Sample viewer

vx.netlux.org/Virus.DOS.Loreen.1343

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:25.38840349Z 26 PC: 1413a | Set disk transfer address
2018-12-17T23:02:25.390241168Z 78 PC: 1413a | Find first file
2018-12-17T23:02:25.399977603Z 61 PC: 1413a | Open file (Filename = 'TEST.EXE')
2018-12-17T23:02:25.407271702Z 44 PC: 1413a | Get time 0x1413a: push bp
0x1413b: push ax
0x1413c: pushf
0x1413d: pop ax
0x1413e: mov bp, sp
0x14140: add bp, 8
0x14143: mov word ptr [bp], ax
0x14146: pop ax
0x14147: pop bp
0x14148: iret
0x14149: sub ah, byte ptr [bx + si]
0x1414b: dec sp
0x1414c: dec di
0x1414d: push dx
0x1414e: inc bp
0x1414f: inc bp
0x14150: dec si
0x14151: and byte ptr [bp + 0x33], dl
0x14154: xor byte ptr cs:[bx + si], dh
0x14157: and byte ptr [bp + si], ch
2018-12-17T23:02:25.41112219Z 63 PC: 1413a | Read file or device (Read 512 bytes on handle 5)
2018-12-17T23:02:25.419544964Z 66 PC: 1413a | Move file pointer
2018-12-17T23:02:25.421678188Z 66 PC: 1413a | Move file pointer
2018-12-17T23:02:25.42367634Z 64 PC: 1413a | Write file or device (Write 512 bytes on handle 5)
2018-12-17T23:02:25.444899813Z 66 PC: 1413a | Move file pointer
2018-12-17T23:02:25.446666468Z 66 PC: 1413a | Move file pointer
2018-12-17T23:02:25.448516957Z 66 PC: 1413a | Move file pointer
2018-12-17T23:02:25.450715797Z 66 PC: 1413a | Move file pointer
2018-12-17T23:02:25.453093798Z 66 PC: 1413a | Move file pointer
2018-12-17T23:02:25.45527403Z 66 PC: 1413a | Move file pointer
2018-12-17T23:02:25.457684011Z 66 PC: 1413a | Move file pointer
2018-12-17T23:02:25.460152382Z 66 PC: 1413a | Move file pointer
2018-12-17T23:02:25.4622539Z 66 PC: 1413a | Move file pointer
2018-12-17T23:02:25.464409554Z 66 PC: 1413a | Move file pointer
2018-12-17T23:02:25.467378316Z 66 PC: 1413a | Move file pointer
2018-12-17T23:02:25.469551457Z 66 PC: 1413a | Move file pointer
2018-12-17T23:02:25.471718182Z 66 PC: 1413a | Move file pointer
2018-12-17T23:02:25.496708103Z 63 PC: 1413a | Read file or device (Read 1203 bytes on handle 5)
2018-12-17T23:02:25.502267845Z 66 PC: 1413a | Move file pointer
2018-12-17T23:02:25.504188129Z 64 PC: 1413a | Write file or device (Write 512 bytes on handle 5)
2018-12-17T23:02:25.51374928Z 64 PC: 1413a | Write file or device (Write 304 bytes on handle 5)
2018-12-17T23:02:25.520965366Z 64 PC: 1413a | Write file or device (Write 1343 bytes on handle 5)
2018-12-17T23:02:25.546619822Z 62 PC: 1413a | Close file
2018-12-17T23:02:25.557053972Z 61 PC: 1413a | Open file (Filename = 'TEST.EXE')
2018-12-17T23:02:25.56593492Z 87 PC: 1413a | Get or set file date and time
2018-12-17T23:02:25.567648777Z 62 PC: 1413a | Close file
2018-12-17T23:02:25.57542262Z 59 PC: 1413a | Change current directory
2018-12-17T23:02:25.580950599Z 42 PC: 1413a | Get date 0x1413a: push bp
0x1413b: push ax
0x1413c: pushf
0x1413d: pop ax
0x1413e: mov bp, sp
0x14140: add bp, 8
0x14143: mov word ptr [bp], ax
0x14146: pop ax
0x14147: pop bp
0x14148: iret
0x14149: sub ah, byte ptr [bx + si]
0x1414b: dec sp
0x1414c: dec di
0x1414d: push dx
0x1414e: inc bp
0x1414f: inc bp
0x14150: dec si
0x14151: and byte ptr [bp + 0x33], dl
0x14154: xor byte ptr cs:[bx + si], dh
0x14157: and byte ptr [bp + si], ch
2018-12-17T23:02:25.583819134Z 9 PC: 12a5c | Display string (Could not find end pointer)
2018-12-17T23:02:25.590376783Z 76 PC: 12a61 | Terminate with return code (Return code = '0')