Sample viewer

vx.netlux.org/Virus.DOS.VCL.BlenderHead.896

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:05:14.320294838Z 47 PC: 12b07 | Get disk transfer address
2018-12-17T23:05:14.321860997Z 26 PC: 12b16 | Set disk transfer address
2018-12-17T23:05:14.327319496Z 78 PC: 12b1e | Find first file
2018-12-17T23:05:14.334208414Z 47 PC: 12b36 | Get disk transfer address
2018-12-17T23:05:14.335664668Z 79 PC: 12b1e | Find next file
2018-12-17T23:05:14.339632298Z 47 PC: 12b36 | Get disk transfer address
2018-12-17T23:05:14.340809979Z 79 PC: 12b1e | Find next file
2018-12-17T23:05:14.343532409Z 47 PC: 12b36 | Get disk transfer address
2018-12-17T23:05:14.346929044Z 79 PC: 12b1e | Find next file
2018-12-17T23:05:14.349827818Z 47 PC: 12b36 | Get disk transfer address
2018-12-17T23:05:14.351584491Z 79 PC: 12b1e | Find next file
2018-12-17T23:05:14.356269451Z 47 PC: 12b36 | Get disk transfer address
2018-12-17T23:05:14.35790459Z 79 PC: 12b1e | Find next file
2018-12-17T23:05:14.361082567Z 47 PC: 12b36 | Get disk transfer address
2018-12-17T23:05:14.363565549Z 79 PC: 12b1e | Find next file
2018-12-17T23:05:14.366745123Z 47 PC: 12b36 | Get disk transfer address
2018-12-17T23:05:14.368124859Z 79 PC: 12b1e | Find next file
2018-12-17T23:05:14.371336205Z 47 PC: 12b36 | Get disk transfer address
2018-12-17T23:05:14.374567453Z 61 PC: 12b59 | Open file (Filename = 'TEST.COM')
2018-12-17T23:05:14.381975585Z 63 PC: 12b64 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:05:14.384861337Z 62 PC: 12b68 | Close file
2018-12-17T23:05:14.388815855Z 79 PC: 12b1e | Find next file
2018-12-17T23:05:14.391704849Z 26 PC: 12b30 | Set disk transfer address
2018-12-17T23:05:14.394781812Z 47 PC: 12b07 | Get disk transfer address
2018-12-17T23:05:14.397967341Z 26 PC: 12b16 | Set disk transfer address
2018-12-17T23:05:14.399022499Z 78 PC: 12b1e | Find first file
2018-12-17T23:05:14.405228022Z 26 PC: 12b30 | Set disk transfer address
2018-12-17T23:05:14.41918627Z 42 PC: 12bc4 | Get date 0x12bc4: cwde
0x12bc5: ret
0x12bc6: push sp
0x12bc7: push 0x7369
0x12bca: and byte ptr [bx + si + 0x72], dh
0x12bcd: outsw dx, word ptr [si]
0x12bce: jb 0x12c32
0x12bd1: insw word ptr es:[di], dx
0x12bd2: and byte ptr [bp + si + 0x65], dh
0x12bd5: jno 0x12c4c
0x12bd7: imul si, word ptr [bp + si + 0x65], 0x2073
0x12bdc: dec bp
0x12bdd: imul sp, word ptr [bp + di + 0x72], 0x736f
0x12be2: outsw dx, word ptr [si]
0x12be3: je 0x12c06
0x12be6: push di
0x12be7: imul bp, word ptr [bp + 0x64], 0x776f
0x12bec: jae 0x12c1c
0x12bee: movups xmm3, xmmword ptr [bx + si]
0x12bf1: sbb word ptr [0xdbdc], ax
2018-12-17T23:05:14.421434831Z 76 PC: 12ae7 | Terminate with return code (Return code = '0')