Sample viewer

vx.netlux.org/Virus.DOS.Birgit.310

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:10:05.374596794Z 11 PC: 12a5c | Get input status
2018-12-17T23:10:05.378146012Z 26 PC: 12a6e | Set disk transfer address
2018-12-17T23:10:05.379645903Z 78 PC: 12a76 | Find first file
2018-12-17T23:10:05.386116847Z 61 PC: 12a81 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:10:05.393410469Z 63 PC: 12a8d | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:10:05.403112509Z 66 PC: 12aa1 | Move file pointer
2018-12-17T23:10:05.404459902Z 64 PC: 12b66 | Write file or device (Write 310 bytes on handle 5)
2018-12-17T23:10:05.420801063Z 66 PC: 12ac3 | Move file pointer
2018-12-17T23:10:05.42331413Z 64 PC: 12ace | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:10:05.430615023Z 62 PC: 12ad2 | Close file
2018-12-17T23:10:05.439620091Z 79 PC: 12a76 | Find next file
2018-12-17T23:10:05.443109745Z 61 PC: 12a81 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:10:05.451048547Z 63 PC: 12a8d | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:10:05.458540858Z 66 PC: 12aa1 | Move file pointer
2018-12-17T23:10:05.461392295Z 64 PC: 12b66 | Write file or device (Write 310 bytes on handle 5)
2018-12-17T23:10:05.464648729Z 66 PC: 12ac3 | Move file pointer
2018-12-17T23:10:05.466134146Z 64 PC: 12ace | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:10:05.469321003Z 62 PC: 12ad2 | Close file
2018-12-17T23:10:05.477981105Z 79 PC: 12a76 | Find next file
2018-12-17T23:10:05.481164371Z 61 PC: 12a81 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:10:05.489666635Z 63 PC: 12a8d | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:10:05.503753929Z 66 PC: 12aa1 | Move file pointer
2018-12-17T23:10:05.505829468Z 64 PC: 12b66 | Write file or device (Write 310 bytes on handle 5)
2018-12-17T23:10:05.509180318Z 66 PC: 12ac3 | Move file pointer
2018-12-17T23:10:05.512149492Z 64 PC: 12ace | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:10:05.515554353Z 62 PC: 12ad2 | Close file
2018-12-17T23:10:05.529482662Z 79 PC: 12a76 | Find next file
2018-12-17T23:10:05.533241963Z 61 PC: 12a81 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:10:05.541081045Z 63 PC: 12a8d | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:10:05.548454736Z 66 PC: 12aa1 | Move file pointer
2018-12-17T23:10:05.552137365Z 64 PC: 12b66 | Write file or device (Write 310 bytes on handle 5)
2018-12-17T23:10:05.555772341Z 66 PC: 12ac3 | Move file pointer
2018-12-17T23:10:05.557346011Z 64 PC: 12ace | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:10:05.560963843Z 62 PC: 12ad2 | Close file
2018-12-17T23:10:05.5709514Z 79 PC: 12a76 | Find next file
2018-12-17T23:10:05.57393718Z 61 PC: 12a81 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:10:05.581870696Z 63 PC: 12a8d | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:10:05.589006271Z 66 PC: 12aa1 | Move file pointer
2018-12-17T23:10:05.591061166Z 64 PC: 12b66 | Write file or device (Write 310 bytes on handle 5)
2018-12-17T23:10:05.596291442Z 66 PC: 12ac3 | Move file pointer
2018-12-17T23:10:05.598160811Z 64 PC: 12ace | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:10:05.601573514Z 62 PC: 12ad2 | Close file
2018-12-17T23:10:05.610752348Z 79 PC: 12a76 | Find next file
2018-12-17T23:10:05.614574024Z 61 PC: 12a81 | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:10:05.621831103Z 63 PC: 12a8d | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:10:05.629963096Z 66 PC: 12aa1 | Move file pointer
2018-12-17T23:10:05.633242253Z 64 PC: 12b66 | Write file or device (Write 310 bytes on handle 5)
2018-12-17T23:10:05.642307261Z 66 PC: 12ac3 | Move file pointer
2018-12-17T23:10:05.643588154Z 64 PC: 12ace | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:10:05.651682615Z 62 PC: 12ad2 | Close file
2018-12-17T23:10:05.670745029Z 79 PC: 12a76 | Find next file
2018-12-17T23:10:05.674440094Z 61 PC: 12a81 | Open file (Filename = 'PAH.COM')
2018-12-17T23:10:05.682901384Z 63 PC: 12a8d | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:10:05.693554855Z 66 PC: 12aa1 | Move file pointer
2018-12-17T23:10:05.696336841Z 64 PC: 12b66 | Write file or device (Write 310 bytes on handle 5)
2018-12-17T23:10:05.701203699Z 66 PC: 12ac3 | Move file pointer
2018-12-17T23:10:05.704209478Z 64 PC: 12ace | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:10:05.70807083Z 62 PC: 12ad2 | Close file
2018-12-17T23:10:05.718567258Z 79 PC: 12a76 | Find next file
2018-12-17T23:10:05.722124763Z 26 PC: 12add | Set disk transfer address
2018-12-17T23:10:05.724116696Z 42 PC: 12ae1 | Get date 0x12ae1: cmp dh, byte ptr ds:[bp + 0x1fc]
0x12ae6: je 0x12af3
0x12ae8: cmp byte ptr ds:[bp + 0x1fc], 0xd
0x12aee: jne 0x12b28
0x12af0: nop
0x12af1: nop
0x12af2: nop
0x12af3: cmp dl, byte ptr ds:[bp + 0x1fb]
0x12af8: je 0x12b05
0x12afa: cmp byte ptr ds:[bp + 0x1fb], 0x20
0x12b00: jne 0x12b28
0x12b02: nop
0x12b03: nop
0x12b04: nop
0x12b05: lea dx, word ptr [bp + 0x1d0]
0x12b09: mov ah, 9
0x12b0b: int 0x21
0x12b0d: jmp 0x12b28
0x12b0f: nop
0x12b10: inc dx