Sample viewer

vx.netlux.org/Virus.DOS.Byworm.900

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:34.871322948Z 26 PC: 12a98 | Set disk transfer address
2018-12-17T23:06:34.872932062Z 71 PC: 12aa2 | Get current directory
2018-12-17T23:06:34.882130308Z 78 PC: 12bcb | Find first file
2018-12-17T23:06:34.888809265Z 67 PC: 12be3 | Get or set file attributes
2018-12-17T23:06:34.90648153Z 61 PC: 12bec | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:06:34.911815713Z 63 PC: 12bfa | Read file or device (Read 28 bytes on handle 5)
2018-12-17T23:06:34.918946524Z 62 PC: 12c2f | Close file
2018-12-17T23:06:34.920828573Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T23:06:34.926475201Z 79 PC: 12bd5 | Find next file
2018-12-17T23:06:34.929426138Z 67 PC: 12be3 | Get or set file attributes
2018-12-17T23:06:34.941392328Z 61 PC: 12bec | Open file (Filename = 'PRINT.COM')
2018-12-17T23:06:34.949803829Z 63 PC: 12bfa | Read file or device (Read 28 bytes on handle 5)
2018-12-17T23:06:34.956877692Z 62 PC: 12c2f | Close file
2018-12-17T23:06:34.958699529Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T23:06:34.964092365Z 79 PC: 12bd5 | Find next file
2018-12-17T23:06:34.967123793Z 67 PC: 12be3 | Get or set file attributes
2018-12-17T23:06:34.978329102Z 61 PC: 12bec | Open file (Filename = 'HELLO.COM')
2018-12-17T23:06:34.985777339Z 63 PC: 12bfa | Read file or device (Read 28 bytes on handle 5)
2018-12-17T23:06:34.993139018Z 62 PC: 12c2f | Close file
2018-12-17T23:06:34.994997311Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T23:06:35.000164884Z 79 PC: 12bd5 | Find next file
2018-12-17T23:06:35.003616578Z 67 PC: 12be3 | Get or set file attributes
2018-12-17T23:06:35.01584021Z 61 PC: 12bec | Open file (Filename = 'PHANG.COM')
2018-12-17T23:06:35.023130828Z 63 PC: 12bfa | Read file or device (Read 28 bytes on handle 5)
2018-12-17T23:06:35.030559179Z 62 PC: 12c2f | Close file
2018-12-17T23:06:35.032585636Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T23:06:35.03787845Z 79 PC: 12bd5 | Find next file
2018-12-17T23:06:35.04167674Z 67 PC: 12be3 | Get or set file attributes
2018-12-17T23:06:35.048937889Z 61 PC: 12bec | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:06:35.056499449Z 63 PC: 12bfa | Read file or device (Read 28 bytes on handle 5)
2018-12-17T23:06:35.064287875Z 62 PC: 12c2f | Close file
2018-12-17T23:06:35.069938618Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T23:06:35.075002135Z 79 PC: 12bd5 | Find next file
2018-12-17T23:06:35.078705729Z 67 PC: 12be3 | Get or set file attributes
2018-12-17T23:06:35.089046677Z 61 PC: 12bec | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:06:35.096169046Z 63 PC: 12bfa | Read file or device (Read 28 bytes on handle 5)
2018-12-17T23:06:35.103228331Z 62 PC: 12c2f | Close file
2018-12-17T23:06:35.105755205Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T23:06:35.110766598Z 79 PC: 12bd5 | Find next file
2018-12-17T23:06:35.113745602Z 67 PC: 12be3 | Get or set file attributes
2018-12-17T23:06:35.124847418Z 61 PC: 12bec | Open file (Filename = 'PAH.COM')
2018-12-17T23:06:35.133028265Z 63 PC: 12bfa | Read file or device (Read 28 bytes on handle 5)
2018-12-17T23:06:35.140227241Z 62 PC: 12c2f | Close file
2018-12-17T23:06:35.142704144Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T23:06:35.147810093Z 79 PC: 12bd5 | Find next file
2018-12-17T23:06:35.150555745Z 67 PC: 12be3 | Get or set file attributes
2018-12-17T23:06:35.161820101Z 61 PC: 12bec | Open file (Filename = 'TEST.COM')
2018-12-17T23:06:35.166960367Z 63 PC: 12bfa | Read file or device (Read 28 bytes on handle 5)
2018-12-17T23:06:35.168770529Z 62 PC: 12c2f | Close file
2018-12-17T23:06:35.170681638Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T23:06:35.174283944Z 79 PC: 12bd5 | Find next file
2018-12-17T23:06:35.176508826Z 78 PC: 12bcb | Find first file
2018-12-17T23:06:35.184089577Z 59 PC: 12ad0 | Change current directory
2018-12-17T23:06:35.189814595Z 44 PC: 12ad6 | Get time 0x12ad6: push dx
0x12ad7: xchg dl, al
0x12ad9: add si, ax
0x12adb: mov al, byte ptr [si]
0x12add: cmp al, 0x5a
0x12adf: jbe 0x12ae5
0x12ae1: sub al, 0x20
0x12ae3: jmp 0x12add
0x12ae5: cmp al, 0x40
0x12ae7: jg 0x12aef
0x12ae9: pop dx
0x12aea: push dx
0x12aeb: add al, dh
0x12aed: jmp 0x12ae5
0x12aef: mov byte ptr [bp + 0x474], al
0x12af3: cmp byte ptr [bp + 0x474], 0x5a
0x12af8: jg 0x12b37
0x12afa: mov ah, 0x4e
0x12afc: mov cx, 0x10
0x12aff: lea dx, word ptr [bp + 0x474]
2018-12-17T23:06:35.191423924Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.199331308Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.203107008Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.206769193Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.214364341Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.218495215Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.225222983Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.232924458Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.23975204Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.246717415Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.253785284Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.261656689Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.265892122Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.269884027Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.277758965Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.284110644Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.290833163Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.298260397Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.305010662Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.311460156Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.318917829Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.325466639Z 78 PC: 12b05 | Find first file
2018-12-17T23:06:35.332790339Z 59 PC: 12b46 | Change current directory
2018-12-17T23:06:35.33864065Z 44 PC: 12b4a | Get time 0x12b4a: cmp dl, 5
0x12b4d: jae 0x12b57
0x12b4f: mov ah, 9
0x12b51: lea dx, word ptr [bp + 0x265]
0x12b55: int 0x21
0x12b57: mov ah, 0x1a
0x12b59: mov dx, 0x80
0x12b5c: int 0x21
0x12b5e: in al, 0x21
0x12b60: and al, 0xfd
0x12b62: out 0x21, al
0x12b64: pop word ptr [bp + 0x480]
0x12b68: pop word ptr [bp + 0x47e]
0x12b6c: pop word ptr [bp + 0x47c]
0x12b70: pop word ptr [bp + 0x47a]
0x12b74: pop es
0x12b75: pop ds
0x12b76: mov ax, es
0x12b78: add ax, 0x10
0x12b7b: add word ptr cs:[bp + 0x263], ax
2018-12-17T23:06:35.341382951Z 9 PC: 12b57 | Display string (String= 'coma - biocoded by worm ')
2018-12-17T23:06:35.346030708Z 26 PC: 12b5e | Set disk transfer address