Sample viewer

vx.netlux.org/Virus.DOS.Corea.457

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:51.621219041Z 42 PC: 12b55 | Get date 0x12b55: ret
0x12b56: dec bp
0x12b57: inc bp
0x12b58: dec bp
0x12b59: inc bx
0x12b5b: dec di
0x12b5c: dec bp
0x12b5d: add byte ptr [bx + si + 0x72], dl
0x12b60: outsw dx, word ptr [si]
0x12b61: jb 0x12bc5
0x12b64: insw word ptr es:[di], dx
0x12b65: and byte ptr [si + 0x6f], dh
0x12b68: outsw dx, word ptr [si]
0x12b69: and byte ptr [bp + si + 0x69], ah
0x12b6c: and byte ptr [edi + ebp*2 + 0x20], dh
0x12b71: imul esi, dword ptr [si + 0x20], 0x6d206e69
0x12b79: insw word ptr es:[di], dx
0x12b7b: outsw dx, word ptr [si]
0x12b7c: jb 0x12bf7
0x12b7e: or cl, byte ptr [di]
2018-12-17T23:04:51.62403108Z 78 PC: 12b55 | Find first file
2018-12-17T23:04:51.631040823Z 67 PC: 12b55 | Get or set file attributes
2018-12-17T23:04:51.647109092Z 61 PC: 12b55 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:04:51.653163497Z 63 PC: 12b55 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:04:51.659144426Z 66 PC: 12b55 | Move file pointer
2018-12-17T23:04:51.660784129Z 64 PC: 12bf1 | Write file or device (Write 457 bytes on handle 5)
2018-12-17T23:04:51.663297186Z 62 PC: 12b55 | Close file
2018-12-17T23:04:51.672465949Z 79 PC: 12b55 | Find next file
2018-12-17T23:04:51.67754989Z 67 PC: 12b55 | Get or set file attributes
2018-12-17T23:04:51.706362356Z 61 PC: 12b55 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:04:51.724117277Z 63 PC: 12b55 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:04:51.737943129Z 66 PC: 12b55 | Move file pointer
2018-12-17T23:04:51.740663735Z 64 PC: 12bf1 | Write file or device (Write 457 bytes on handle 5)
2018-12-17T23:04:51.747259049Z 62 PC: 12b55 | Close file
2018-12-17T23:04:51.761223481Z 79 PC: 12b55 | Find next file
2018-12-17T23:04:51.765240666Z 67 PC: 12b55 | Get or set file attributes
2018-12-17T23:04:51.777012234Z 61 PC: 12b55 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:04:51.787307956Z 63 PC: 12b55 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:04:51.794776733Z 66 PC: 12b55 | Move file pointer
2018-12-17T23:04:51.797076538Z 64 PC: 12bf1 | Write file or device (Write 457 bytes on handle 5)
2018-12-17T23:04:51.801743134Z 62 PC: 12b55 | Close file
2018-12-17T23:04:51.821292269Z 79 PC: 12b55 | Find next file
2018-12-17T23:04:51.8247703Z 67 PC: 12b55 | Get or set file attributes
2018-12-17T23:04:51.836938534Z 61 PC: 12b55 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:04:51.84467267Z 63 PC: 12b55 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:04:51.852103815Z 66 PC: 12b55 | Move file pointer
2018-12-17T23:04:51.85451545Z 64 PC: 12bf1 | Write file or device (Write 457 bytes on handle 5)
2018-12-17T23:04:51.8592584Z 62 PC: 12b55 | Close file
2018-12-17T23:04:51.868812468Z 79 PC: 12b55 | Find next file
2018-12-17T23:04:51.872280841Z 67 PC: 12b55 | Get or set file attributes
2018-12-17T23:04:51.884196911Z 61 PC: 12b55 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:04:51.898179066Z 63 PC: 12b55 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:04:51.912965735Z 66 PC: 12b55 | Move file pointer
2018-12-17T23:04:51.91648299Z 64 PC: 12bf1 | Write file or device (Write 457 bytes on handle 5)
2018-12-17T23:04:51.922443629Z 62 PC: 12b55 | Close file
2018-12-17T23:04:51.933731508Z 79 PC: 12b55 | Find next file
2018-12-17T23:04:51.947743991Z 67 PC: 12b55 | Get or set file attributes
2018-12-17T23:04:51.9691884Z 61 PC: 12b55 | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:04:51.97680797Z 63 PC: 12b55 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:04:51.984224137Z 66 PC: 12b55 | Move file pointer
2018-12-17T23:04:51.987169807Z 64 PC: 12bf1 | Write file or device (Write 457 bytes on handle 5)
2018-12-17T23:04:51.99048439Z 62 PC: 12b55 | Close file
2018-12-17T23:04:51.998988834Z 79 PC: 12b55 | Find next file
2018-12-17T23:04:52.004076052Z 67 PC: 12b55 | Get or set file attributes
2018-12-17T23:04:52.014792686Z 61 PC: 12b55 | Open file (Filename = 'PAH.COM')
2018-12-17T23:04:52.022333347Z 63 PC: 12b55 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:04:52.030510856Z 66 PC: 12b55 | Move file pointer
2018-12-17T23:04:52.033278942Z 64 PC: 12bf1 | Write file or device (Write 457 bytes on handle 5)
2018-12-17T23:04:52.036808139Z 62 PC: 12b55 | Close file
2018-12-17T23:04:52.046415838Z 79 PC: 12b55 | Find next file
2018-12-17T23:04:52.050052667Z 67 PC: 12b55 | Get or set file attributes
2018-12-17T23:04:52.061024131Z 61 PC: 12b55 | Open file (Filename = 'TEST.COM')
2018-12-17T23:04:52.071284637Z 63 PC: 12b55 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:04:52.07926215Z 79 PC: 12b55 | Find next file
2018-12-17T23:04:52.082255489Z 53 PC: 12b55 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:52.083889462Z 37 PC: 12b55 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:52.086886519Z 9 PC: 12b55 | Display string (Could not find end pointer)
2018-12-17T23:04:52.09152932Z 49 PC: 12b55 | Terminate and stay resident (Return code = '36' | Memory size = '45')