Sample viewer

vx.netlux.org/Virus.DOS.July16.594

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:23.839300841Z 26 PC: 12bcb | Set disk transfer address
2018-12-17T22:57:23.840496982Z 78 PC: 12bcb | Find first file
2018-12-17T22:57:23.848245551Z 67 PC: 12bcb | Get or set file attributes
2018-12-17T22:57:23.86535994Z 61 PC: 12bcb | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:57:23.872477087Z 87 PC: 12bcb | Get or set file date and time
2018-12-17T22:57:23.874576887Z 63 PC: 12bcb | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:57:23.881357407Z 87 PC: 12bcb | Get or set file date and time
2018-12-17T22:57:23.882857319Z 62 PC: 12bcb | Close file
2018-12-17T22:57:23.891367059Z 79 PC: 12bcb | Find next file
2018-12-17T22:57:23.894214334Z 67 PC: 12bcb | Get or set file attributes
2018-12-17T22:57:23.904778809Z 61 PC: 12bcb | Open file (Filename = 'PRINT.COM')
2018-12-17T22:57:23.911861055Z 87 PC: 12bcb | Get or set file date and time
2018-12-17T22:57:23.917389066Z 63 PC: 12bcb | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:57:23.923570996Z 87 PC: 12bcb | Get or set file date and time
2018-12-17T22:57:23.924907329Z 62 PC: 12bcb | Close file
2018-12-17T22:57:23.931429867Z 79 PC: 12bcb | Find next file
2018-12-17T22:57:23.933837499Z 67 PC: 12bcb | Get or set file attributes
2018-12-17T22:57:23.944259098Z 61 PC: 12bcb | Open file (Filename = 'HELLO.COM')
2018-12-17T22:57:23.951944491Z 87 PC: 12bcb | Get or set file date and time
2018-12-17T22:57:23.953778956Z 63 PC: 12bcb | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:57:23.960800688Z 87 PC: 12bcb | Get or set file date and time
2018-12-17T22:57:23.963028304Z 62 PC: 12bcb | Close file
2018-12-17T22:57:23.971043269Z 79 PC: 12bcb | Find next file
2018-12-17T22:57:23.974361983Z 67 PC: 12bcb | Get or set file attributes
2018-12-17T22:57:23.989003964Z 61 PC: 12bcb | Open file (Filename = 'PHANG.COM')
2018-12-17T22:57:23.996466967Z 87 PC: 12bcb | Get or set file date and time
2018-12-17T22:57:23.998145793Z 63 PC: 12bcb | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:57:24.006819247Z 87 PC: 12bcb | Get or set file date and time
2018-12-17T22:57:24.009162836Z 62 PC: 12bcb | Close file
2018-12-17T22:57:24.017361992Z 79 PC: 12bcb | Find next file
2018-12-17T22:57:24.020508364Z 67 PC: 12bcb | Get or set file attributes
2018-12-17T22:57:24.03248395Z 61 PC: 12bcb | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:57:24.039909Z 87 PC: 12bcb | Get or set file date and time
2018-12-17T22:57:24.041490663Z 63 PC: 12bcb | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:57:24.050185724Z 87 PC: 12bcb | Get or set file date and time
2018-12-17T22:57:24.05181494Z 62 PC: 12bcb | Close file
2018-12-17T22:57:24.059558569Z 79 PC: 12bcb | Find next file
2018-12-17T22:57:24.063640815Z 67 PC: 12bcb | Get or set file attributes
2018-12-17T22:57:24.074508934Z 61 PC: 12bcb | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:57:24.082826234Z 87 PC: 12bcb | Get or set file date and time
2018-12-17T22:57:24.08504794Z 63 PC: 12bcb | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:57:24.092527503Z 87 PC: 12bcb | Get or set file date and time
2018-12-17T22:57:24.094685163Z 62 PC: 12bcb | Close file
2018-12-17T22:57:24.103722195Z 79 PC: 12bcb | Find next file
2018-12-17T22:57:24.107365315Z 67 PC: 12bcb | Get or set file attributes
2018-12-17T22:57:24.121944539Z 61 PC: 12bcb | Open file (Filename = 'PAH.COM')
2018-12-17T22:57:24.129774072Z 87 PC: 12bcb | Get or set file date and time
2018-12-17T22:57:24.132981043Z 63 PC: 12bcb | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:57:24.138471378Z 87 PC: 12bcb | Get or set file date and time
2018-12-17T22:57:24.140029324Z 62 PC: 12bcb | Close file
2018-12-17T22:57:24.148622732Z 79 PC: 12bcb | Find next file
2018-12-17T22:57:24.151306115Z 67 PC: 12bcb | Get or set file attributes
2018-12-17T22:57:24.167230351Z 61 PC: 12bcb | Open file (Filename = 'TEST.COM')
2018-12-17T22:57:24.175410473Z 87 PC: 12bcb | Get or set file date and time
2018-12-17T22:57:24.177011893Z 63 PC: 12bcb | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:57:24.184718908Z 87 PC: 12bcb | Get or set file date and time
2018-12-17T22:57:24.187279757Z 62 PC: 12bcb | Close file
2018-12-17T22:57:24.195271779Z 79 PC: 12bcb | Find next file
2018-12-17T22:57:24.197984624Z 26 PC: 12bcb | Set disk transfer address
2018-12-17T22:57:24.215236452Z 78 PC: 12bcb | Find first file
2018-12-17T22:57:24.222098777Z 59 PC: 12bcb | Change current directory
2018-12-17T22:57:24.227108021Z 42 PC: 12bcb | Get date 0x12bcb: ret
0x12bcc: or cl, byte ptr [bp + 0x65]
0x12bcf: and byte ptr fs:[bx + di + 0x6f], bh
0x12bd4: jne 0x12c02
0x12bd6: and byte ptr [si + 0x72], al
0x12bd9: popaw
0x12bdb: insw word ptr es:[di], dx
0x12bdc: and byte ptr [bx + di + 0x6f], bh
0x12bdf: jne 0x12beb
0x12be1: inc si
0x12be2: imul bp, word ptr [bp + 0x64], 0x7920
0x12be7: outsw dx, word ptr [si]
0x12be8: jne 0x12c16
0x12bea: and byte ptr [si + 0x61], dl
0x12bed: jae 0x12c63
0x12bef: and byte ptr gs:[bx + di + 0x6f], bh
0x12bf3: jne 0x12bff
0x12bf5: inc si
0x12bf6: jne 0x12c5b
0x12bf8: imul sp, word ptr [bx + si], 0x79