Sample viewer

vx.netlux.org/Virus.DOS.VCL.Lemenu.903

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:28.979223426Z 37 PC: 12b5a | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:57:28.980879398Z 37 PC: 12b5e | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:57:28.983891681Z 74 PC: 12b72 | Reallocate memory
2018-12-17T22:57:28.987347468Z 81 PC: 12145 | Get current PSP
2018-12-17T22:57:28.988616353Z 80 PC: 12152 | Set current PSP
2018-12-17T22:57:28.990681846Z 72 PC: 12174 | Allocate memory
2018-12-17T22:57:28.992897782Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:57:28.996075065Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T22:57:29.001995795Z 2 PC: 1268d | Character output (Char = '4d')
2018-12-17T22:57:29.008152129Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:57:29.013076356Z 2 PC: 1268d | Character output (Char = '6d')
2018-12-17T22:57:29.016040708Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:57:29.024537913Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:57:29.029274837Z 2 PC: 1268d | Character output (Char = '79')
2018-12-17T22:57:29.032928917Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:57:29.038472919Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:57:29.040683695Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:57:29.042808259Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:57:29.046152235Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:57:29.048578286Z 2 PC: 1268d | Character output (Char = '63')
2018-12-17T22:57:29.051119103Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:57:29.054766539Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:57:29.057766098Z 2 PC: 1268d | Character output (Char = '69')
2018-12-17T22:57:29.06132046Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:57:29.063921991Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:57:29.066920638Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:57:29.069468667Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:57:29.07202324Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:57:29.076685204Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:57:29.082104091Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:57:29.084438259Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:57:29.102344761Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:57:29.104686594Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T22:57:29.108992619Z 2 PC: 1268d | Character output (Char = '43')
2018-12-17T22:57:29.114633393Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:57:29.118069993Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:57:29.121053542Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:57:29.126321395Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:57:29.130677314Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:57:29.136214073Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:57:29.139279415Z 2 PC: 1268d | Character output (Char = '73')
2018-12-17T22:57:29.143874593Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:57:29.146361528Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:57:29.149039603Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:57:29.151626587Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:57:29.154053639Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:57:29.156617178Z 2 PC: 1268d | Character output (Char = '43')
2018-12-17T22:57:29.160802516Z 2 PC: 1268d | Character output (Char = '4f')
2018-12-17T22:57:29.164160599Z 2 PC: 1268d | Character output (Char = '4d')
2018-12-17T22:57:29.166450163Z 2 PC: 1268d | Character output (Char = '4d')
2018-12-17T22:57:29.170138006Z 2 PC: 1268d | Character output (Char = '41')
2018-12-17T22:57:29.172711944Z 2 PC: 1268d | Character output (Char = '4e')
2018-12-17T22:57:29.17593299Z 2 PC: 1268d | Character output (Char = '44')
2018-12-17T22:57:29.179892153Z 2 PC: 1268d | Character output (Char = '2c')
2018-12-17T22:57:29.182267759Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:57:29.184650628Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:57:29.1871997Z 2 PC: 1268d | Character output (Char = '78')
2018-12-17T22:57:29.189991709Z 2 PC: 1268d | Character output (Char = '69')
2018-12-17T22:57:29.192282636Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:57:29.194559716Z 2 PC: 1268d | Character output (Char = '69')
2018-12-17T22:57:29.197939489Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:57:29.20431214Z 2 PC: 1268d | Character output (Char = '67')
2018-12-17T22:57:29.207468113Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:57:29.21197199Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T22:57:29.215971638Z 73 PC: 1210b | Release memory
2018-12-17T22:57:29.217709846Z 80 PC: 12113 | Set current PSP
2018-12-17T22:57:29.219734292Z 71 PC: 12c4a | Get current directory
2018-12-17T22:57:29.222862222Z 59 PC: 12c51 | Change current directory
2018-12-17T22:57:29.227090931Z 47 PC: 12c66 | Get disk transfer address
2018-12-17T22:57:29.22885597Z 26 PC: 12c74 | Set disk transfer address
2018-12-17T22:57:29.230072667Z 78 PC: 12c7e | Find first file
2018-12-17T22:57:29.237467158Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.242785115Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.246009927Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.249116888Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.252414287Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.255582723Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.259174115Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.262277028Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.266132035Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.268806973Z 47 PC: 12ccd | Get disk transfer address
2018-12-17T22:57:29.270362117Z 26 PC: 12cdc | Set disk transfer address
2018-12-17T22:57:29.272745387Z 78 PC: 12ce4 | Find first file
2018-12-17T22:57:29.279078543Z 47 PC: 12d01 | Get disk transfer address
2018-12-17T22:57:29.280337069Z 61 PC: 12d3b | Open file (Filename = 'TEST.COM')
2018-12-17T22:57:29.288170745Z 60 PC: 12d49 | Create or truncate file
2018-12-17T22:57:29.307152119Z 64 PC: 12edb | Write file or device (Write 903 bytes on handle 5)
2018-12-17T22:57:29.316373303Z 62 PC: 12d51 | Close file
2018-12-17T22:57:29.329896776Z 26 PC: 12cf6 | Set disk transfer address
2018-12-17T22:57:29.331507324Z 26 PC: 12cb4 | Set disk transfer address
2018-12-17T22:57:29.332881517Z 59 PC: 12c5b | Change current directory
2018-12-17T22:57:29.335387889Z 71 PC: 12c4a | Get current directory
2018-12-17T22:57:29.33927676Z 59 PC: 12c51 | Change current directory
2018-12-17T22:57:29.343979691Z 47 PC: 12c66 | Get disk transfer address
2018-12-17T22:57:29.345558028Z 26 PC: 12c74 | Set disk transfer address
2018-12-17T22:57:29.347638429Z 78 PC: 12c7e | Find first file
2018-12-17T22:57:29.354278462Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.357214641Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.361257261Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.364123249Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.366871916Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.371138777Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.374139218Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.377067122Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.380670336Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.386030181Z 47 PC: 12ccd | Get disk transfer address
2018-12-17T22:57:29.387138825Z 26 PC: 12cdc | Set disk transfer address
2018-12-17T22:57:29.389342178Z 78 PC: 12ce4 | Find first file
2018-12-17T22:57:29.394064485Z 47 PC: 12d01 | Get disk transfer address
2018-12-17T22:57:29.395222302Z 61 PC: 12d3b | Open file (Filename = 'TEST.COM')
2018-12-17T22:57:29.40081742Z 79 PC: 12ce4 | Find next file
2018-12-17T22:57:29.4036897Z 26 PC: 12cf6 | Set disk transfer address
2018-12-17T22:57:29.404788565Z 26 PC: 12cb4 | Set disk transfer address
2018-12-17T22:57:29.405884977Z 59 PC: 12c5b | Change current directory
2018-12-17T22:57:29.408515171Z 71 PC: 12c4a | Get current directory
2018-12-17T22:57:29.410955499Z 59 PC: 12c51 | Change current directory
2018-12-17T22:57:29.414146216Z 47 PC: 12c66 | Get disk transfer address
2018-12-17T22:57:29.4158983Z 26 PC: 12c74 | Set disk transfer address
2018-12-17T22:57:29.417064603Z 78 PC: 12c7e | Find first file
2018-12-17T22:57:29.421758447Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.424562007Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.426748988Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.428867351Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.431561566Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.433733078Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.435831914Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.438475594Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.440602211Z 79 PC: 12ca5 | Find next file
2018-12-17T22:57:29.442857691Z 47 PC: 12ccd | Get disk transfer address
2018-12-17T22:57:29.4441869Z 26 PC: 12cdc | Set disk transfer address
2018-12-17T22:57:29.445662624Z 78 PC: 12ce4 | Find first file
2018-12-17T22:57:29.450965964Z 47 PC: 12d01 | Get disk transfer address
2018-12-17T22:57:29.45373534Z 61 PC: 12d3b | Open file (Filename = 'TEST.COM')
2018-12-17T22:57:29.461217656Z 79 PC: 12ce4 | Find next file
2018-12-17T22:57:29.464471493Z 26 PC: 12cf6 | Set disk transfer address
2018-12-17T22:57:29.466113951Z 26 PC: 12cb4 | Set disk transfer address
2018-12-17T22:57:29.468979678Z 59 PC: 12c5b | Change current directory
2018-12-17T22:57:29.471201485Z 42 PC: 12d72 | Get date 0x12d72: mov al, dl
0x12d74: cwde
0x12d75: ret
0x12d76: out dx, ax
0x12d77: push bx
0x12d79: mov bx, 0x2cb4
0x12d7d: int 0x21
0x12d7f: mov al, ch
0x12d81: cwde
0x12d82: ret
0x12d83: lcall 0xb8de:0x7fe0
0x12d88: mov ah, 0x2a
0x12d8a: int 0x21
0x12d8c: cwde
0x12d8d: ret
0x12d8e: inc bx
0x12d8f: cmp bl, byte ptr [si + 0x6c]
0x12d92: insw word ptr es:[di], dx
0x12d94: outsb dx, byte ptr gs:[si]
0x12d96: jne 0x12df4
2018-12-17T22:57:29.473703959Z 44 PC: 12d7f | Get time 0x12d7f: mov al, ch
0x12d81: cwde
0x12d82: ret
0x12d83: lcall 0xb8de:0x7fe0
0x12d88: mov ah, 0x2a
0x12d8a: int 0x21
0x12d8c: cwde
0x12d8d: ret
0x12d8e: inc bx
0x12d8f: cmp bl, byte ptr [si + 0x6c]
0x12d92: insw word ptr es:[di], dx
0x12d94: outsb dx, byte ptr gs:[si]
0x12d96: jne 0x12df4
0x12d98: sub ch, byte ptr [0x2a]
0x12d9c: push ax
0x12d9d: jb 0x12e08
0x12d9f: outsb dx, byte ptr [si]
0x12da0: je 0x12e07
0x12da2: jb 0x12dc4
0x12da4: imul si, word ptr [bp + di + 0x20], 0x756f
2018-12-17T22:57:29.477402152Z 42 PC: 12d8c | Get date 0x12d8c: cwde
0x12d8d: ret
0x12d8e: inc bx
0x12d8f: cmp bl, byte ptr [si + 0x6c]
0x12d92: insw word ptr es:[di], dx
0x12d94: outsb dx, byte ptr gs:[si]
0x12d96: jne 0x12df4
0x12d98: sub ch, byte ptr [0x2a]
0x12d9c: push ax
0x12d9d: jb 0x12e08
0x12d9f: outsb dx, byte ptr [si]
0x12da0: je 0x12e07
0x12da2: jb 0x12dc4
0x12da4: imul si, word ptr [bp + di + 0x20], 0x756f
0x12da9: je 0x12dcb
0x12dab: outsw dx, word ptr [si]
0x12dac: and byte ptr [bp + di + 0x65], dh
0x12db0: jb 0x12e28
0x12db2: imul sp, word ptr [bp + di + 0x65], 0x6f20
0x12db7: outsb dx, byte ptr [si]
2018-12-17T22:57:29.480907902Z 42 PC: 12d8c | Get date 0x12d8c: cwde
0x12d8d: ret
0x12d8e: inc bx
0x12d8f: cmp bl, byte ptr [si + 0x6c]
0x12d92: insw word ptr es:[di], dx
0x12d94: outsb dx, byte ptr gs:[si]
0x12d96: jne 0x12df4
0x12d98: sub ch, byte ptr [0x2a]
0x12d9c: push ax
0x12d9d: jb 0x12e08
0x12d9f: outsb dx, byte ptr [si]
0x12da0: je 0x12e07
0x12da2: jb 0x12dc4
0x12da4: imul si, word ptr [bp + di + 0x20], 0x756f
0x12da9: je 0x12dcb
0x12dab: outsw dx, word ptr [si]
0x12dac: and byte ptr [bp + di + 0x65], dh
0x12db0: jb 0x12e28
0x12db2: imul sp, word ptr [bp + di + 0x65], 0x6f20
0x12db7: outsb dx, byte ptr [si]
2018-12-17T22:57:29.483643154Z 76 PC: 12c36 | Terminate with return code (Return code = '0')