Sample viewer

vx.netlux.org/Virus.DOS.Marawi.2899

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:36.917371107Z 240 PC: 1346f | UNKNOWN!
2018-12-17T23:06:36.918624285Z 74 PC: 1339d | Reallocate memory
2018-12-17T23:06:36.920291985Z 53 PC: 133af | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:36.92160667Z 37 PC: 13149 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:36.923320779Z 53 PC: 13149 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:06:36.925292487Z 37 PC: 13149 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:06:36.92768614Z 26 PC: 13149 | Set disk transfer address
2018-12-17T23:06:36.929067079Z 78 PC: 13149 | Find first file
2018-12-17T23:06:36.936651624Z 53 PC: 13149 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:36.938175376Z 37 PC: 13149 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:36.939619681Z 61 PC: 13149 | Open file (Filename = 'A:TEST.EXE')
2018-12-17T23:06:36.947717406Z 66 PC: 13149 | Move file pointer
2018-12-17T23:06:36.962402875Z 63 PC: 13149 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T23:06:36.965630367Z 66 PC: 13149 | Move file pointer
2018-12-17T23:06:36.967954978Z 63 PC: 13149 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:06:36.971115478Z 62 PC: 13149 | Close file
2018-12-17T23:06:36.97348615Z 54 PC: 13149 | Get free disk space
2018-12-17T23:06:36.98367772Z 72 PC: 13149 | Allocate memory
2018-12-17T23:06:36.985493189Z 67 PC: 13149 | Get or set file attributes
2018-12-17T23:06:36.992642632Z 67 PC: 13149 | Get or set file attributes
2018-12-17T23:06:37.00979143Z 61 PC: 13149 | Open file (Filename = 'A:TEST.EXE')
2018-12-17T23:06:37.01486331Z 87 PC: 13149 | Get or set file date and time
2018-12-17T23:06:37.016128349Z 66 PC: 13149 | Move file pointer
2018-12-17T23:06:37.017396823Z 66 PC: 13149 | Move file pointer
2018-12-17T23:06:37.019164977Z 63 PC: 13149 | Read file or device (Read 32 bytes on handle 5)
2018-12-17T23:06:37.024958729Z 44 PC: 13149 | Get time 0x13149: ret
0x1314a: add al, al
0x1314c: fnstsw ax
0x1314e: fnstsw ax
0x13150: fnstsw ax
0x13152: fnstsw ax
0x13154: fnstsw ax
0x13156: mov word ptr [0xe0], ax
0x13159: rol dl, 0xe0
0x1315c: ret 0xd2e0
0x1315f: loopne 0x13133
0x13161: loopne 0x13135
0x13163: loopne 0x13115
0x13165: loopne 0x13167
0x13167: rcr bh, 0xe0
0x1316a: fnstsw ax
0x1316c: fnstsw ax
0x1316e: fnstsw ax
0x13170: fnstsw ax
0x13172: shl al, 1
2018-12-17T23:06:37.028083344Z 44 PC: 13149 | Get time 0x13149: ret
0x1314a: add al, al
0x1314c: fnstsw ax
0x1314e: fnstsw ax
0x13150: fnstsw ax
0x13152: fnstsw ax
0x13154: fnstsw ax
0x13156: mov word ptr [0xe0], ax
0x13159: rol dl, 0xe0
0x1315c: ret 0xd2e0
0x1315f: loopne 0x13133
0x13161: loopne 0x13135
0x13163: loopne 0x13115
0x13165: loopne 0x13167
0x13167: rcr bh, 0xe0
0x1316a: fnstsw ax
0x1316c: fnstsw ax
0x1316e: fnstsw ax
0x13170: fnstsw ax
0x13172: shl al, 1
2018-12-17T23:06:37.031252958Z 44 PC: 13149 | Get time 0x13149: ret
0x1314a: add al, al
0x1314c: fnstsw ax
0x1314e: fnstsw ax
0x13150: fnstsw ax
0x13152: fnstsw ax
0x13154: fnstsw ax
0x13156: mov word ptr [0xe0], ax
0x13159: rol dl, 0xe0
0x1315c: ret 0xd2e0
0x1315f: loopne 0x13133
0x13161: loopne 0x13135
0x13163: loopne 0x13115
0x13165: loopne 0x13167
0x13167: rcr bh, 0xe0
0x1316a: fnstsw ax
0x1316c: fnstsw ax
0x1316e: fnstsw ax
0x13170: fnstsw ax
0x13172: shl al, 1
2018-12-17T23:06:37.034756525Z 44 PC: 13149 | Get time 0x13149: ret
0x1314a: add al, al
0x1314c: fnstsw ax
0x1314e: fnstsw ax
0x13150: fnstsw ax
0x13152: fnstsw ax
0x13154: fnstsw ax
0x13156: mov word ptr [0xe0], ax
0x13159: rol dl, 0xe0
0x1315c: ret 0xd2e0
0x1315f: loopne 0x13133
0x13161: loopne 0x13135
0x13163: loopne 0x13115
0x13165: loopne 0x13167
0x13167: rcr bh, 0xe0
0x1316a: fnstsw ax
0x1316c: fnstsw ax
0x1316e: fnstsw ax
0x13170: fnstsw ax
0x13172: shl al, 1
2018-12-17T23:06:37.038006345Z 66 PC: 13149 | Move file pointer
2018-12-17T23:06:37.040682515Z 64 PC: 13149 | Write file or device (Write 2891 bytes on handle 5)
2018-12-17T23:06:37.050902548Z 66 PC: 13149 | Move file pointer
2018-12-17T23:06:37.052567838Z 64 PC: 13149 | Write file or device (Write 28 bytes on handle 5)
2018-12-17T23:06:37.055797505Z 87 PC: 13149 | Get or set file date and time
2018-12-17T23:06:37.057146798Z 62 PC: 13149 | Close file
2018-12-17T23:06:37.062829155Z 67 PC: 13149 | Get or set file attributes
2018-12-17T23:06:37.072482655Z 73 PC: 13149 | Release memory
2018-12-17T23:06:37.074310111Z 26 PC: 13149 | Set disk transfer address
2018-12-17T23:06:37.076147123Z 78 PC: 13149 | Find first file
2018-12-17T23:06:37.083109638Z 37 PC: 13149 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:37.085092728Z 75 PC: 13149 | Execute program
2018-12-17T23:06:37.106738572Z 9 PC: 1452f | Display string (Could not find end pointer)
2018-12-17T23:06:37.112912231Z 76 PC: 14533 | Terminate with return code (Return code = '36')
2018-12-17T23:06:37.11718727Z 73 PC: 13149 | Release memory
2018-12-17T23:06:37.118760408Z 77 PC: 13149 | Get program return code
2018-12-17T23:06:37.120740535Z 49 PC: 1340f | Terminate and stay resident (Return code = '36' | Memory size = '219')