Sample viewer

vx.netlux.org/Virus.DOS.SillyOC.IMF.754

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:53.468343053Z 42 PC: 12c21 | Get date 0x12c21: ret
0x12c22: dec bp
0x12c23: inc bp
0x12c24: dec bp
0x12c25: inc bx
0x12c27: dec di
0x12c28: dec bp
0x12c29: add byte ptr [bx + di + 0x6e], cl
0x12c2c: arpl word ptr [bx + 0x72], bp
0x12c2f: jb 0x12c96
0x12c31: arpl word ptr [si + 0x20], si
0x12c34: inc sp
0x12c35: dec di
0x12c36: push bx
0x12c37: and byte ptr [bp + 0x65], dh
0x12c3a: jb 0x12caf
0x12c3c: imul bp, word ptr [bx + 0x6e], 0xd0a
0x12c41: and al, 0
0x12c43: add byte ptr [bx + si], al
0x12c45: add byte ptr [bp + si], ch
2018-12-17T23:11:53.471116609Z 78 PC: 12c21 | Find first file
2018-12-17T23:11:53.479288337Z 67 PC: 12c21 | Get or set file attributes
2018-12-17T23:11:53.497428401Z 61 PC: 12c21 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:11:53.50540452Z 63 PC: 12c21 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:11:53.513437327Z 66 PC: 12ab6 | Move file pointer
2018-12-17T23:11:53.515484787Z 66 PC: 12c21 | Move file pointer
2018-12-17T23:11:53.517473026Z 44 PC: 12ac9 | Get time 0x12ac9: mov byte ptr [0x3c5], dl
0x12acd: mov byte ptr [0x3cc], dl
0x12ad1: mov byte ptr [0x3d4], dl
0x12ad5: mov byte ptr [0x3df], dl
0x12ad9: mov byte ptr [0x3e4], dl
0x12add: mov byte ptr [0x3eb], dl
0x12ae1: mov byte ptr [0x3f0], dl
0x12ae5: mov byte ptr [0x3a7], dl
0x12ae9: mov byte ptr [0x3b8], dl
0x12aed: mov byte ptr [0x3bf], dl
0x12af1: mov byte ptr [0x3e8], dl
0x12af5: mov byte ptr [0x3db], dl
0x12af9: mov byte ptr [0x3d5], dl
0x12afd: mov byte ptr [0x3cd], dl
0x12b01: mov byte ptr [0x3c6], dl
0x12b05: mov byte ptr [0x397], dl
0x12b09: mov byte ptr [0x39d], dl
0x12b0d: mov byte ptr [0x3a2], dl
0x12b11: mov byte ptr [0x3ad], dl
0x12b15: mov byte ptr [0xb3], dl
2018-12-17T23:11:53.521759698Z 64 PC: 12cf6 | Write file or device (Write 754 bytes on handle 5)
2018-12-17T23:11:53.532946055Z 62 PC: 12c21 | Close file
2018-12-17T23:11:53.543114417Z 62 PC: 12b2a | Close file
2018-12-17T23:11:53.546051982Z 79 PC: 12c21 | Find next file
2018-12-17T23:11:53.550512199Z 67 PC: 12c21 | Get or set file attributes
2018-12-17T23:11:53.562251376Z 61 PC: 12c21 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:11:53.576237899Z 63 PC: 12c21 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:11:53.58901124Z 66 PC: 12ab6 | Move file pointer
2018-12-17T23:11:53.590793973Z 66 PC: 12c21 | Move file pointer
2018-12-17T23:11:53.592661064Z 44 PC: 12ac9 | Get time 0x12ac9: mov byte ptr [0x3c5], dl
0x12acd: mov byte ptr [0x3cc], dl
0x12ad1: mov byte ptr [0x3d4], dl
0x12ad5: mov byte ptr [0x3df], dl
0x12ad9: mov byte ptr [0x3e4], dl
0x12add: mov byte ptr [0x3eb], dl
0x12ae1: mov byte ptr [0x3f0], dl
0x12ae5: mov byte ptr [0x3a7], dl
0x12ae9: mov byte ptr [0x3b8], dl
0x12aed: mov byte ptr [0x3bf], dl
0x12af1: mov byte ptr [0x3e8], dl
0x12af5: mov byte ptr [0x3db], dl
0x12af9: mov byte ptr [0x3d5], dl
0x12afd: mov byte ptr [0x3cd], dl
0x12b01: mov byte ptr [0x3c6], dl
0x12b05: mov byte ptr [0x397], dl
0x12b09: mov byte ptr [0x39d], dl
0x12b0d: mov byte ptr [0x3a2], dl
0x12b11: mov byte ptr [0x3ad], dl
0x12b15: mov byte ptr [0xb3], dl
2018-12-17T23:11:53.596272386Z 64 PC: 12cf6 | Write file or device (Write 754 bytes on handle 5)
2018-12-17T23:11:53.605316945Z 62 PC: 12c21 | Close file
2018-12-17T23:11:53.614539719Z 62 PC: 12b2a | Close file
2018-12-17T23:11:53.617190795Z 79 PC: 12c21 | Find next file
2018-12-17T23:11:53.62025116Z 67 PC: 12c21 | Get or set file attributes
2018-12-17T23:11:53.631393113Z 61 PC: 12c21 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:11:53.639716526Z 63 PC: 12c21 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:11:53.64664215Z 66 PC: 12ab6 | Move file pointer
2018-12-17T23:11:53.648184361Z 66 PC: 12c21 | Move file pointer
2018-12-17T23:11:53.650524822Z 44 PC: 12ac9 | Get time 0x12ac9: mov byte ptr [0x3c5], dl
0x12acd: mov byte ptr [0x3cc], dl
0x12ad1: mov byte ptr [0x3d4], dl
0x12ad5: mov byte ptr [0x3df], dl
0x12ad9: mov byte ptr [0x3e4], dl
0x12add: mov byte ptr [0x3eb], dl
0x12ae1: mov byte ptr [0x3f0], dl
0x12ae5: mov byte ptr [0x3a7], dl
0x12ae9: mov byte ptr [0x3b8], dl
0x12aed: mov byte ptr [0x3bf], dl
0x12af1: mov byte ptr [0x3e8], dl
0x12af5: mov byte ptr [0x3db], dl
0x12af9: mov byte ptr [0x3d5], dl
0x12afd: mov byte ptr [0x3cd], dl
0x12b01: mov byte ptr [0x3c6], dl
0x12b05: mov byte ptr [0x397], dl
0x12b09: mov byte ptr [0x39d], dl
0x12b0d: mov byte ptr [0x3a2], dl
0x12b11: mov byte ptr [0x3ad], dl
0x12b15: mov byte ptr [0xb3], dl
2018-12-17T23:11:53.65357078Z 64 PC: 12cf6 | Write file or device (Write 754 bytes on handle 5)
2018-12-17T23:11:53.663527425Z 62 PC: 12c21 | Close file
2018-12-17T23:11:53.675028854Z 62 PC: 12b2a | Close file
2018-12-17T23:11:53.676817858Z 79 PC: 12c21 | Find next file
2018-12-17T23:11:53.679715057Z 67 PC: 12c21 | Get or set file attributes
2018-12-17T23:11:53.690908417Z 61 PC: 12c21 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:11:53.698685312Z 63 PC: 12c21 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:11:53.705507703Z 66 PC: 12ab6 | Move file pointer
2018-12-17T23:11:53.707037079Z 66 PC: 12c21 | Move file pointer
2018-12-17T23:11:53.709246724Z 44 PC: 12ac9 | Get time 0x12ac9: mov byte ptr [0x3c5], dl
0x12acd: mov byte ptr [0x3cc], dl
0x12ad1: mov byte ptr [0x3d4], dl
0x12ad5: mov byte ptr [0x3df], dl
0x12ad9: mov byte ptr [0x3e4], dl
0x12add: mov byte ptr [0x3eb], dl
0x12ae1: mov byte ptr [0x3f0], dl
0x12ae5: mov byte ptr [0x3a7], dl
0x12ae9: mov byte ptr [0x3b8], dl
0x12aed: mov byte ptr [0x3bf], dl
0x12af1: mov byte ptr [0x3e8], dl
0x12af5: mov byte ptr [0x3db], dl
0x12af9: mov byte ptr [0x3d5], dl
0x12afd: mov byte ptr [0x3cd], dl
0x12b01: mov byte ptr [0x3c6], dl
0x12b05: mov byte ptr [0x397], dl
0x12b09: mov byte ptr [0x39d], dl
0x12b0d: mov byte ptr [0x3a2], dl
0x12b11: mov byte ptr [0x3ad], dl
0x12b15: mov byte ptr [0xb3], dl
2018-12-17T23:11:53.712028926Z 64 PC: 12cf6 | Write file or device (Write 754 bytes on handle 5)
2018-12-17T23:11:53.721084015Z 62 PC: 12c21 | Close file
2018-12-17T23:11:54.05378051Z 62 PC: 12b2a | Close file
2018-12-17T23:11:54.060152704Z 79 PC: 12c21 | Find next file
2018-12-17T23:11:54.063466065Z 67 PC: 12c21 | Get or set file attributes
2018-12-17T23:11:54.080823737Z 61 PC: 12c21 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:11:54.08863152Z 63 PC: 12c21 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:11:54.096129501Z 66 PC: 12ab6 | Move file pointer
2018-12-17T23:11:54.099257243Z 66 PC: 12c21 | Move file pointer
2018-12-17T23:11:54.103526191Z 44 PC: 12ac9 | Get time 0x12ac9: mov byte ptr [0x3c5], dl
0x12acd: mov byte ptr [0x3cc], dl
0x12ad1: mov byte ptr [0x3d4], dl
0x12ad5: mov byte ptr [0x3df], dl
0x12ad9: mov byte ptr [0x3e4], dl
0x12add: mov byte ptr [0x3eb], dl
0x12ae1: mov byte ptr [0x3f0], dl
0x12ae5: mov byte ptr [0x3a7], dl
0x12ae9: mov byte ptr [0x3b8], dl
0x12aed: mov byte ptr [0x3bf], dl
0x12af1: mov byte ptr [0x3e8], dl
0x12af5: mov byte ptr [0x3db], dl
0x12af9: mov byte ptr [0x3d5], dl
0x12afd: mov byte ptr [0x3cd], dl
0x12b01: mov byte ptr [0x3c6], dl
0x12b05: mov byte ptr [0x397], dl
0x12b09: mov byte ptr [0x39d], dl
0x12b0d: mov byte ptr [0x3a2], dl
0x12b11: mov byte ptr [0x3ad], dl
0x12b15: mov byte ptr [0xb3], dl
2018-12-17T23:11:54.106756235Z 64 PC: 12cf6 | Write file or device (Write 754 bytes on handle 5)
2018-12-17T23:11:54.116568949Z 62 PC: 12c21 | Close file
2018-12-17T23:11:54.126117826Z 62 PC: 12b2a | Close file
2018-12-17T23:11:54.128570679Z 79 PC: 12c21 | Find next file
2018-12-17T23:11:54.132743567Z 67 PC: 12c21 | Get or set file attributes
2018-12-17T23:11:54.14515645Z 61 PC: 12c21 | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:11:54.153546599Z 63 PC: 12c21 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:11:54.161106726Z 66 PC: 12ab6 | Move file pointer
2018-12-17T23:11:54.164480571Z 66 PC: 12c21 | Move file pointer
2018-12-17T23:11:54.16658618Z 44 PC: 12ac9 | Get time 0x12ac9: mov byte ptr [0x3c5], dl
0x12acd: mov byte ptr [0x3cc], dl
0x12ad1: mov byte ptr [0x3d4], dl
0x12ad5: mov byte ptr [0x3df], dl
0x12ad9: mov byte ptr [0x3e4], dl
0x12add: mov byte ptr [0x3eb], dl
0x12ae1: mov byte ptr [0x3f0], dl
0x12ae5: mov byte ptr [0x3a7], dl
0x12ae9: mov byte ptr [0x3b8], dl
0x12aed: mov byte ptr [0x3bf], dl
0x12af1: mov byte ptr [0x3e8], dl
0x12af5: mov byte ptr [0x3db], dl
0x12af9: mov byte ptr [0x3d5], dl
0x12afd: mov byte ptr [0x3cd], dl
0x12b01: mov byte ptr [0x3c6], dl
0x12b05: mov byte ptr [0x397], dl
0x12b09: mov byte ptr [0x39d], dl
0x12b0d: mov byte ptr [0x3a2], dl
0x12b11: mov byte ptr [0x3ad], dl
0x12b15: mov byte ptr [0xb3], dl
2018-12-17T23:11:54.16981354Z 64 PC: 12cf6 | Write file or device (Write 754 bytes on handle 5)
2018-12-17T23:11:54.18017738Z 62 PC: 12c21 | Close file
2018-12-17T23:11:54.189346684Z 62 PC: 12b2a | Close file
2018-12-17T23:11:54.190976248Z 79 PC: 12c21 | Find next file
2018-12-17T23:11:54.195117997Z 67 PC: 12c21 | Get or set file attributes
2018-12-17T23:11:54.205595631Z 61 PC: 12c21 | Open file (Filename = 'PAH.COM')
2018-12-17T23:11:54.213048177Z 63 PC: 12c21 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:11:54.221466137Z 66 PC: 12ab6 | Move file pointer
2018-12-17T23:11:54.223099278Z 66 PC: 12c21 | Move file pointer
2018-12-17T23:11:54.224688527Z 44 PC: 12ac9 | Get time 0x12ac9: mov byte ptr [0x3c5], dl
0x12acd: mov byte ptr [0x3cc], dl
0x12ad1: mov byte ptr [0x3d4], dl
0x12ad5: mov byte ptr [0x3df], dl
0x12ad9: mov byte ptr [0x3e4], dl
0x12add: mov byte ptr [0x3eb], dl
0x12ae1: mov byte ptr [0x3f0], dl
0x12ae5: mov byte ptr [0x3a7], dl
0x12ae9: mov byte ptr [0x3b8], dl
0x12aed: mov byte ptr [0x3bf], dl
0x12af1: mov byte ptr [0x3e8], dl
0x12af5: mov byte ptr [0x3db], dl
0x12af9: mov byte ptr [0x3d5], dl
0x12afd: mov byte ptr [0x3cd], dl
0x12b01: mov byte ptr [0x3c6], dl
0x12b05: mov byte ptr [0x397], dl
0x12b09: mov byte ptr [0x39d], dl
0x12b0d: mov byte ptr [0x3a2], dl
0x12b11: mov byte ptr [0x3ad], dl
0x12b15: mov byte ptr [0xb3], dl
2018-12-17T23:11:54.227790069Z 64 PC: 12cf6 | Write file or device (Write 754 bytes on handle 5)
2018-12-17T23:11:54.237509658Z 62 PC: 12c21 | Close file
2018-12-17T23:11:54.246930996Z 62 PC: 12b2a | Close file
2018-12-17T23:11:54.248901111Z 79 PC: 12c21 | Find next file
2018-12-17T23:11:54.253338546Z 67 PC: 12c21 | Get or set file attributes
2018-12-17T23:11:54.264070328Z 61 PC: 12c21 | Open file (Filename = 'TEST.COM')
2018-12-17T23:11:54.271596512Z 63 PC: 12c21 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:11:54.275360871Z 62 PC: 12b2a | Close file
2018-12-17T23:11:54.277280951Z 79 PC: 12c21 | Find next file
2018-12-17T23:11:54.281037195Z 78 PC: 12b4d | Find first file
2018-12-17T23:11:54.289328438Z 53 PC: 12b58 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:54.291025169Z 37 PC: 12b68 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:54.293156046Z 53 PC: 12c21 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:54.295521284Z 37 PC: 12c21 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:11:54.297469548Z 9 PC: 12c21 | Display string (Could not find end pointer)
2018-12-17T23:11:54.302548489Z 37 PC: 12b98 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:11:54.304727887Z 49 PC: 12c21 | Terminate and stay resident (Return code = '36' | Memory size = '64')