Sample viewer

vx.netlux.org/Virus.DOS.Lazarus.1457

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:01:46.180114306Z 37 PC: 12a55 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T23:01:46.183342101Z 209 PC: 12a6d | UNKNOWN!
2018-12-17T23:01:46.184874771Z 82 PC: 12d88 | Get DOS internal pointers (SYSVARS)
2018-12-17T23:01:46.186589984Z 53 PC: 12a98 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:46.188095312Z 37 PC: 12aa8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:46.190927754Z 67 PC: 9eec2 | Get or set file attributes
2018-12-17T23:01:46.200971827Z 67 PC: 9eed3 | Get or set file attributes
2018-12-17T23:01:46.623738432Z 61 PC: 9f18e | Open file (Filename = 'C:\DOS\FORMAT.COM')
2018-12-17T23:01:46.633189551Z 87 PC: 9eeeb | Get or set file date and time
2018-12-17T23:01:46.635041791Z 63 PC: 9ef01 | Read file or device (Read 24 bytes on handle 5)
2018-12-17T23:01:46.643277246Z 66 PC: 9f198 | Move file pointer
2018-12-17T23:01:46.6466485Z 63 PC: 9efec | Read file or device (Read 5 bytes on handle 5)
2018-12-17T23:01:46.650801444Z 66 PC: 9f1a2 | Move file pointer
2018-12-17T23:01:46.655136539Z 44 PC: 9f1a7 | Get time 0x9f1a7: add ch, cl
0x9f1a9: add ch, dh
0x9f1ab: add ch, dl
0x9f1ad: mov al, ch
0x9f1af: mov byte ptr cs:[0x126], al
0x9f1b3: push cs
0x9f1b4: pop ds
0x9f1b5: push cs
0x9f1b6: pop es
0x9f1b7: mov si, 0x100
0x9f1ba: mov di, 0x6b1
0x9f1bd: mov cx, 0x5b1
0x9f1c0: rep movsb byte ptr es:[di], byte ptr [si]
0x9f1c2: mov di, 0x6b1
0x9f1c5: add di, 0x28
0x9f1c9: mov cx, 0x589
0x9f1cc: xor byte ptr es:[di], al
0x9f1cf: inc di
0x9f1d0: loop 0x9f1cc
0x9f1d2: mov ah, 0x40
2018-12-17T23:01:46.66110852Z 64 PC: 9f1dc | Write file or device (Write 1457 bytes on handle 5)
2018-12-17T23:01:46.670946085Z 66 PC: 9f198 | Move file pointer
2018-12-17T23:01:46.675680491Z 64 PC: 9f024 | Write file or device (Write 5 bytes on handle 5)
2018-12-17T23:01:46.679467367Z 87 PC: 9f033 | Get or set file date and time
2018-12-17T23:01:46.682607607Z 62 PC: 9f037 | Close file
2018-12-17T23:01:46.69101782Z 67 PC: 9f043 | Get or set file attributes
2018-12-17T23:01:46.70164618Z 61 PC: 12ab5 | Open file (Filename = ''COM2 �')
2018-12-17T23:01:46.710262019Z 62 PC: 12ad4 | Close file
2018-12-17T23:01:46.712711562Z 67 PC: 12f24 | Get or set file attributes
2018-12-17T23:01:46.720100947Z 65 PC: 12f28 | Delete file (Filename = '')
2018-12-17T23:01:46.727706388Z 67 PC: 12f24 | Get or set file attributes
2018-12-17T23:01:46.734012316Z 65 PC: 12f28 | Delete file (Filename = '')
2018-12-17T23:01:46.74072044Z 67 PC: 12f24 | Get or set file attributes
2018-12-17T23:01:46.748203882Z 65 PC: 12f28 | Delete file (Filename = '')
2018-12-17T23:01:46.755171544Z 76 PC: 12b5f | Terminate with return code (Return code = '0')