Sample viewer

vx.netlux.org/Virus.DOS.VCL.Angel.436

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:08:05.162247714Z 47 PC: 12b31 | Get disk transfer address
2018-12-17T23:08:05.164250867Z 26 PC: 12b39 | Set disk transfer address
2018-12-17T23:08:05.165467298Z 44 PC: 12c48 | Get time 0x12c48: mov al, dh
0x12c4a: cwde
0x12c4b: ret
0x12c4c: lea si, word ptr [di + 0x24d]
0x12c50: mov ah, 0xe
0x12c52: lodsb al, byte ptr [si]
0x12c53: or al, al
0x12c55: je 0x12c5b
0x12c57: int 0x10
0x12c59: jmp 0x12c52
0x12c5b: ret
0x12c5c: or ax, 0x70a
0x12c5f: inc cx
0x12c60: outsb dx, byte ptr [si]
0x12c61: insb byte ptr es:[edi], dx
0x12c64: and byte ptr [bx + si + 0x20], bl
0x12c67: jbe 0x12c97
0x12c69: xor word ptr [0xd31], bp
0x12c6d: or ch, byte ptr [bx + si]
0x12c6f: arpl word ptr [bx + di], bp
2018-12-17T23:08:05.167793052Z 47 PC: 12b79 | Get disk transfer address
2018-12-17T23:08:05.170146862Z 26 PC: 12b88 | Set disk transfer address
2018-12-17T23:08:05.171380659Z 78 PC: 12b92 | Find first file
2018-12-17T23:08:05.177403135Z 47 PC: 12bab | Get disk transfer address
2018-12-17T23:08:05.185195271Z 61 PC: 12bbb | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:08:05.191877728Z 63 PC: 12bc7 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:08:05.198258497Z 66 PC: 12bcf | Move file pointer
2018-12-17T23:08:05.200517428Z 62 PC: 12bd4 | Close file
2018-12-17T23:08:05.202288798Z 67 PC: 12bf4 | Get or set file attributes
2018-12-17T23:08:05.218401127Z 61 PC: 12bfb | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:08:05.225014571Z 64 PC: 12c07 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:08:05.228091986Z 66 PC: 12c0f | Move file pointer
2018-12-17T23:08:05.229403133Z 64 PC: 12c1a | Write file or device (Write 436 bytes on handle 5)
2018-12-17T23:08:05.237867544Z 87 PC: 12c25 | Get or set file date and time
2018-12-17T23:08:05.240255635Z 62 PC: 12c29 | Close file
2018-12-17T23:08:05.247817896Z 67 PC: 12c36 | Get or set file attributes
2018-12-17T23:08:05.257703715Z 26 PC: 12ba4 | Set disk transfer address
2018-12-17T23:08:05.26059964Z 26 PC: 12b55 | Set disk transfer address
2018-12-17T23:08:05.261868552Z 9 PC: 12a47 | Display string (String= '(C) 1993 American Eagle Poblications Inc., All Rights Reserved. Unauthorized use will be prosecuted under applicable copyright and software piracy laws. HOST #1 - You have just released a virus!')
2018-12-17T23:08:05.269188569Z 76 PC: 12a4c | Terminate with return code (Return code = '0')