Sample viewer

vx.netlux.org/Virus.DOS.VCL.Westar.657

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:10:47.291913049Z 47 PC: 12a61 | Get disk transfer address
2018-12-17T23:10:47.293462027Z 26 PC: 12a69 | Set disk transfer address
2018-12-17T23:10:47.296014386Z 42 PC: 12c1e | Get date 0x12c1e: mov al, dl
0x12c20: cwde
0x12c21: ret
0x12c22: mov ah, 0x2a
0x12c24: int 0x21
0x12c26: mov al, dh
0x12c28: cwde
0x12c29: ret
0x12c2a: mov ah, 0x2a
0x12c2c: int 0x21
0x12c2e: xchg ax, cx
0x12c2f: ret
0x12c30: sub ch, byte ptr [bp + si]
0x12c32: sub ch, byte ptr [bp + si]
0x12c34: and byte ptr [bx + si], ah
0x12c36: dec ax
0x12c37: jb 0x12c9f
0x12c3a: and byte ptr [bx + di + 0x73], ch
0x12c3d: and byte ptr [bx + di + 0x20], ah
0x12c40: ja 0x12ca7
2018-12-17T23:10:47.298790821Z 42 PC: 12c26 | Get date 0x12c26: mov al, dh
0x12c28: cwde
0x12c29: ret
0x12c2a: mov ah, 0x2a
0x12c2c: int 0x21
0x12c2e: xchg ax, cx
0x12c2f: ret
0x12c30: sub ch, byte ptr [bp + si]
0x12c32: sub ch, byte ptr [bp + si]
0x12c34: and byte ptr [bx + si], ah
0x12c36: dec ax
0x12c37: jb 0x12c9f
0x12c3a: and byte ptr [bx + di + 0x73], ch
0x12c3d: and byte ptr [bx + di + 0x20], ah
0x12c40: ja 0x12ca7
0x12c42: insb byte ptr es:[di], dx
0x12c43: arpl word ptr [bx + 0x6d], bp
0x12c46: and byte ptr gs:[si + 0x6f], dh
0x12c4a: and byte ptr [bx + di + 0x6f], bh
0x12c4d: jne 0x12c6f
2018-12-17T23:10:47.301517667Z 42 PC: 12c2e | Get date 0x12c2e: xchg ax, cx
0x12c2f: ret
0x12c30: sub ch, byte ptr [bp + si]
0x12c32: sub ch, byte ptr [bp + si]
0x12c34: and byte ptr [bx + si], ah
0x12c36: dec ax
0x12c37: jb 0x12c9f
0x12c3a: and byte ptr [bx + di + 0x73], ch
0x12c3d: and byte ptr [bx + di + 0x20], ah
0x12c40: ja 0x12ca7
0x12c42: insb byte ptr es:[di], dx
0x12c43: arpl word ptr [bx + 0x6d], bp
0x12c46: and byte ptr gs:[si + 0x6f], dh
0x12c4a: and byte ptr [bx + di + 0x6f], bh
0x12c4d: jne 0x12c6f
0x12c4f: outsd dx, dword ptr [si]
0x12c51: jb 0x12c73
0x12c53: je 0x12cbd
0x12c55: and byte ptr gs:[bp + 0x65], cl
0x12c59: ja 0x12c7b
2018-12-17T23:10:47.310618895Z 71 PC: 12aca | Get current directory
2018-12-17T23:10:47.315078082Z 59 PC: 12ad2 | Change current directory
2018-12-17T23:10:47.319610102Z 47 PC: 12ae7 | Get disk transfer address
2018-12-17T23:10:47.322277514Z 26 PC: 12af5 | Set disk transfer address
2018-12-17T23:10:47.323528656Z 78 PC: 12b00 | Find first file
2018-12-17T23:10:47.331181062Z 79 PC: 12b28 | Find next file
2018-12-17T23:10:47.335218298Z 79 PC: 12b28 | Find next file
2018-12-17T23:10:47.338497472Z 79 PC: 12b28 | Find next file
2018-12-17T23:10:47.341261622Z 79 PC: 12b28 | Find next file
2018-12-17T23:10:47.34402812Z 79 PC: 12b28 | Find next file
2018-12-17T23:10:47.347535095Z 79 PC: 12b28 | Find next file
2018-12-17T23:10:47.358260034Z 79 PC: 12b28 | Find next file
2018-12-17T23:10:47.361129632Z 79 PC: 12b28 | Find next file
2018-12-17T23:10:47.372922847Z 79 PC: 12b28 | Find next file
2018-12-17T23:10:47.375795887Z 47 PC: 12b4c | Get disk transfer address
2018-12-17T23:10:47.37712537Z 26 PC: 12b5b | Set disk transfer address
2018-12-17T23:10:47.379032952Z 78 PC: 12b63 | Find first file
2018-12-17T23:10:47.385536234Z 47 PC: 12b7b | Get disk transfer address
2018-12-17T23:10:47.386778321Z 61 PC: 12b94 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:10:47.394536678Z 63 PC: 12ba0 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:10:47.402625438Z 66 PC: 12ba8 | Move file pointer
2018-12-17T23:10:47.40527155Z 62 PC: 12bad | Close file
2018-12-17T23:10:47.408618467Z 67 PC: 12bcd | Get or set file attributes
2018-12-17T23:10:47.427177645Z 61 PC: 12bd2 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:10:47.435308069Z 64 PC: 12bde | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:10:47.439504416Z 66 PC: 12be6 | Move file pointer
2018-12-17T23:10:47.441095768Z 64 PC: 12bf1 | Write file or device (Write 657 bytes on handle 5)
2018-12-17T23:10:47.450851805Z 87 PC: 12bfc | Get or set file date and time
2018-12-17T23:10:47.452736586Z 62 PC: 12c00 | Close file
2018-12-17T23:10:47.462837966Z 67 PC: 12c0d | Get or set file attributes
2018-12-17T23:10:47.474924385Z 26 PC: 12b75 | Set disk transfer address
2018-12-17T23:10:47.476775524Z 26 PC: 12b38 | Set disk transfer address
2018-12-17T23:10:47.479341327Z 59 PC: 12adc | Change current directory
2018-12-17T23:10:47.482416827Z 71 PC: 12aca | Get current directory
2018-12-17T23:10:47.485936639Z 59 PC: 12ad2 | Change current directory
2018-12-17T23:10:47.491387862Z 47 PC: 12ae7 | Get disk transfer address
2018-12-17T23:10:47.493723235Z 26 PC: 12af5 | Set disk transfer address
2018-12-17T23:10:47.494956388Z 78 PC: 12b00 | Find first file
2018-12-17T23:10:47.502052909Z 79 PC: 12b28 | Find next file
2018-12-17T23:10:47.504874037Z 79 PC: 12b28 | Find next file
2018-12-17T23:10:47.507594127Z 79 PC: 12b28 | Find next file
2018-12-17T23:10:47.5110539Z 79 PC: 12b28 | Find next file
2018-12-17T23:10:47.514115105Z 79 PC: 12b28 | Find next file
2018-12-17T23:10:47.517186571Z 79 PC: 12b28 | Find next file
2018-12-17T23:10:47.520669461Z 79 PC: 12b28 | Find next file
2018-12-17T23:10:47.523968526Z 79 PC: 12b28 | Find next file
2018-12-17T23:10:47.526968439Z 79 PC: 12b28 | Find next file
2018-12-17T23:10:47.529814434Z 47 PC: 12b4c | Get disk transfer address
2018-12-17T23:10:47.531499341Z 26 PC: 12b5b | Set disk transfer address
2018-12-17T23:10:47.533153528Z 78 PC: 12b63 | Find first file
2018-12-17T23:10:47.537688513Z 47 PC: 12b7b | Get disk transfer address
2018-12-17T23:10:47.539395211Z 61 PC: 12b94 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:10:47.543950264Z 63 PC: 12ba0 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:10:47.549416193Z 66 PC: 12ba8 | Move file pointer
2018-12-17T23:10:47.551418967Z 62 PC: 12bad | Close file
2018-12-17T23:10:47.55309858Z 79 PC: 12b63 | Find next file
2018-12-17T23:10:47.555385438Z 47 PC: 12b7b | Get disk transfer address
2018-12-17T23:10:47.557879573Z 61 PC: 12b94 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:10:47.562505857Z 63 PC: 12ba0 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:10:47.567228264Z 66 PC: 12ba8 | Move file pointer
2018-12-17T23:10:47.572083957Z 62 PC: 12bad | Close file
2018-12-17T23:10:47.574064194Z 67 PC: 12bcd | Get or set file attributes
2018-12-17T23:10:47.585340112Z 61 PC: 12bd2 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:10:47.593346219Z 64 PC: 12bde | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:10:47.596431727Z 66 PC: 12be6 | Move file pointer
2018-12-17T23:10:47.597957706Z 64 PC: 12bf1 | Write file or device (Write 657 bytes on handle 5)
2018-12-17T23:10:47.604122941Z 87 PC: 12bfc | Get or set file date and time
2018-12-17T23:10:47.605404763Z 62 PC: 12c00 | Close file
2018-12-17T23:10:47.614043413Z 67 PC: 12c0d | Get or set file attributes
2018-12-17T23:10:47.62562363Z 26 PC: 12b75 | Set disk transfer address
2018-12-17T23:10:47.627406857Z 26 PC: 12b38 | Set disk transfer address
2018-12-17T23:10:47.62862788Z 59 PC: 12adc | Change current directory
2018-12-17T23:10:47.630590658Z 26 PC: 12aaa | Set disk transfer address