Sample viewer

vx.netlux.org/Virus.DOS.Gobot.4006

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:05:31.926505392Z 53 PC: 12a56 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:05:31.928833464Z 37 PC: 12a66 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:05:31.929901482Z 78 PC: 12a75 | Find first file
2018-12-17T22:05:31.935580867Z 61 PC: 12a7f | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:05:31.942417785Z 63 PC: 12a8a | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:05:31.948545825Z 44 PC: 12ade | Get time 0x12ade: xor dh, dh
0x12ae0: and dl, 7
0x12ae3: cmp dx, 6
0x12ae6: nop
0x12ae7: jg 0x12ada
0x12ae9: push dx
0x12aea: add dx, 0x348
0x12aee: mov si, dx
0x12af0: mov dl, byte ptr cs:[si]
0x12af3: mov byte ptr [0x103], dl
0x12af7: pop dx
0x12af8: push dx
0x12af9: add dx, 0x35d
0x12afd: mov si, dx
0x12aff: mov dl, byte ptr cs:[si]
0x12b02: mov byte ptr [0x100], dl
0x12b06: mov ah, 0x2c
0x12b08: int 0x21
0x12b0a: xor dh, dh
0x12b0c: and dl, 7
2018-12-17T22:05:31.950743686Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34f
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x356
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:05:31.953258274Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34f
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x356
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:05:31.955738165Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34f
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x356
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:05:31.958034033Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34f
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x356
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:05:31.961638862Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34f
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x356
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:05:31.964225955Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34f
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x356
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:05:31.966540694Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34f
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x356
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:05:31.96884342Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34f
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x356
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:05:31.972056807Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34f
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x356
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:05:31.97494207Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34f
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x356
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:05:31.977206089Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34f
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x356
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:05:31.982619193Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34f
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x356
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:05:31.98462006Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34f
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x356
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:05:31.988209431Z 66 PC: 12b41 | Move file pointer
2018-12-17T22:05:31.99018327Z 44 PC: 12b46 | Get time 0x12b46: mov word ptr [0x10a2], dx
0x12b4a: mov si, 0x2f3
0x12b4d: mov di, 0x10aa
0x12b50: mov cx, 0x1a
0x12b53: nop
0x12b54: rep movsb byte ptr es:[di], byte ptr [si]
0x12b56: call 0x139ea
0x12b59: mov ah, 0x3e
0x12b5b: int 0x21
0x12b5d: mov ah, 0x2c
0x12b5f: int 0x21
0x12b61: xor dh, dh
0x12b63: and dl, 0x3f
0x12b66: cmp dx, 0x69
0x12b69: nop
0x12b6a: jg 0x12b5d
0x12b6c: mov ah, 9
0x12b6e: add dx, dx
0x12b70: add dx, 0x364
0x12b74: mov si, dx
2018-12-17T22:05:31.994233415Z 64 PC: 139fc | Write file or device (Write 4006 bytes on handle 5)
2018-12-17T22:05:32.010404728Z 62 PC: 12b5d | Close file
2018-12-17T22:05:32.019036514Z 44 PC: 12b61 | Get time 0x12b61: xor dh, dh
0x12b63: and dl, 0x3f
0x12b66: cmp dx, 0x69
0x12b69: nop
0x12b6a: jg 0x12b5d
0x12b6c: mov ah, 9
0x12b6e: add dx, dx
0x12b70: add dx, 0x364
0x12b74: mov si, dx
0x12b76: mov dx, word ptr cs:[si]
0x12b79: int 0x21
0x12b7b: int 0x20
0x12b7d: mov ah, 0xf
0x12b7f: int 0x10
0x12b81: xor ah, ah
0x12b83: int 0x10
0x12b85: mov ah, 1
0x12b87: mov cx, 0x2607
0x12b8a: int 0x10
0x12b8c: mov ax, 0xb800
2018-12-17T22:05:32.021315715Z 9 PC: 12b7b | Display string (String= 'Batch file missing ')