Sample viewer

vx.netlux.org/Virus.DOS.SomeKit.Marvin

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:05:19.729971697Z 26 PC: 12a8a | Set disk transfer address
2018-12-17T23:05:19.731803874Z 78 PC: 12a92 | Find first file
2018-12-17T23:05:19.739162329Z 67 PC: 12ab0 | Get or set file attributes
2018-12-17T23:05:19.757182084Z 61 PC: 12ab5 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:05:19.764520965Z 63 PC: 12ac1 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:05:19.772283108Z 66 PC: 12ac9 | Move file pointer
2018-12-17T23:05:19.774174523Z 87 PC: 12b0f | Get or set file date and time
2018-12-17T23:05:19.776599898Z 62 PC: 12b13 | Close file
2018-12-17T23:05:19.785939464Z 67 PC: 12b22 | Get or set file attributes
2018-12-17T23:05:19.797292044Z 79 PC: 12a92 | Find next file
2018-12-17T23:05:19.800692577Z 79 PC: 12a92 | Find next file
2018-12-17T23:05:19.804604059Z 67 PC: 12ab0 | Get or set file attributes
2018-12-17T23:05:19.817848111Z 61 PC: 12ab5 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:05:19.825648017Z 63 PC: 12ac1 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:05:19.832330823Z 66 PC: 12ac9 | Move file pointer
2018-12-17T23:05:19.833580129Z 87 PC: 12b0f | Get or set file date and time
2018-12-17T23:05:19.834871937Z 62 PC: 12b13 | Close file
2018-12-17T23:05:19.840895939Z 67 PC: 12b22 | Get or set file attributes
2018-12-17T23:05:19.849487399Z 79 PC: 12a92 | Find next file
2018-12-17T23:05:19.852711138Z 67 PC: 12ab0 | Get or set file attributes
2018-12-17T23:05:19.864276586Z 61 PC: 12ab5 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:05:19.877588776Z 63 PC: 12ac1 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:05:19.884869916Z 66 PC: 12ac9 | Move file pointer
2018-12-17T23:05:19.887620332Z 87 PC: 12b0f | Get or set file date and time
2018-12-17T23:05:19.889793129Z 62 PC: 12b13 | Close file
2018-12-17T23:05:19.897806242Z 67 PC: 12b22 | Get or set file attributes
2018-12-17T23:05:19.908912152Z 79 PC: 12a92 | Find next file
2018-12-17T23:05:19.912612967Z 67 PC: 12ab0 | Get or set file attributes
2018-12-17T23:05:19.924578523Z 61 PC: 12ab5 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:05:19.933004565Z 63 PC: 12ac1 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:05:19.941752818Z 66 PC: 12ac9 | Move file pointer
2018-12-17T23:05:19.943561342Z 87 PC: 12b0f | Get or set file date and time
2018-12-17T23:05:19.945453622Z 62 PC: 12b13 | Close file
2018-12-17T23:05:19.954635077Z 67 PC: 12b22 | Get or set file attributes
2018-12-17T23:05:19.966132577Z 79 PC: 12a92 | Find next file
2018-12-17T23:05:19.969537955Z 67 PC: 12ab0 | Get or set file attributes
2018-12-17T23:05:19.983052923Z 61 PC: 12ab5 | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:05:19.990822317Z 63 PC: 12ac1 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:05:19.998922284Z 66 PC: 12ac9 | Move file pointer
2018-12-17T23:05:20.001163694Z 87 PC: 12b0f | Get or set file date and time
2018-12-17T23:05:20.002867055Z 62 PC: 12b13 | Close file
2018-12-17T23:05:20.014417442Z 67 PC: 12b22 | Get or set file attributes
2018-12-17T23:05:20.028272105Z 79 PC: 12a92 | Find next file
2018-12-17T23:05:20.031743111Z 67 PC: 12ab0 | Get or set file attributes
2018-12-17T23:05:20.042624395Z 61 PC: 12ab5 | Open file (Filename = 'PAH.COM')
2018-12-17T23:05:20.050128458Z 63 PC: 12ac1 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:05:20.056884758Z 66 PC: 12ac9 | Move file pointer
2018-12-17T23:05:20.06135663Z 87 PC: 12b0f | Get or set file date and time
2018-12-17T23:05:20.063292206Z 62 PC: 12b13 | Close file
2018-12-17T23:05:20.072462956Z 67 PC: 12b22 | Get or set file attributes
2018-12-17T23:05:20.083432612Z 79 PC: 12a92 | Find next file
2018-12-17T23:05:20.08670672Z 67 PC: 12ab0 | Get or set file attributes
2018-12-17T23:05:20.098725643Z 61 PC: 12ab5 | Open file (Filename = 'TEST.COM')
2018-12-17T23:05:20.106237856Z 63 PC: 12ac1 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:05:20.115720886Z 66 PC: 12ac9 | Move file pointer
2018-12-17T23:05:20.118450844Z 87 PC: 12b0f | Get or set file date and time
2018-12-17T23:05:20.120251772Z 62 PC: 12b13 | Close file
2018-12-17T23:05:20.128300708Z 67 PC: 12b22 | Get or set file attributes
2018-12-17T23:05:20.143031912Z 79 PC: 12a92 | Find next file
2018-12-17T23:05:20.145713247Z 44 PC: 12b2b | Get time 0x12b2b: cmp dl, 4
0x12b2e: jb 0x12b42
0x12b30: jmp 0x12b62
0x12b32: cmp ax, 0x4b00
0x12b35: je 0x12b3c
0x12b37: ljmp ptr cs:[0x256]
0x12b3c: mov ah, 0x3c
0x12b3e: int 0x21
0x12b40: int 0x20
0x12b42: mov ax, 0x3521
0x12b45: int 0x21
0x12b47: mov word ptr cs:[0x256], bx
0x12b4c: mov word ptr cs:[0x258], es
0x12b51: mov ax, 0x2521
0x12b54: lea dx, word ptr [bp + 0x1f2]
0x12b58: int 0x21
0x12b5a: lea dx, word ptr [bp + 0x202]
0x12b5e: int 0x27
0x12b60: int 0x20
0x12b62: mov dx, 0x80
2018-12-17T23:05:20.148186475Z 53 PC: 12b47 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:05:20.1550658Z 37 PC: 12b5a | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:05:20.159661571Z 49 PC: 12b60 | Terminate and stay resident (Return code = '0' | Memory size = '33')