Sample viewer

vx.netlux.org/Virus.DOS.Lauren.653

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:42.439740567Z 26 PC: 12e5e | Set disk transfer address
2018-12-17T23:02:42.441459208Z 71 PC: 12e68 | Get current directory
2018-12-17T23:02:42.444201141Z 53 PC: 12e6d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:42.445225785Z 37 PC: 12e7f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:42.454514246Z 78 PC: 12e9b | Find first file
2018-12-17T23:02:42.46043666Z 67 PC: 12f7c | Get or set file attributes
2018-12-17T23:02:42.471696354Z 67 PC: 12f7c | Get or set file attributes
2018-12-17T23:02:42.487436937Z 61 PC: 12ee9 | Open file (Filename = ' Access denied  Memory allocation error& Cannot load COMMAND, system halted ! Cannot start COMMAND, exiting . Top level process aborted, cannot continue  � ')
2018-12-17T23:02:42.498936297Z 63 PC: 12ef5 | Read file or device (Read 7 bytes on handle 5)
2018-12-17T23:02:42.505124237Z 66 PC: 12f73 | Move file pointer
2018-12-17T23:02:42.506665375Z 64 PC: 12f34 | Write file or device (Write 653 bytes on handle 5)
2018-12-17T23:02:42.516261176Z 66 PC: 12f73 | Move file pointer
2018-12-17T23:02:42.517692884Z 64 PC: 12f44 | Write file or device (Write 7 bytes on handle 5)
2018-12-17T23:02:42.524019926Z 87 PC: 12f58 | Get or set file date and time
2018-12-17T23:02:42.52589633Z 62 PC: 12f5c | Close file
2018-12-17T23:02:42.533593895Z 67 PC: 12f7c | Get or set file attributes
2018-12-17T23:02:42.543330344Z 79 PC: 12e9b | Find next file
2018-12-17T23:02:42.554490941Z 67 PC: 12f7c | Get or set file attributes
2018-12-17T23:02:42.56019915Z 67 PC: 12f7c | Get or set file attributes
2018-12-17T23:02:42.570143367Z 61 PC: 12ee9 | Open file (Filename = ' Access denied  Memory allocation error& Cannot load COMMAND, system halted ! Cannot start COMMAND, exiting . Top level process aborted, cannot continue  � ')
2018-12-17T23:02:42.582453111Z 63 PC: 12ef5 | Read file or device (Read 7 bytes on handle 5)
2018-12-17T23:02:42.588859481Z 66 PC: 12f73 | Move file pointer
2018-12-17T23:02:42.590214178Z 64 PC: 12f34 | Write file or device (Write 653 bytes on handle 5)
2018-12-17T23:02:42.598461759Z 66 PC: 12f73 | Move file pointer
2018-12-17T23:02:42.599810726Z 64 PC: 12f44 | Write file or device (Write 7 bytes on handle 5)
2018-12-17T23:02:42.60623063Z 87 PC: 12f58 | Get or set file date and time
2018-12-17T23:02:42.608200174Z 62 PC: 12f5c | Close file
2018-12-17T23:02:42.615846211Z 67 PC: 12f7c | Get or set file attributes
2018-12-17T23:02:42.625397551Z 79 PC: 12e9b | Find next file
2018-12-17T23:02:42.628486041Z 67 PC: 12f7c | Get or set file attributes
2018-12-17T23:02:42.634395815Z 67 PC: 12f7c | Get or set file attributes
2018-12-17T23:02:42.644404261Z 61 PC: 12ee9 | Open file (Filename = ' Access denied  Memory allocation error& Cannot load COMMAND, system halted ! Cannot start COMMAND, exiting . Top level process aborted, cannot continue  � ')
2018-12-17T23:02:42.65159113Z 63 PC: 12ef5 | Read file or device (Read 7 bytes on handle 5)
2018-12-17T23:02:42.657843017Z 66 PC: 12f73 | Move file pointer
2018-12-17T23:02:42.65923867Z 64 PC: 12f34 | Write file or device (Write 653 bytes on handle 5)
2018-12-17T23:02:42.667583749Z 66 PC: 12f73 | Move file pointer
2018-12-17T23:02:42.66919497Z 64 PC: 12f44 | Write file or device (Write 7 bytes on handle 5)
2018-12-17T23:02:42.675632855Z 87 PC: 12f58 | Get or set file date and time
2018-12-17T23:02:42.677552694Z 62 PC: 12f5c | Close file
2018-12-17T23:02:42.685147384Z 67 PC: 12f7c | Get or set file attributes
2018-12-17T23:02:42.694841968Z 37 PC: 12f8e | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:02:42.696905497Z 26 PC: 12f99 | Set disk transfer address
2018-12-17T23:02:42.698099076Z 59 PC: 12fa1 | Change current directory
2018-12-17T23:02:42.702261151Z 42 PC: 12fa5 | Get date 0x12fa5: cmp dx, 0x520
0x12fa9: jne 0x12fba
0x12fab: mov ax, 3
0x12fae: int 0x10
0x12fb0: mov ah, 9
0x12fb2: lea dx, word ptr [bp + 0x302]
0x12fb6: int 0x21
0x12fb8: jmp 0x12fb8
0x12fba: cmp byte ptr ds:[bp + 0x37b], 1
0x12fc1: je 0x12fce
0x12fc3: mov bx, 0xfeff
0x12fc6: mov ax, bx
0x12fc8: xor bx, bx
0x12fca: not ax
0x12fcc: jmp ax
0x12fce: mov word ptr cs:[0x2f0], 0x9090
0x12fd5: mov word ptr cs:[0x2f2], 0x9090
0x12fdc: mov word ptr cs:[0x2f4], 0x20cd
0x12fe3: mov dx, word ptr cs:[bp + 0x3d4]
0x12fe8: mov ax, word ptr cs:[bp + 0x3d6]