Sample viewer

vx.netlux.org/Virus.DOS.V.1443

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:06.928130754Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x10
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:06.930950392Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:06.93389619Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:06.937769948Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:06.940449481Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: stc
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:06.943038976Z 42 PC: 138c0 | Get date 0x138c0: mov al, byte ptr [bx + 0x33a]
0x138c4: mov byte ptr [bx + 0x4df], al
0x138c8: mov byte ptr [bx + 0x33a], dh
0x138cc: ret
2018-12-17T23:11:06.945822514Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:06.948408942Z 47 PC: 1395e | Get disk transfer address
2018-12-17T23:11:06.949759166Z 26 PC: 13976 | Set disk transfer address
2018-12-17T23:11:06.951172749Z 78 PC: 137e5 | Find first file
2018-12-17T23:11:06.959351261Z 79 PC: 137e5 | Find next file
2018-12-17T23:11:06.962172041Z 78 PC: 137e5 | Find first file
2018-12-17T23:11:06.972608322Z 67 PC: 13533 | Get or set file attributes
2018-12-17T23:11:06.983881495Z 61 PC: 1354d | Open file (Filename = 'C:\DOS\ATTRIB.EXE')
2018-12-17T23:11:06.989482401Z 87 PC: 13559 | Get or set file date and time
2018-12-17T23:11:06.990757963Z 66 PC: 138d5 | Move file pointer
2018-12-17T23:11:06.992836031Z 63 PC: 1357a | Read file or device (Read 24 bytes on handle 5)
2018-12-17T23:11:06.997085542Z 66 PC: 138d5 | Move file pointer
2018-12-17T23:11:06.998384936Z 66 PC: 138d5 | Move file pointer
2018-12-17T23:11:07.00237621Z 64 PC: 135e1 | Write file or device (Write 24 bytes on handle 5)
2018-12-17T23:11:07.005183915Z 66 PC: 138d5 | Move file pointer
2018-12-17T23:11:07.006368661Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.009033556Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.010864263Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.012832078Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.027043241Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.029602802Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.032138284Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.034595506Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.03718904Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.039911076Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.043449508Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.050055624Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.052042239Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.05450859Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.057722814Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.060284007Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.062730918Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.074553204Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.077665478Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.079954584Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.082603326Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.085954309Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.088636925Z 64 PC: 136f8 | Write file or device (Write 1620 bytes on handle 5)
2018-12-17T23:11:07.437573531Z 87 PC: 13708 | Get or set file date and time
2018-12-17T23:11:07.440710328Z 62 PC: 1370c | Close file
2018-12-17T23:11:07.449292687Z 44 PC: 13894 | Get time 0x13894: mov ax, dx
0x13896: pop dx
0x13897: pop cx
0x13898: ret
0x13899: mov al, 0x1e
0x1389b: sub ah, al
0x1389d: mov bx, bp
0x1389f: cmp ah, 1
0x138a2: jbe 0x138b7
0x138a4: mov word ptr [bx + 0x84], 0xea
0x138aa: mov al, 3
0x138ac: xor dx, dx
0x138ae: jmp 0x138b2
0x138b0: nop
2018-12-17T23:11:07.451974459Z 47 PC: 13982 | Get disk transfer address
2018-12-17T23:11:07.454819465Z 9 PC: 133f2 | Display string (Could not find end pointer)
2018-12-17T23:11:07.460314755Z 76 PC: 133f8 | Terminate with return code (Return code = '0')