Sample viewer

vx.netlux.org/Virus.DOS.PS-MPC.Violite

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:44.37826502Z 26 PC: 1333f | Set disk transfer address
2018-12-17T23:02:44.386770751Z 78 PC: 133cb | Find first file
2018-12-17T23:02:44.39809064Z 61 PC: 135ae | Open file (Filename = 'C:\DOS\ATTRIB.EXE')
2018-12-17T23:02:44.406067948Z 63 PC: 133ee | Read file or device (Read 26 bytes on handle 5)
2018-12-17T23:02:44.412570135Z 62 PC: 133f2 | Close file
2018-12-17T23:02:44.415581283Z 67 PC: 135b9 | Get or set file attributes
2018-12-17T23:02:44.834001738Z 61 PC: 135ae | Open file (Filename = 'C:\DOS\ATTRIB.EXE')
2018-12-17T23:02:44.841916247Z 64 PC: 1352c | Write file or device (Write 26 bytes on handle 5)
2018-12-17T23:02:44.846832745Z 66 PC: 13534 | Move file pointer
2018-12-17T23:02:44.848649679Z 44 PC: 13538 | Get time 0x13538: mov word ptr [bp + 0x104], dx
0x1353c: lea si, word ptr [bp + 0x103]
0x13540: lea di, word ptr [bp + 0x6ea]
0x13544: mov al, 0x53
0x13546: stosb byte ptr es:[di], al
0x13547: mov cx, 0x10
0x1354a: rep movsb byte ptr es:[di], byte ptr [si]
0x1354c: lea si, word ptr [bp + 0x6c9]
0x13550: mov cx, 0xd
0x13553: rep movsb byte ptr es:[di], byte ptr [si]
0x13555: lea si, word ptr [bp + 0x103]
0x13559: mov cx, 0x10
0x1355c: rep movsb byte ptr es:[di], byte ptr [si]
0x1355e: mov ax, 0xc35b
0x13561: stosw word ptr es:[di], ax
0x13562: pop ax
0x13563: mov word ptr [bp + 0x107], ax
0x13567: call 0x135ba
0x1356a: xchg di, si
0x1356c: lea di, word ptr [bp + 0x103]
2018-12-17T23:02:44.851643294Z 64 PC: 135d7 | Write file or device (Write 1511 bytes on handle 5)
2018-12-17T23:02:44.863367101Z 87 PC: 13585 | Get or set file date and time
2018-12-17T23:02:44.865308158Z 62 PC: 13589 | Close file
2018-12-17T23:02:44.873099167Z 67 PC: 135b9 | Get or set file attributes
2018-12-17T23:02:44.883989118Z 79 PC: 133cb | Find next file
2018-12-17T23:02:44.887557272Z 61 PC: 135ae | Open file (Filename = 'C:\DOS\CHKDSK.EXE')
2018-12-17T23:02:44.894857699Z 63 PC: 133ee | Read file or device (Read 26 bytes on handle 5)
2018-12-17T23:02:44.901971294Z 62 PC: 133f2 | Close file
2018-12-17T23:02:44.904408103Z 67 PC: 135b9 | Get or set file attributes
2018-12-17T23:02:44.915311149Z 61 PC: 135ae | Open file (Filename = 'C:\DOS\CHKDSK.EXE')
2018-12-17T23:02:44.923036133Z 64 PC: 1352c | Write file or device (Write 26 bytes on handle 5)
2018-12-17T23:02:44.927676301Z 66 PC: 13534 | Move file pointer
2018-12-17T23:02:44.929285935Z 44 PC: 13538 | Get time 0x13538: mov word ptr [bp + 0x104], dx
0x1353c: lea si, word ptr [bp + 0x103]
0x13540: lea di, word ptr [bp + 0x6ea]
0x13544: mov al, 0x53
0x13546: stosb byte ptr es:[di], al
0x13547: mov cx, 0x10
0x1354a: rep movsb byte ptr es:[di], byte ptr [si]
0x1354c: lea si, word ptr [bp + 0x6c9]
0x13550: mov cx, 0xd
0x13553: rep movsb byte ptr es:[di], byte ptr [si]
0x13555: lea si, word ptr [bp + 0x103]
0x13559: mov cx, 0x10
0x1355c: rep movsb byte ptr es:[di], byte ptr [si]
0x1355e: mov ax, 0xc35b
0x13561: stosw word ptr es:[di], ax
0x13562: pop ax
0x13563: mov word ptr [bp + 0x107], ax
0x13567: call 0x135ba
0x1356a: xchg di, si
0x1356c: lea di, word ptr [bp + 0x103]
2018-12-17T23:02:44.932065077Z 64 PC: 135d7 | Write file or device (Write 1511 bytes on handle 5)
2018-12-17T23:02:44.94222134Z 87 PC: 13585 | Get or set file date and time
2018-12-17T23:02:44.944870306Z 62 PC: 13589 | Close file
2018-12-17T23:02:44.953038864Z 67 PC: 135b9 | Get or set file attributes
2018-12-17T23:02:44.964020207Z 79 PC: 133cb | Find next file
2018-12-17T23:02:44.968413492Z 61 PC: 135ae | Open file (Filename = 'C:\DOS\DEBUG.EXE')
2018-12-17T23:02:44.975791153Z 63 PC: 133ee | Read file or device (Read 26 bytes on handle 5)
2018-12-17T23:02:44.982474941Z 62 PC: 133f2 | Close file
2018-12-17T23:02:44.984673773Z 67 PC: 135b9 | Get or set file attributes
2018-12-17T23:02:44.995212805Z 61 PC: 135ae | Open file (Filename = 'C:\DOS\DEBUG.EXE')
2018-12-17T23:02:45.003418312Z 64 PC: 1352c | Write file or device (Write 26 bytes on handle 5)
2018-12-17T23:02:45.007052109Z 66 PC: 13534 | Move file pointer
2018-12-17T23:02:45.009518043Z 44 PC: 13538 | Get time 0x13538: mov word ptr [bp + 0x104], dx
0x1353c: lea si, word ptr [bp + 0x103]
0x13540: lea di, word ptr [bp + 0x6ea]
0x13544: mov al, 0x53
0x13546: stosb byte ptr es:[di], al
0x13547: mov cx, 0x10
0x1354a: rep movsb byte ptr es:[di], byte ptr [si]
0x1354c: lea si, word ptr [bp + 0x6c9]
0x13550: mov cx, 0xd
0x13553: rep movsb byte ptr es:[di], byte ptr [si]
0x13555: lea si, word ptr [bp + 0x103]
0x13559: mov cx, 0x10
0x1355c: rep movsb byte ptr es:[di], byte ptr [si]
0x1355e: mov ax, 0xc35b
0x13561: stosw word ptr es:[di], ax
0x13562: pop ax
0x13563: mov word ptr [bp + 0x107], ax
0x13567: call 0x135ba
0x1356a: xchg di, si
0x1356c: lea di, word ptr [bp + 0x103]
2018-12-17T23:02:45.013562321Z 64 PC: 135d7 | Write file or device (Write 1511 bytes on handle 5)
2018-12-17T23:02:45.023989202Z 87 PC: 13585 | Get or set file date and time
2018-12-17T23:02:45.025914179Z 62 PC: 13589 | Close file
2018-12-17T23:02:45.035285997Z 67 PC: 135b9 | Get or set file attributes
2018-12-17T23:02:45.046571802Z 79 PC: 133cb | Find next file
2018-12-17T23:02:45.049877884Z 61 PC: 135ae | Open file (Filename = 'C:\DOS\EXPAND.EXE')
2018-12-17T23:02:45.057337269Z 63 PC: 133ee | Read file or device (Read 26 bytes on handle 5)
2018-12-17T23:02:45.06455484Z 62 PC: 133f2 | Close file
2018-12-17T23:02:45.0671253Z 67 PC: 135b9 | Get or set file attributes
2018-12-17T23:02:45.077889254Z 61 PC: 135ae | Open file (Filename = 'C:\DOS\EXPAND.EXE')
2018-12-17T23:02:45.086287694Z 64 PC: 1352c | Write file or device (Write 26 bytes on handle 5)
2018-12-17T23:02:45.089309181Z 66 PC: 13534 | Move file pointer
2018-12-17T23:02:45.090893999Z 44 PC: 13538 | Get time 0x13538: mov word ptr [bp + 0x104], dx
0x1353c: lea si, word ptr [bp + 0x103]
0x13540: lea di, word ptr [bp + 0x6ea]
0x13544: mov al, 0x53
0x13546: stosb byte ptr es:[di], al
0x13547: mov cx, 0x10
0x1354a: rep movsb byte ptr es:[di], byte ptr [si]
0x1354c: lea si, word ptr [bp + 0x6c9]
0x13550: mov cx, 0xd
0x13553: rep movsb byte ptr es:[di], byte ptr [si]
0x13555: lea si, word ptr [bp + 0x103]
0x13559: mov cx, 0x10
0x1355c: rep movsb byte ptr es:[di], byte ptr [si]
0x1355e: mov ax, 0xc35b
0x13561: stosw word ptr es:[di], ax
0x13562: pop ax
0x13563: mov word ptr [bp + 0x107], ax
0x13567: call 0x135ba
0x1356a: xchg di, si
0x1356c: lea di, word ptr [bp + 0x103]
2018-12-17T23:02:45.094447114Z 64 PC: 135d7 | Write file or device (Write 1511 bytes on handle 5)
2018-12-17T23:02:45.104185892Z 87 PC: 13585 | Get or set file date and time
2018-12-17T23:02:45.105827386Z 62 PC: 13589 | Close file
2018-12-17T23:02:45.114445188Z 67 PC: 135b9 | Get or set file attributes
2018-12-17T23:02:45.124791578Z 79 PC: 133cb | Find next file
2018-12-17T23:02:45.127997953Z 61 PC: 135ae | Open file (Filename = 'C:\DOS\FDISK.EXE')
2018-12-17T23:02:45.136204482Z 63 PC: 133ee | Read file or device (Read 26 bytes on handle 5)
2018-12-17T23:02:45.142152627Z 62 PC: 133f2 | Close file
2018-12-17T23:02:45.14453322Z 67 PC: 135b9 | Get or set file attributes
2018-12-17T23:02:45.155432419Z 61 PC: 135ae | Open file (Filename = 'C:\DOS\FDISK.EXE')
2018-12-17T23:02:45.164941926Z 64 PC: 1352c | Write file or device (Write 26 bytes on handle 5)
2018-12-17T23:02:45.168192844Z 66 PC: 13534 | Move file pointer
2018-12-17T23:02:45.170685868Z 44 PC: 13538 | Get time 0x13538: mov word ptr [bp + 0x104], dx
0x1353c: lea si, word ptr [bp + 0x103]
0x13540: lea di, word ptr [bp + 0x6ea]
0x13544: mov al, 0x53
0x13546: stosb byte ptr es:[di], al
0x13547: mov cx, 0x10
0x1354a: rep movsb byte ptr es:[di], byte ptr [si]
0x1354c: lea si, word ptr [bp + 0x6c9]
0x13550: mov cx, 0xd
0x13553: rep movsb byte ptr es:[di], byte ptr [si]
0x13555: lea si, word ptr [bp + 0x103]
0x13559: mov cx, 0x10
0x1355c: rep movsb byte ptr es:[di], byte ptr [si]
0x1355e: mov ax, 0xc35b
0x13561: stosw word ptr es:[di], ax
0x13562: pop ax
0x13563: mov word ptr [bp + 0x107], ax
0x13567: call 0x135ba
0x1356a: xchg di, si
0x1356c: lea di, word ptr [bp + 0x103]
2018-12-17T23:02:45.174165746Z 64 PC: 135d7 | Write file or device (Write 1511 bytes on handle 5)
2018-12-17T23:02:45.18600428Z 87 PC: 13585 | Get or set file date and time
2018-12-17T23:02:45.1877501Z 62 PC: 13589 | Close file
2018-12-17T23:02:45.196167926Z 67 PC: 135b9 | Get or set file attributes
2018-12-17T23:02:45.206396585Z 26 PC: 13446 | Set disk transfer address