Sample viewer

vx.netlux.org/Virus.DOS.V.1798

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:07:01.22810417Z 53 PC: 2069e | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:07:01.230656824Z 53 PC: 206aa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:01.232284086Z 53 PC: 206b6 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T23:07:01.234077623Z 53 PC: 206cd | Get interrupt vector (Interrupt = '38' AKA 'Create PSP')
2018-12-17T23:07:01.236672053Z 42 PC: 20cd0 | Get date 0x20cd0: sub cx, 0x7bc
0x20cd4: mov ax, 0x16d
0x20cd7: push dx
0x20cd8: mul cx
0x20cda: pop dx
0x20cdb: xchg ax, bx
0x20cdc: mov cl, 0x1e
0x20cde: mov al, dh
0x20ce0: dec ax
0x20ce1: mul cl
0x20ce3: add bx, ax
0x20ce5: xor dh, dh
0x20ce7: add bx, dx
0x20ce9: ret
0x20cea: jmp 0x2246a
0x20ced: adc al, byte ptr [bx + si]
0x20cef: add al, 4
0x20cf1: sub al, 0
0x20cf3: inc bx
0x20cf4: dec di
2018-12-17T23:07:01.249332004Z 80 PC: 20fcb | Set current PSP
2018-12-17T23:07:01.250537605Z 74 PC: 20fd2 | Reallocate memory
2018-12-17T23:07:01.253043185Z 37 PC: 20fec | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:07:01.254614355Z 37 PC: 20ff4 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:01.256371958Z 72 PC: 21027 | Allocate memory
2018-12-17T23:07:01.259479885Z 53 PC: 2125c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:01.260746814Z 53 PC: 21268 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T23:07:01.262023655Z 53 PC: 21274 | Get interrupt vector (Interrupt = '38' AKA 'Create PSP')
2018-12-17T23:07:01.263711165Z 53 PC: 21280 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:07:01.265263631Z 37 PC: 21296 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:07:01.266762891Z 37 PC: 2129e | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:01.268578581Z 37 PC: 212a7 | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T23:07:01.270482827Z 37 PC: 212b0 | Set interrupt vector (Interrupt = '38' AKA 'Create PSP')
2018-12-17T23:07:01.271907395Z 67 PC: 212b7 | Get or set file attributes
2018-12-17T23:07:01.278839177Z 61 PC: 212be | Open file (Filename = '��������������W')
2018-12-17T23:07:01.286428148Z 66 PC: 212d9 | Move file pointer
2018-12-17T23:07:01.288328268Z 63 PC: 212fc | Read file or device (Read 65535 bytes on handle 5)
2018-12-17T23:07:01.291944577Z 62 PC: 21300 | Close file
2018-12-17T23:07:01.294818241Z 54 PC: 21327 | Get free disk space
2018-12-17T23:07:01.338085338Z 67 PC: 21341 | Get or set file attributes
2018-12-17T23:07:01.678539028Z 61 PC: 21358 | Open file (Filename = '')
2018-12-17T23:07:01.68767586Z 87 PC: 21360 | Get or set file date and time
2018-12-17T23:07:01.68995838Z 63 PC: 21374 | Read file or device (Read 24 bytes on handle 5)
2018-12-17T23:07:01.69963541Z 66 PC: 21382 | Move file pointer
2018-12-17T23:07:01.702880408Z 64 PC: 2144b | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:07:01.707001669Z 66 PC: 21452 | Move file pointer
2018-12-17T23:07:01.708643689Z 72 PC: 2145a | Allocate memory
2018-12-17T23:07:01.711797391Z 42 PC: 21530 | Get date 0x21530: sub cx, 0x7bc
0x21534: mov ax, 0x16d
0x21537: push dx
0x21538: mul cx
0x2153a: pop dx
0x2153b: xchg ax, bx
0x2153c: mov cl, 0x1e
0x2153e: mov al, dh
0x21540: dec ax
0x21541: mul cl
0x21543: add bx, ax
0x21545: xor dh, dh
0x21547: add bx, dx
0x21549: ret
0x2154a: jmp 0x22aba
0x2154d: adc al, byte ptr [bx + si]
0x2154f: add al, 4
0x21551: sub al, 0
0x21553: inc bx
0x21554: dec di
2018-12-17T23:07:01.714586959Z 64 PC: 2147c | Write file or device (Write 1778 bytes on handle 5)
2018-12-17T23:07:01.733171102Z 64 PC: 2148e | Write file or device (Write 9 bytes on handle 5)
2018-12-17T23:07:01.738078211Z 73 PC: 21492 | Release memory
2018-12-17T23:07:01.739877012Z 87 PC: 214a4 | Get or set file date and time
2018-12-17T23:07:01.741993121Z 62 PC: 214a8 | Close file
2018-12-17T23:07:01.75107215Z 67 PC: 214b5 | Get or set file attributes
2018-12-17T23:07:01.761765387Z 37 PC: 214cb | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:07:01.76349518Z 37 PC: 214d4 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:01.765247854Z 37 PC: 214dd | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T23:07:01.768062527Z 37 PC: 214e6 | Set interrupt vector (Interrupt = '38' AKA 'Create PSP')
2018-12-17T23:07:01.769797758Z 73 PC: 21035 | Release memory
2018-12-17T23:07:01.771698173Z 72 PC: 2103d | Allocate memory
2018-12-17T23:07:01.775906518Z 72 PC: 21041 | Allocate memory
2018-12-17T23:07:01.778163509Z 80 PC: 14a29 | Set current PSP
2018-12-17T23:07:01.779565668Z 48 PC: 14a2e | Get DOS version
2018-12-17T23:07:01.782194275Z 2 PC: 148dc | Character output (Char = '4d')
2018-12-17T23:07:01.78534708Z 2 PC: 148dc | Character output (Char = '61')
2018-12-17T23:07:01.788176608Z 2 PC: 148dc | Character output (Char = '75')
2018-12-17T23:07:01.791774257Z 2 PC: 148dc | Character output (Char = '76')
2018-12-17T23:07:01.794914084Z 2 PC: 148dc | Character output (Char = '61')
2018-12-17T23:07:01.79774462Z 2 PC: 148dc | Character output (Char = '69')
2018-12-17T23:07:01.800751673Z 2 PC: 148dc | Character output (Char = '73')
2018-12-17T23:07:01.804405354Z 2 PC: 148dc | Character output (Char = '65')
2018-12-17T23:07:01.807230605Z 2 PC: 148dc | Character output (Char = '20')
2018-12-17T23:07:01.810052748Z 2 PC: 148dc | Character output (Char = '76')
2018-12-17T23:07:01.814836317Z 2 PC: 148dc | Character output (Char = '65')
2018-12-17T23:07:01.817646975Z 2 PC: 148dc | Character output (Char = '72')
2018-12-17T23:07:01.820474049Z 2 PC: 148dc | Character output (Char = '73')
2018-12-17T23:07:01.82429295Z 2 PC: 148dc | Character output (Char = '69')
2018-12-17T23:07:01.827097997Z 2 PC: 148dc | Character output (Char = '6f')
2018-12-17T23:07:01.829849986Z 2 PC: 148dc | Character output (Char = '6e')
2018-12-17T23:07:01.833521763Z 2 PC: 148dc | Character output (Char = '20')
2018-12-17T23:07:01.836674118Z 2 PC: 148dc | Character output (Char = '64')
2018-12-17T23:07:01.839503604Z 2 PC: 148dc | Character output (Char = '65')
2018-12-17T23:07:01.843075532Z 2 PC: 148dc | Character output (Char = '20')
2018-12-17T23:07:01.846191553Z 2 PC: 148dc | Character output (Char = '4d')
2018-12-17T23:07:01.848996183Z 2 PC: 148dc | Character output (Char = '53')
2018-12-17T23:07:01.852340766Z 2 PC: 148dc | Character output (Char = '2d')
2018-12-17T23:07:01.855180659Z 2 PC: 148dc | Character output (Char = '44')
2018-12-17T23:07:01.866837309Z 2 PC: 148dc | Character output (Char = '4f')
2018-12-17T23:07:01.870339891Z 2 PC: 148dc | Character output (Char = '53')
2018-12-17T23:07:01.872856835Z 2 PC: 148dc | Character output (Char = '0d')
2018-12-17T23:07:01.875219766Z 2 PC: 148dc | Character output (Char = '0a')