Sample viewer

vx.netlux.org/Virus.DOS.Serbu.3322.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:08:29.733353396Z 98 PC: 13b13 | Get current PSP
2018-12-17T23:08:29.737492167Z 74 PC: 15084 | Reallocate memory
2018-12-17T23:08:29.739005767Z 72 PC: 1508b | Allocate memory
2018-12-17T23:08:29.740819346Z 85 PC: 15094 | Create program PSP
2018-12-17T23:08:29.747573371Z 80 PC: 1509a | Set current PSP
2018-12-17T23:08:29.748386965Z 73 PC: 150a3 | Release memory
2018-12-17T23:08:29.749568582Z 72 PC: 150a7 | Allocate memory
2018-12-17T23:08:29.751274908Z 42 PC: 15a21 | Get date 0x15a21: sti
0x15a22: ret
0x15a23: cli
0x15a24: pushf
0x15a25: lcall 0x19:0x44bd
0x15a2a: sti
0x15a2b: ret
0x15a2c: add al, byte ptr [si]
0x15a2e: and byte ptr ds:[bp + si + 0x4c], al
0x15a33: sub ax, 0x3339
0x15a36: xor word ptr [bx + di], si
0x15a38: xor ax, 0x3c20
0x15a3b: cmp al, 0x80
0x15a3d: loopne 0x15a3d
0x15a3f: add al, 0xf1
0x15a41: neg byte ptr [bp + si]
0x15a43: fstpnce st(0), st(0)
0x15a45: fcmovnu st(0), st(2)
0x15a47: fstp st(4)
0x15a49: fstp st(6), st(0)
2018-12-17T23:08:29.755778378Z 76 PC: 1399c | Terminate with return code (Return code = '0')
2018-12-17T23:08:29.759138394Z 77 PC: 11fe0 | Get program return code
2018-12-17T23:08:29.760639543Z 72 PC: 12174 | Allocate memory
2018-12-17T23:08:29.763453335Z 72 PC: 1218d | Allocate memory
2018-12-17T23:08:29.765430201Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:08:29.766860672Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:29.769833335Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:29.771959041Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:29.773688546Z 62 PC: 122ab | Close file
2018-12-17T23:08:29.776554889Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:29.779332899Z 62 PC: 122ab | Close file
2018-12-17T23:08:29.781597526Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:29.784710035Z 62 PC: 122ab | Close file
2018-12-17T23:08:29.786784054Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:29.788565379Z 62 PC: 122ab | Close file
2018-12-17T23:08:29.790761843Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:29.792962368Z 62 PC: 122ab | Close file
2018-12-17T23:08:29.795026956Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:29.796911503Z 62 PC: 122ab | Close file
2018-12-17T23:08:29.799241183Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:29.800907189Z 62 PC: 122ab | Close file
2018-12-17T23:08:29.803025114Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:29.805078764Z 62 PC: 122ab | Close file
2018-12-17T23:08:29.807667466Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:29.809538722Z 62 PC: 122ab | Close file
2018-12-17T23:08:29.812548063Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:29.814307407Z 62 PC: 122ab | Close file
2018-12-17T23:08:29.816258184Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:29.818473895Z 62 PC: 122ab | Close file
2018-12-17T23:08:29.820437998Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:29.822115544Z 62 PC: 122ab | Close file
2018-12-17T23:08:29.824964523Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:29.826769027Z 62 PC: 122ab | Close file
2018-12-17T23:08:29.828843651Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:29.831163702Z 62 PC: 122ab | Close file
2018-12-17T23:08:29.833289756Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:29.835101128Z 62 PC: 122ab | Close file
2018-12-17T23:08:29.839067028Z 99 PC: 9a5d7 | Get DBCS lead byte table pointer
2018-12-17T23:08:29.840708466Z 56 PC: 94df9 | Get or set country info
2018-12-17T23:08:29.843257212Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:08:29.849251692Z 25 PC: 94e62 | Get default drive
2018-12-17T23:08:29.850800842Z 71 PC: 970dd | Get current directory
2018-12-17T23:08:29.854913383Z 64 PC: 9a848 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T23:08:29.858859477Z 2 PC: 970b2 | Character output (Char = '3e')
2018-12-17T23:08:29.861272264Z 93 PC: 94f20 | File sharing functions
2018-12-17T23:08:29.863192793Z 93 PC: 94f27 | File sharing functions
2018-12-17T23:08:29.866535261Z 10 PC: 94f39 | Buffered keyboard input
2018-12-17T23:08:44.723110119Z 0 PC: 0 | Program terminate
2018-12-17T23:08:46.077826715Z 0 PC: 0 | Program terminate
2018-12-17T23:08:46.180238926Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:08:46.184119938Z 41 PC: 94fae | Parse filename
2018-12-17T23:08:46.186539329Z 41 PC: 9502f | Parse filename
2018-12-17T23:08:46.187759585Z 41 PC: 9504c | Parse filename
2018-12-17T23:08:46.189363762Z 26 PC: 984f7 | Set disk transfer address
2018-12-17T23:08:46.191074517Z 71 PC: 986f3 | Get current directory
2018-12-17T23:08:46.198655089Z 47 PC: 13601 | Get disk transfer address
2018-12-17T23:08:46.200460221Z 78 PC: 13601 | Find first file
2018-12-17T23:08:46.211719266Z 71 PC: 9856c | Get current directory
2018-12-17T23:08:46.221066439Z 73 PC: 97c09 | Release memory
2018-12-17T23:08:46.222946428Z 61 PC: 13601 | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T23:08:46.231074847Z 87 PC: 13601 | Get or set file date and time
2018-12-17T23:08:46.232733692Z 62 PC: 13601 | Close file
2018-12-17T23:08:46.234485203Z 53 PC: 13601 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:46.236383963Z 37 PC: 135db | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:46.237867057Z 67 PC: 13354 | Get or set file attributes
2018-12-17T23:08:46.243934161Z 67 PC: 1335d | Get or set file attributes
2018-12-17T23:08:46.261482687Z 61 PC: 13364 | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T23:08:46.280404825Z 63 PC: 13231 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T23:08:46.287700364Z 66 PC: 13261 | Move file pointer
2018-12-17T23:08:46.290623901Z 62 PC: 1337e | Close file
2018-12-17T23:08:46.29283774Z 67 PC: 1338a | Get or set file attributes
2018-12-17T23:08:46.303400208Z 37 PC: 13391 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:46.304837445Z 75 PC: 11821 | Execute program
2018-12-17T23:08:46.316304361Z 9 PC: 138a7 | Display string (String= 'Hello, World! ')
2018-12-17T23:08:46.330564708Z 76 PC: 138ab | Terminate with return code (Return code = '36')
2018-12-17T23:08:46.336857696Z 77 PC: 11fe0 | Get program return code
2018-12-17T23:08:46.339325056Z 72 PC: 12174 | Allocate memory
2018-12-17T23:08:46.341342885Z 72 PC: 1218d | Allocate memory
2018-12-17T23:08:46.344642783Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:08:46.347281447Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:08:46.348961045Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:08:46.351356126Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:46.354325691Z 62 PC: 122ab | Close file
2018-12-17T23:08:46.357427598Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:46.359372523Z 62 PC: 122ab | Close file
2018-12-17T23:08:46.362540172Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:46.364414618Z 62 PC: 122ab | Close file
2018-12-17T23:08:46.366559305Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:46.36936332Z 62 PC: 122ab | Close file
2018-12-17T23:08:46.371913812Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:46.373877982Z 62 PC: 122ab | Close file
2018-12-17T23:08:46.377320133Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:46.379144048Z 62 PC: 122ab | Close file
2018-12-17T23:08:46.381187225Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:46.383474773Z 62 PC: 122ab | Close file
2018-12-17T23:08:46.385302967Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:46.386774393Z 62 PC: 122ab | Close file
2018-12-17T23:08:46.38870411Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:46.390824427Z 62 PC: 122ab | Close file
2018-12-17T23:08:46.392628883Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:46.394119924Z 62 PC: 122ab | Close file
2018-12-17T23:08:46.396529745Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:46.398071124Z 62 PC: 122ab | Close file
2018-12-17T23:08:46.399864454Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:46.402563219Z 62 PC: 122ab | Close file
2018-12-17T23:08:46.404323987Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:46.405804129Z 62 PC: 122ab | Close file
2018-12-17T23:08:46.408666611Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:46.410389163Z 62 PC: 122ab | Close file
2018-12-17T23:08:46.412377774Z 68 PC: 13601 | I/O control for devices (Set for = 'mfyW� Wv W�Wj W� WcW� W�W W5W')
2018-12-17T23:08:46.415044722Z 62 PC: 122ab | Close file
2018-12-17T23:08:46.417925898Z 99 PC: 9a5d7 | Get DBCS lead byte table pointer
2018-12-17T23:08:46.419317473Z 56 PC: 94df9 | Get or set country info
2018-12-17T23:08:46.422825857Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:08:46.427564879Z 25 PC: 94e62 | Get default drive
2018-12-17T23:08:46.429428645Z 71 PC: 970dd | Get current directory
2018-12-17T23:08:46.435585196Z 64 PC: 9a848 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T23:08:46.438773551Z 2 PC: 970b2 | Character output (Char = '3e')
2018-12-17T23:08:46.44107407Z 93 PC: 94f20 | File sharing functions
2018-12-17T23:08:46.4436408Z 93 PC: 94f27 | File sharing functions
2018-12-17T23:08:46.446255525Z 10 PC: 94f39 | Buffered keyboard input