Sample viewer

vx.netlux.org/Virus.DOS.Beda.1857

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:00:49.588768932Z 42 PC: 12c10 | Get date 0x12c10: mov al, dh
0x12c12: mov cl, 0x1e
0x12c14: mul cl
0x12c16: xor dh, dh
0x12c18: add ax, dx
0x12c1a: mov word ptr [0x7fe], ax
0x12c1d: mov ax, 0xbeda
0x12c20: int 0x21
0x12c22: cmp ax, 0xc0fe
0x12c25: jne 0x12c2a
0x12c27: jmp 0x12cb8
0x12c2a: mov ah, 0x52
0x12c2c: int 0x21
0x12c2e: mov ax, word ptr es:[bx - 2]
0x12c32: mov es, ax
0x12c34: xor bx, bx
0x12c36: cmp byte ptr es:[bx], 0x5a
0x12c3a: je 0x12c43
0x12c3c: add ax, word ptr es:[bx + 3]
0x12c40: inc ax
2018-12-17T23:00:49.592630127Z 190 PC: 12c22 | UNKNOWN!
2018-12-17T23:00:49.595588146Z 82 PC: 12c2e | Get DOS internal pointers (SYSVARS)
2018-12-17T23:00:49.597731874Z 53 PC: 12c61 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:49.599809198Z 53 PC: 12c8b | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:00:49.603068582Z 37 PC: 12caf | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:49.605820964Z 37 PC: 12cb7 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:00:49.60835694Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-17T23:00:49.61428535Z 76 PC: 12a86 | Terminate with return code (Return code = '36')
2018-12-17T23:00:49.618358855Z 77 PC: 11fe0 | Get program return code
2018-12-17T23:00:49.62038401Z 72 PC: 12174 | Allocate memory
2018-12-17T23:00:49.623323203Z 72 PC: 1218d | Allocate memory
2018-12-17T23:00:49.628359397Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:00:49.630091431Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:00:49.632440746Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:00:49.634630892Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:00:49.637212252Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:00:49.639869887Z 62 PC: 9f5f1 | Close file
2018-12-17T23:00:49.64278777Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:00:49.645269232Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:00:49.64734897Z 62 PC: 9f5f1 | Close file
2018-12-17T23:00:49.649964365Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:00:49.652823688Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:00:49.655592501Z 62 PC: 9f5f1 | Close file
2018-12-17T23:00:49.658160236Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:00:49.661010452Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:00:49.663550826Z 62 PC: 9f5f1 | Close file
2018-12-17T23:00:49.6655863Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:00:49.668144768Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:00:49.670888114Z 62 PC: 9f5f1 | Close file
2018-12-17T23:00:49.673084681Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:00:49.675701318Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:00:49.683025141Z 62 PC: 9f5f1 | Close file
2018-12-17T23:00:49.686539795Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:00:49.688929866Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:00:49.691548026Z 62 PC: 9f5f1 | Close file
2018-12-17T23:00:49.695373364Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:00:49.697404311Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:00:49.699926019Z 62 PC: 9f5f1 | Close file
2018-12-17T23:00:49.701334195Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:00:49.702750557Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:00:49.706079523Z 62 PC: 9f5f1 | Close file
2018-12-17T23:00:49.708092715Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:00:49.709939696Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:00:49.712833334Z 62 PC: 9f5f1 | Close file
2018-12-17T23:00:49.714728575Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:00:49.716453346Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:00:49.718379726Z 62 PC: 9f5f1 | Close file
2018-12-17T23:00:49.727032746Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:00:49.728625168Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:00:49.730503808Z 62 PC: 9f5f1 | Close file
2018-12-17T23:00:49.733550043Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:00:49.735538439Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:00:49.73751306Z 62 PC: 9f5f1 | Close file
2018-12-17T23:00:49.74059982Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:00:49.742478631Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:00:49.744703431Z 62 PC: 9f5f1 | Close file
2018-12-17T23:00:49.747562845Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:00:49.749500396Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:00:49.751653922Z 62 PC: 9f5f1 | Close file
2018-12-17T23:00:49.756091752Z 99 PC: 999d7 | Get DBCS lead byte table pointer
2018-12-17T23:00:49.758087983Z 56 PC: 941f9 | Get or set country info
2018-12-17T23:00:49.760668201Z 64 PC: 99c48 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:00:49.767655441Z 25 PC: 94262 | Get default drive
2018-12-17T23:00:49.771996298Z 71 PC: 964dd | Get current directory
2018-12-17T23:00:49.780626124Z 64 PC: 99c48 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T23:00:49.786196131Z 2 PC: 964b2 | Character output (Char = '3e')
2018-12-17T23:00:49.789246122Z 93 PC: 94320 | File sharing functions
2018-12-17T23:00:49.791360857Z 93 PC: 94327 | File sharing functions
2018-12-17T23:00:49.79428413Z 10 PC: 94339 | Buffered keyboard input
2018-12-17T23:01:04.569893274Z 0 PC: 0 | Program terminate
2018-12-17T23:01:05.925360892Z 0 PC: 0 | Program terminate
2018-12-17T23:01:06.028072666Z 64 PC: 99c48 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:01:06.034744793Z 41 PC: 943ae | Parse filename
2018-12-17T23:01:06.036796399Z 41 PC: 9442f | Parse filename
2018-12-17T23:01:06.039278653Z 41 PC: 9444c | Parse filename
2018-12-17T23:01:06.043333612Z 26 PC: 978f7 | Set disk transfer address
2018-12-17T23:01:06.045988721Z 71 PC: 97af3 | Get current directory
2018-12-17T23:01:06.055703546Z 78 PC: 9f47e | Find first file
2018-12-17T23:01:06.062712837Z 47 PC: 9f486 | Get disk transfer address
2018-12-17T23:01:06.064079055Z 71 PC: 9796c | Get current directory
2018-12-17T23:01:06.06729633Z 73 PC: 97009 | Release memory
2018-12-17T23:01:06.068686493Z 37 PC: 9f290 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:06.069900874Z 67 PC: 9f29b | Get or set file attributes
2018-12-17T23:01:06.075219428Z 67 PC: 9f2ac | Get or set file attributes
2018-12-17T23:01:06.090546379Z 61 PC: 9f627 | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T23:01:06.103319981Z 87 PC: 9f63b | Get or set file date and time
2018-12-17T23:01:06.106116206Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:01:06.107772228Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:01:06.109331799Z 62 PC: 9f5f1 | Close file
2018-12-17T23:01:06.112495133Z 61 PC: 9f2c4 | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T23:01:06.125930379Z 87 PC: 9f2d2 | Get or set file date and time
2018-12-17T23:01:06.127681349Z 66 PC: 9f2e4 | Move file pointer
2018-12-17T23:01:06.130258742Z 66 PC: 9f2f3 | Move file pointer
2018-12-17T23:01:06.132121983Z 63 PC: 9f2fd | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:01:06.139334245Z 66 PC: 9f30e | Move file pointer
2018-12-17T23:01:06.142067842Z 64 PC: 9f326 | Write file or device (Write 5 bytes on handle 5)
2018-12-17T23:01:06.145586173Z 66 PC: 9f34b | Move file pointer
2018-12-17T23:01:06.147915039Z 64 PC: 9f60f | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:01:06.151240769Z 66 PC: 9f434 | Move file pointer
2018-12-17T23:01:06.153882974Z 64 PC: 9f60f | Write file or device (Write 1857 bytes on handle 5)
2018-12-17T23:01:06.163350564Z 87 PC: 9f44a | Get or set file date and time
2018-12-17T23:01:06.165878554Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:01:06.169017382Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:01:06.171351759Z 62 PC: 9f5f1 | Close file
2018-12-17T23:01:06.180119324Z 67 PC: 9f45f | Get or set file attributes
2018-12-17T23:01:06.192585829Z 75 PC: 11821 | Execute program
2018-12-17T23:01:06.209976948Z 42 PC: 12ab0 | Get date 0x12ab0: mov al, dh
0x12ab2: mov cl, 0x1e
0x12ab4: mul cl
0x12ab6: xor dh, dh
0x12ab8: add ax, dx
0x12aba: sub ax, 7
0x12abd: cmp word ptr [0x7fe], ax
0x12ac1: ja 0x12aed
0x12ac3: jmp 0x13137
0x12ac6: jmp 0x12aed
0x12ac8: push ds
0x12ac9: pop es
0x12aca: mov ax, 0xf000
0x12acd: mov ds, ax
0x12acf: mov si, 0xfff5
0x12ad2: mov di, 0x800
0x12ad5: mov cx, 8
0x12ad8: rep movsb byte ptr es:[di], byte ptr [si]
0x12ada: push es
0x12adb: pop ds
2018-12-17T23:01:06.212800885Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T23:01:06.218329704Z 76 PC: 12a4b | Terminate with return code (Return code = '36')
2018-12-17T23:01:06.221886537Z 77 PC: 11fe0 | Get program return code
2018-12-17T23:01:06.224959142Z 72 PC: 12174 | Allocate memory
2018-12-17T23:01:06.228878326Z 72 PC: 1218d | Allocate memory
2018-12-17T23:01:06.232856902Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:01:06.234769275Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:01:06.23698597Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:01:06.238725078Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:01:06.240559957Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:01:06.242801268Z 62 PC: 9f5f1 | Close file
2018-12-17T23:01:06.245405602Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:01:06.247705664Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:01:06.249977793Z 62 PC: 9f5f1 | Close file
2018-12-17T23:01:06.253476337Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:01:06.255516401Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:01:06.25741034Z 62 PC: 9f5f1 | Close file
2018-12-17T23:01:06.260411639Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:01:06.262653592Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:01:06.264847515Z 62 PC: 9f5f1 | Close file
2018-12-17T23:01:06.268129272Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:01:06.270327693Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:01:06.272532706Z 62 PC: 9f5f1 | Close file
2018-12-17T23:01:06.275361001Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:01:06.277336523Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:01:06.279521378Z 62 PC: 9f5f1 | Close file
2018-12-17T23:01:06.282545871Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:01:06.284371793Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:01:06.287922745Z 62 PC: 9f5f1 | Close file
2018-12-17T23:01:06.290886584Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:01:06.292925045Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:01:06.294910135Z 62 PC: 9f5f1 | Close file
2018-12-17T23:01:06.297696641Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:01:06.299747976Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:01:06.301742584Z 62 PC: 9f5f1 | Close file
2018-12-17T23:01:06.304489976Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:01:06.306346354Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:01:06.308397899Z 62 PC: 9f5f1 | Close file
2018-12-17T23:01:06.311291076Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:01:06.313732985Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:01:06.315666067Z 62 PC: 9f5f1 | Close file
2018-12-17T23:01:06.317952133Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:01:06.320826353Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:01:06.322725803Z 62 PC: 9f5f1 | Close file
2018-12-17T23:01:06.324540563Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:01:06.327265483Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:01:06.329390026Z 62 PC: 9f5f1 | Close file
2018-12-17T23:01:06.331599217Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:01:06.335071481Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:01:06.337528488Z 62 PC: 9f5f1 | Close file
2018-12-17T23:01:06.340018758Z 66 PC: 9f5c8 | Move file pointer
2018-12-17T23:01:06.343015609Z 87 PC: 9f5ce | Get or set file date and time
2018-12-17T23:01:06.344952569Z 62 PC: 9f5f1 | Close file
2018-12-17T23:01:06.348455521Z 99 PC: 999d7 | Get DBCS lead byte table pointer
2018-12-17T23:01:06.351619867Z 56 PC: 941f9 | Get or set country info
2018-12-17T23:01:06.354028272Z 64 PC: 99c48 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:01:06.358984907Z 25 PC: 94262 | Get default drive
2018-12-17T23:01:06.361797872Z 71 PC: 964dd | Get current directory
2018-12-17T23:01:06.366217727Z 64 PC: 99c48 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T23:01:06.36982746Z 2 PC: 964b2 | Character output (Char = '3e')
2018-12-17T23:01:06.373476337Z 93 PC: 94320 | File sharing functions
2018-12-17T23:01:06.375732407Z 93 PC: 94327 | File sharing functions
2018-12-17T23:01:06.378561513Z 10 PC: 94339 | Buffered keyboard input