Sample viewer

vx.netlux.org/Virus.DOS.Gdog.1062

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:03:46.401365809Z 42 PC: 12a4f | Get date 0x12a4f: or bp, bp
0x12a51: je 0x12a6b
0x12a53: mov al, byte ptr [bp + 0x51c]
0x12a57: mov cx, 0x3f1
0x12a5a: lea si, word ptr [bp + 0x12b]
0x12a5e: xor byte ptr [si], al
0x12a60: nop
0x12a61: inc si
0x12a62: nop
0x12a63: inc al
0x12a65: adc al, cl
0x12a67: loop 0x12a5e
0x12a69: mov ah, 0x2a
0x12a6b: mov ax, 0xcaca
0x12a6e: int 0x21
0x12a70: cmp ax, 0xfafa
0x12a73: je 0x12ac3
0x12a75: mov ax, 0x3521
0x12a78: int 0x21
0x12a7a: mov word ptr [bp + 0x1d0], bx
2018-12-17T22:03:46.40487626Z 202 PC: 12a70 | UNKNOWN!
2018-12-17T22:03:46.405865067Z 53 PC: 12a7a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:03:46.407247784Z 74 PC: 12a99 | Reallocate memory
2018-12-17T22:03:46.408707496Z 72 PC: 12a9f | Allocate memory
2018-12-17T22:03:46.421701579Z 37 PC: 12ac3 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:03:46.4291192Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:03:46.430506394Z 72 PC: 12174 | Allocate memory
2018-12-17T22:03:46.433179378Z 72 PC: 1218d | Allocate memory
2018-12-17T22:03:46.435331321Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:03:46.437726646Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:03:46.44148856Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:03:46.443706071Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:03:46.44512242Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:03:46.446694705Z 62 PC: 122ab | Close file
2018-12-17T22:03:46.448949886Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:03:46.450437363Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:03:46.452014922Z 62 PC: 122ab | Close file
2018-12-17T22:03:46.455298527Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:03:46.456791925Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:03:46.458243662Z 62 PC: 122ab | Close file
2018-12-17T22:03:46.460266997Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:03:46.46173391Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:03:46.462921332Z 62 PC: 122ab | Close file
2018-12-17T22:03:46.465598136Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:03:46.467065642Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:03:46.468082229Z 62 PC: 122ab | Close file
2018-12-17T22:03:46.470132486Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:03:46.471574181Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:03:46.472680938Z 62 PC: 122ab | Close file
2018-12-17T22:03:46.475307072Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:03:46.477213508Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:03:46.478739872Z 62 PC: 122ab | Close file
2018-12-17T22:03:46.481119317Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:03:46.48278809Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:03:46.483992174Z 62 PC: 122ab | Close file
2018-12-17T22:03:46.485912588Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:03:46.487466258Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:03:46.48849954Z 62 PC: 122ab | Close file
2018-12-17T22:03:46.490506595Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:03:46.492188117Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:03:46.494103695Z 62 PC: 122ab | Close file
2018-12-17T22:03:46.496578283Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:03:46.49806118Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:03:46.499098692Z 62 PC: 122ab | Close file
2018-12-17T22:03:46.501356577Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:03:46.503108897Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:03:46.504155598Z 62 PC: 122ab | Close file
2018-12-17T22:03:46.506204104Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:03:46.507729192Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:03:46.508883657Z 62 PC: 122ab | Close file
2018-12-17T22:03:46.510779578Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:03:46.512803043Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:03:46.513797396Z 62 PC: 122ab | Close file
2018-12-17T22:03:46.515627852Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:03:46.517257271Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:03:46.518369412Z 62 PC: 122ab | Close file
2018-12-17T22:03:46.52102725Z 99 PC: 99d57 | Get DBCS lead byte table pointer
2018-12-17T22:03:46.522700806Z 56 PC: 94579 | Get or set country info
2018-12-17T22:03:46.524413988Z 64 PC: 99fc8 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:03:46.528660177Z 25 PC: 945e2 | Get default drive
2018-12-17T22:03:46.531322585Z 71 PC: 9685d | Get current directory
2018-12-17T22:03:46.53535876Z 64 PC: 99fc8 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:03:46.538575253Z 2 PC: 96832 | Character output (Char = '3e')
2018-12-17T22:03:46.547653035Z 93 PC: 946a0 | File sharing functions
2018-12-17T22:03:46.550051946Z 93 PC: 946a7 | File sharing functions
2018-12-17T22:03:46.551751518Z 10 PC: 946b9 | Buffered keyboard input
2018-12-17T22:04:01.396134945Z 0 PC: 0 | Program terminate
2018-12-17T22:04:02.749146244Z 0 PC: 0 | Program terminate
2018-12-17T22:04:02.852169779Z 64 PC: 99fc8 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:04:02.857595836Z 41 PC: 9472e | Parse filename
2018-12-17T22:04:02.859657689Z 41 PC: 947af | Parse filename
2018-12-17T22:04:02.862358895Z 41 PC: 947cc | Parse filename
2018-12-17T22:04:02.869694116Z 26 PC: 97c77 | Set disk transfer address
2018-12-17T22:04:02.871212725Z 71 PC: 97e73 | Get current directory
2018-12-17T22:04:02.879099242Z 78 PC: 9f465 | Find first file
2018-12-17T22:04:02.887752611Z 47 PC: 9f46f | Get disk transfer address
2018-12-17T22:04:02.889086272Z 71 PC: 97cec | Get current directory
2018-12-17T22:04:02.894880957Z 73 PC: 97389 | Release memory
2018-12-17T22:04:02.896326992Z 61 PC: 9f571 | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T22:04:02.903264782Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:04:02.905817982Z 62 PC: 9f6a4 | Close file
2018-12-17T22:04:02.919946142Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:02.921072029Z 75 PC: 11821 | Execute program
2018-12-17T22:04:02.937061509Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T22:04:02.940912586Z 76 PC: 12a4b | Terminate with return code (Return code = '36')
2018-12-17T22:04:02.943819959Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:04:02.945626858Z 72 PC: 12174 | Allocate memory
2018-12-17T22:04:02.947250674Z 72 PC: 1218d | Allocate memory
2018-12-17T22:04:02.948859468Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:04:02.950587077Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:04:02.95174513Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:02.95343211Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:04:02.961460527Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:02.962553787Z 62 PC: 122ab | Close file
2018-12-17T22:04:02.964456296Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:04:02.966241254Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:02.967274283Z 62 PC: 122ab | Close file
2018-12-17T22:04:02.969170903Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:04:02.971047701Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:02.972361484Z 62 PC: 122ab | Close file
2018-12-17T22:04:02.974382209Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:04:02.976436928Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:02.977563318Z 62 PC: 122ab | Close file
2018-12-17T22:04:02.978907884Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:04:02.980364222Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:02.981337906Z 62 PC: 122ab | Close file
2018-12-17T22:04:02.983164336Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:04:02.992391122Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:02.993482554Z 62 PC: 122ab | Close file
2018-12-17T22:04:02.995398901Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:04:02.997368825Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:02.998641255Z 62 PC: 122ab | Close file
2018-12-17T22:04:03.000598312Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:04:03.00287987Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:03.003871414Z 62 PC: 122ab | Close file
2018-12-17T22:04:03.006360013Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:04:03.008139406Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:03.009199498Z 62 PC: 122ab | Close file
2018-12-17T22:04:03.0110542Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:04:03.012488787Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:03.013519921Z 62 PC: 122ab | Close file
2018-12-17T22:04:03.015388029Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:04:03.016968984Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:03.017925247Z 62 PC: 122ab | Close file
2018-12-17T22:04:03.019753223Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:04:03.021313044Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:03.022176314Z 62 PC: 122ab | Close file
2018-12-17T22:04:03.023913138Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:04:03.025442981Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:03.026481724Z 62 PC: 122ab | Close file
2018-12-17T22:04:03.029088319Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:04:03.030664992Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:03.031653754Z 62 PC: 122ab | Close file
2018-12-17T22:04:03.03350863Z 87 PC: 9f695 | Get or set file date and time
2018-12-17T22:04:03.035010488Z 37 PC: 9f728 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:03.036059199Z 62 PC: 122ab | Close file
2018-12-17T22:04:03.039151049Z 99 PC: 99d57 | Get DBCS lead byte table pointer
2018-12-17T22:04:03.04187842Z 56 PC: 94579 | Get or set country info
2018-12-17T22:04:03.043629709Z 64 PC: 99fc8 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:04:03.048324646Z 25 PC: 945e2 | Get default drive
2018-12-17T22:04:03.055462832Z 71 PC: 9685d | Get current directory
2018-12-17T22:04:03.059191651Z 64 PC: 99fc8 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:04:03.062190501Z 2 PC: 96832 | Character output (Char = '3e')
2018-12-17T22:04:03.064667905Z 93 PC: 946a0 | File sharing functions
2018-12-17T22:04:03.066219369Z 93 PC: 946a7 | File sharing functions
2018-12-17T22:04:03.067821128Z 10 PC: 946b9 | Buffered keyboard input