC: 9fa6e | Find first file
2018-12-17T22:57:01.715955711Z 47 PC: 9fa6e | Get disk transfer address
2018-12-17T22:57:01.720277441Z 71 PC: 95e6c | Get current directory
2018-12-17T22:57:01.726878914Z 73 PC: 95509 | Release memory
2018-12-17T22:57:01.731433767Z 75 PC: 9dfa2 | Execute program
2018-12-17T22:57:01.745093086Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:57:01.749381383Z 54 PC: 9fa6e | Get free disk space
2018-12-17T22:57:01.760072861Z 67 PC: 9fa6e | Get or set file attributes
2018-12-17T22:57:01.766150922Z 67 PC: 9fa6e | Get or set file attributes
2018-12-17T22:57:01.78869471Z 61 PC: 9fa6e | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T22:57:01.795531015Z 50 PC: 9fa6e | Get disk parameter block for specified drive
2018-12-17T22:57:01.800241904Z 87 PC: 9fa6e | Get or set file date and time
2018-12-17T22:57:01.80263801Z 66 PC: 9fa6e | Move file pointer
2018-12-17T22:57:01.803981646Z 63 PC: 9fa6e | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:57:01.810161099Z 66 PC: 9fa6e | Move file pointer
2018-12-17T22:57:01.812470842Z 63 PC: 9fa6e | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:57:01.81483168Z 66 PC: 9fa6e | Move file pointer
2018-12-17T22:57:01.816639003Z 42 PC: 9fa6e | Get date 0x9fa6e: ret
0x9fa6f: add bl, ch
0x9fa71: add dl, byte ptr [bx + si - 0x1800]
0x9fa75: add byte ptr [bx + di], al
0x9fa77: add byte ptr [bx + di], al
0x9fa79: add byte ptr [bp + di + 0x57], cl
0x9fa7c: adc word ptr [bx + 0x11], dx
0x9fa7f: push di
0x9fa80: adc word ptr [bx], cx
0x9fa82: add ax, 0x45
0x9fa85: lcall 0x7789:0x10
0x9fa8a: push cs
0x9fa8b: or ax, word ptr [bx + si]
0x9fa8d: js 0x9fad5
0x9fa8f: jo 0x9fac6
0x9fa91: add ax, 0x16
0x9fa94: lcall 0x4d06:0xc610
0x9fa99: or bh, bh
0x9fa9b: jmp 0x9f6ec
0x9fa9e: call 0x9ff9e
2018-12-17T22:57:01.819912067Z 62 PC: 9fa6e | Close file
2018-12-17T22:57:01.821915863Z 67 PC: 9fa6e | Get or set file attributes
2018-12-17T22:57:01.832912693Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:57:01.837153522Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T22:57:01.845250958Z 76 PC: 12a4b | Terminate with return code (Return code = '36')
2018-12-17T22:57:01.851755752Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:57:01.856996493Z 72 PC: 12174 | Allocate memory
2018-12-17T22:57:01.861875643Z 72 PC: 1218d | Allocate memory
2018-12-17T22:57:01.86669341Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:57:01.871452278Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:01.877484629Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:01.881742574Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:57:01.883980739Z 62 PC: 122ab | Close file
2018-12-17T22:57:01.88904956Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:57:01.890500593Z 62 PC: 122ab | Close file
2018-12-17T22:57:01.8953672Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:57:01.897019445Z 62 PC: 122ab | Close file
2018-12-17T22:57:01.901604515Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:57:01.903890495Z 62 PC: 122ab | Close file
2018-12-17T22:57:01.908446748Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:57:01.910108772Z 62 PC: 122ab | Close file
2018-12-17T22:57:01.916073027Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:57:01.917367006Z 62 PC: 122ab | Close file
2018-12-17T22:57:01.929216919Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:57:01.930800154Z 62 PC: 122ab | Close file
2018-12-17T22:57:01.935041674Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:57:01.936294373Z 62 PC: 122ab | Close file
2018-12-17T22:57:01.940953316Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:57:01.94260371Z 62 PC: 122ab | Close file
2018-12-17T22:57:01.947088552Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:57:01.949479691Z 62 PC: 122ab | Close file
2018-12-17T22:57:01.955518748Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:57:01.956980361Z 62 PC: 122ab | Close file
2018-12-17T22:57:01.96208909Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:57:01.963805131Z 62 PC: 122ab | Close file
2018-12-17T22:57:01.971299005Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:57:01.973384452Z 62 PC: 122ab | Close file
2018-12-17T22:57:01.977836355Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:57:01.979382986Z 62 PC: 122ab | Close file
2018-12-17T22:57:01.985321264Z 81 PC: 9fa6e | Get current PSP
2018-12-17T22:57:01.986755961Z 62 PC: 122ab | Close file
2018-12-17T22:57:01.992738215Z 99 PC: 97ed7 | Get DBCS lead byte table pointer
2018-12-17T22:57:01.998237466Z 56 PC: 926f9 | Get or set country info
2018-12-17T22:57:02.003903729Z 64 PC: 98148 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:57:02.011645457Z 25 PC: 92762 | Get default drive
2018-12-17T22:57:02.018067021Z 71 PC: 949dd | Get current directory
2018-12-17T22:57:02.025434971Z 64 PC: 98148 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:57:02.031897741Z 2 PC: 949b2 | Character output (Char = '3e')
2018-12-17T22:57:02.038515658Z 93 PC: 92820 | File sharing functions
2018-12-17T22:57:02.044227693Z 93 PC: 92827 | File sharing functions
2018-12-17T22:57:02.050119987Z 10 PC: 92839 | Buffered keyboard input