Sample viewer

vx.netlux.org/Virus.DOS.BackFormat.2381

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:00.050444436Z 92 PC: 16817 | Lock or unlock file
2018-12-17T22:57:00.053968041Z 82 PC: 1681e | Get DOS internal pointers (SYSVARS)
2018-12-17T22:57:00.055687914Z 61 PC: 16868 | Open file (Filename = '')
2018-12-17T22:57:00.062639654Z 63 PC: 1687a | Read file or device (Read 32 bytes on handle 5)
2018-12-17T22:57:00.067043413Z 42 PC: 12b93 | Get date 0x12b93: test al, 1
0x12b95: jne 0x12ba2
0x12b97: cmp dh, 0xb
0x12b9a: je 0x12ba2
0x12b9c: mov byte ptr cs:[0xa04], 0xfe
0x12ba2: xor cx, cx
0x12ba4: xor dx, dx
0x12ba6: mov ax, 0x4202
0x12ba9: int 0x21
0x12bab: sub ax, 0x947
0x12bae: mov word ptr cs:[0x87d], ax
0x12bb2: mov dx, word ptr [0xb07]
0x12bb6: add dx, 3
0x12bb9: mov ax, 0x4200
0x12bbc: int 0x21
0x12bbe: mov word ptr cs:[0xafa], ax
0x12bc2: mov dx, 0xb06
0x12bc5: mov cx, 0x20
0x12bc8: mov ax, 0x3f00
0x12bcb: int 0x21
2018-12-17T22:57:00.07006262Z 66 PC: 12bab | Move file pointer
2018-12-17T22:57:00.07213724Z 66 PC: 12bbe | Move file pointer
2018-12-17T22:57:00.075007556Z 63 PC: 12bcd | Read file or device (Read 32 bytes on handle 5)
2018-12-17T22:57:00.087293365Z 87 PC: 12bf8 | Get or set file date and time
2018-12-17T22:57:00.093515673Z 66 PC: 12c09 | Move file pointer
2018-12-17T22:57:00.095374588Z 66 PC: 12c28 | Move file pointer
2018-12-17T22:57:00.098189561Z 98 PC: 12c2e | Get current PSP
2018-12-17T22:57:00.099366523Z 48 PC: 12c44 | Get DOS version
2018-12-17T22:57:00.101218535Z 82 PC: 12c5b | Get DOS internal pointers (SYSVARS)
2018-12-17T22:57:00.104605122Z 64 PC: 1347d | Write file or device (Write 2365 bytes on handle 5)
2018-12-17T22:57:00.44704829Z 66 PC: 12f2c | Move file pointer
2018-12-17T22:57:00.44961765Z 64 PC: 12f36 | Write file or device (Write 32 bytes on handle 5)
2018-12-17T22:57:00.454863512Z 87 PC: 12f47 | Get or set file date and time
2018-12-17T22:57:00.45736235Z 66 PC: 12f7c | Move file pointer
2018-12-17T22:57:00.459585019Z 87 PC: 12f9c | Get or set file date and time
2018-12-17T22:57:00.462976375Z 63 PC: 12fbc | Read file or device (Read 32 bytes on handle 5)
2018-12-17T22:57:00.467747365Z 66 PC: 12ff1 | Move file pointer
2018-12-17T22:57:00.470523184Z 63 PC: 13000 | Read file or device (Read 32 bytes on handle 5)
2018-12-17T22:57:00.475067988Z 62 PC: 12c9c | Close file
2018-12-17T22:57:00.483840812Z 74 PC: 12ca5 | Reallocate memory
2018-12-17T22:57:00.486113185Z 82 PC: 12ca9 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:57:00.488140025Z 73 PC: 12cd5 | Release memory
2018-12-17T22:57:00.491331635Z 75 PC: 12d38 | Execute program
2018-12-17T22:57:00.512810848Z 98 PC: 15ba8 | Get current PSP
2018-12-17T22:57:00.514578852Z 74 PC: 15be7 | Reallocate memory
2018-12-17T22:57:00.518049717Z 82 PC: 15bed | Get DOS internal pointers (SYSVARS)
2018-12-17T22:57:00.520099772Z 25 PC: 16c43 | Get default drive
2018-12-17T22:57:00.522110773Z 13 PC: 16bf8 | Disk reset
2018-12-17T22:57:00.526294017Z 99 PC: 147db | Get DBCS lead byte table pointer
2018-12-17T22:57:00.528000425Z 68 PC: 147f5 | I/O control for devices (Set for = '')
2018-12-17T22:57:00.53006139Z 68 PC: 14800 | I/O control for devices (Set for = '')
2018-12-17T22:57:00.532482382Z 68 PC: 1480b | I/O control for devices (Set for = '')
2018-12-17T22:57:00.535345855Z 68 PC: 14813 | I/O control for devices (Set for = '��b���g�t�S3����[r�2��W�<t�<u�6�u����>��>W')
2018-12-17T22:57:00.537586758Z 48 PC: 14818 | Get DOS version
2018-12-17T22:57:00.541119069Z 64 PC: 14a91 | Write file or device (Write 23 bytes on handle 2)
2018-12-17T22:57:00.546730469Z 76 PC: 16c21 | Terminate with return code (Return code = '0')