Sample viewer

vx.netlux.org/Virus.DOS.VCL.RedTeam

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:12:19.930240192Z 47 PC: 12a66 | Get disk transfer address
2018-12-17T23:12:19.931359371Z 26 PC: 12a6e | Set disk transfer address
2018-12-17T23:12:19.97512081Z 37 PC: 12a83 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T23:12:19.97620286Z 37 PC: 12a87 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:12:19.977857272Z 71 PC: 12b22 | Get current directory
2018-12-17T23:12:19.981442252Z 59 PC: 12b2a | Change current directory
2018-12-17T23:12:19.985828087Z 47 PC: 12b3f | Get disk transfer address
2018-12-17T23:12:19.987284872Z 26 PC: 12b4d | Set disk transfer address
2018-12-17T23:12:19.989570936Z 78 PC: 12b58 | Find first file
2018-12-17T23:12:19.995750244Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:19.998517869Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.004091071Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.005999785Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.007749734Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.010491374Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.013177866Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.01512246Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.01726448Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.019441485Z 47 PC: 12ba9 | Get disk transfer address
2018-12-17T23:12:20.020446715Z 26 PC: 12bb8 | Set disk transfer address
2018-12-17T23:12:20.021411588Z 78 PC: 12bc0 | Find first file
2018-12-17T23:12:20.025904655Z 47 PC: 12bdd | Get disk transfer address
2018-12-17T23:12:20.026852804Z 61 PC: 12bf6 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:12:20.030852131Z 63 PC: 12c02 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:12:20.035242665Z 66 PC: 12c0a | Move file pointer
2018-12-17T23:12:20.040228453Z 62 PC: 12c0f | Close file
2018-12-17T23:12:20.041567828Z 67 PC: 12c2f | Get or set file attributes
2018-12-17T23:12:20.055351745Z 61 PC: 12c34 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:12:20.059773345Z 64 PC: 12c40 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:12:20.061639576Z 66 PC: 12c48 | Move file pointer
2018-12-17T23:12:20.063757898Z 64 PC: 12d23 | Write file or device (Write 716 bytes on handle 5)
2018-12-17T23:12:20.069378659Z 87 PC: 12c58 | Get or set file date and time
2018-12-17T23:12:20.070464382Z 62 PC: 12c5c | Close file
2018-12-17T23:12:20.075820285Z 67 PC: 12c69 | Get or set file attributes
2018-12-17T23:12:20.082153702Z 26 PC: 12bd2 | Set disk transfer address
2018-12-17T23:12:20.082945724Z 26 PC: 12b90 | Set disk transfer address
2018-12-17T23:12:20.084415353Z 59 PC: 12b34 | Change current directory
2018-12-17T23:12:20.085751378Z 71 PC: 12b22 | Get current directory
2018-12-17T23:12:20.087677093Z 59 PC: 12b2a | Change current directory
2018-12-17T23:12:20.090723425Z 47 PC: 12b3f | Get disk transfer address
2018-12-17T23:12:20.091941897Z 26 PC: 12b4d | Set disk transfer address
2018-12-17T23:12:20.092756721Z 78 PC: 12b58 | Find first file
2018-12-17T23:12:20.099496751Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.101596775Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.103268019Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.105118047Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.111449546Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.113102432Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.114727986Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.116939187Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.118650957Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.120215932Z 47 PC: 12ba9 | Get disk transfer address
2018-12-17T23:12:20.12158711Z 26 PC: 12bb8 | Set disk transfer address
2018-12-17T23:12:20.122393817Z 78 PC: 12bc0 | Find first file
2018-12-17T23:12:20.128814583Z 47 PC: 12bdd | Get disk transfer address
2018-12-17T23:12:20.130256646Z 61 PC: 12bf6 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:12:20.137449206Z 63 PC: 12c02 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:12:20.141464209Z 66 PC: 12c0a | Move file pointer
2018-12-17T23:12:20.143082432Z 62 PC: 12c0f | Close file
2018-12-17T23:12:20.144422751Z 79 PC: 12bc0 | Find next file
2018-12-17T23:12:20.146298399Z 47 PC: 12bdd | Get disk transfer address
2018-12-17T23:12:20.148257505Z 61 PC: 12bf6 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:12:20.154602201Z 63 PC: 12c02 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:12:20.160532791Z 66 PC: 12c0a | Move file pointer
2018-12-17T23:12:20.162385728Z 62 PC: 12c0f | Close file
2018-12-17T23:12:20.163944657Z 67 PC: 12c2f | Get or set file attributes
2018-12-17T23:12:20.273461315Z 61 PC: 12c34 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:12:20.280704754Z 64 PC: 12c40 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:12:20.283358127Z 66 PC: 12c48 | Move file pointer
2018-12-17T23:12:20.285545188Z 64 PC: 12d23 | Write file or device (Write 716 bytes on handle 5)
2018-12-17T23:12:20.415585989Z 87 PC: 12c58 | Get or set file date and time
2018-12-17T23:12:20.416976472Z 62 PC: 12c5c | Close file
2018-12-17T23:12:20.460411923Z 67 PC: 12c69 | Get or set file attributes
2018-12-17T23:12:20.470922841Z 26 PC: 12bd2 | Set disk transfer address
2018-12-17T23:12:20.472009857Z 26 PC: 12b90 | Set disk transfer address
2018-12-17T23:12:20.473194555Z 59 PC: 12b34 | Change current directory
2018-12-17T23:12:20.476091916Z 71 PC: 12b22 | Get current directory
2018-12-17T23:12:20.47891531Z 59 PC: 12b2a | Change current directory
2018-12-17T23:12:20.48272863Z 47 PC: 12b3f | Get disk transfer address
2018-12-17T23:12:20.484588303Z 26 PC: 12b4d | Set disk transfer address
2018-12-17T23:12:20.485741831Z 78 PC: 12b58 | Find first file
2018-12-17T23:12:20.491593042Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.494998189Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.498276353Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.501044998Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.504698469Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.507933803Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.510743617Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.514352836Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.516767917Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.519164493Z 47 PC: 12ba9 | Get disk transfer address
2018-12-17T23:12:20.52136413Z 26 PC: 12bb8 | Set disk transfer address
2018-12-17T23:12:20.522402365Z 78 PC: 12bc0 | Find first file
2018-12-17T23:12:20.533008983Z 47 PC: 12bdd | Get disk transfer address
2018-12-17T23:12:20.535533179Z 61 PC: 12bf6 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:12:20.541852784Z 63 PC: 12c02 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:12:20.547996878Z 66 PC: 12c0a | Move file pointer
2018-12-17T23:12:20.549930692Z 62 PC: 12c0f | Close file
2018-12-17T23:12:20.551634815Z 79 PC: 12bc0 | Find next file
2018-12-17T23:12:20.554318645Z 47 PC: 12bdd | Get disk transfer address
2018-12-17T23:12:20.556532112Z 61 PC: 12bf6 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:12:20.563103151Z 63 PC: 12c02 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:12:20.569533929Z 66 PC: 12c0a | Move file pointer
2018-12-17T23:12:20.57141535Z 62 PC: 12c0f | Close file
2018-12-17T23:12:20.574389517Z 79 PC: 12bc0 | Find next file
2018-12-17T23:12:20.577273728Z 47 PC: 12bdd | Get disk transfer address
2018-12-17T23:12:20.578674324Z 61 PC: 12bf6 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:12:20.586368575Z 63 PC: 12c02 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:12:20.592886109Z 66 PC: 12c0a | Move file pointer
2018-12-17T23:12:20.59456847Z 62 PC: 12c0f | Close file
2018-12-17T23:12:20.597349877Z 67 PC: 12c2f | Get or set file attributes
2018-12-17T23:12:20.607591713Z 61 PC: 12c34 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:12:20.614454557Z 64 PC: 12c40 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:12:20.617960094Z 66 PC: 12c48 | Move file pointer
2018-12-17T23:12:20.620316083Z 64 PC: 12d23 | Write file or device (Write 716 bytes on handle 5)
2018-12-17T23:12:20.628727338Z 87 PC: 12c58 | Get or set file date and time
2018-12-17T23:12:20.631163853Z 62 PC: 12c5c | Close file
2018-12-17T23:12:20.638825126Z 67 PC: 12c69 | Get or set file attributes
2018-12-17T23:12:20.649370244Z 26 PC: 12bd2 | Set disk transfer address
2018-12-17T23:12:20.651430428Z 26 PC: 12b90 | Set disk transfer address
2018-12-17T23:12:20.653036443Z 59 PC: 12b34 | Change current directory
2018-12-17T23:12:20.654801918Z 71 PC: 12b22 | Get current directory
2018-12-17T23:12:20.65999519Z 59 PC: 12b2a | Change current directory
2018-12-17T23:12:20.669071249Z 47 PC: 12b3f | Get disk transfer address
2018-12-17T23:12:20.670484981Z 26 PC: 12b4d | Set disk transfer address
2018-12-17T23:12:20.672632924Z 78 PC: 12b58 | Find first file
2018-12-17T23:12:20.682335385Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.685012075Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.688158627Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.691007647Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.693779973Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.696767215Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.700098644Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.70652438Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.709604952Z 79 PC: 12b80 | Find next file
2018-12-17T23:12:20.713159668Z 47 PC: 12ba9 | Get disk transfer address
2018-12-17T23:12:20.714622211Z 26 PC: 12bb8 | Set disk transfer address
2018-12-17T23:12:20.7160389Z 78 PC: 12bc0 | Find first file
2018-12-17T23:12:20.722714899Z 47 PC: 12bdd | Get disk transfer address
2018-12-17T23:12:20.724176217Z 61 PC: 12bf6 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:12:20.730915227Z 63 PC: 12c02 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:12:20.738652556Z 66 PC: 12c0a | Move file pointer
2018-12-17T23:12:20.740385369Z 62 PC: 12c0f | Close file
2018-12-17T23:12:20.742517987Z 79 PC: 12bc0 | Find next file
2018-12-17T23:12:20.747613202Z 47 PC: 12bdd | Get disk transfer address
2018-12-17T23:12:20.749322064Z 61 PC: 12bf6 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:12:20.7563271Z 63 PC: 12c02 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:12:20.776556477Z 66 PC: 12c0a | Move file pointer
2018-12-17T23:12:20.778376657Z 62 PC: 12c0f | Close file
2018-12-17T23:12:20.781184243Z 79 PC: 12bc0 | Find next file
2018-12-17T23:12:20.785468523Z 47 PC: 12bdd | Get disk transfer address
2018-12-17T23:12:20.786888665Z 61 PC: 12bf6 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:12:20.794494946Z 63 PC: 12c02 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:12:20.809339969Z 66 PC: 12c0a | Move file pointer
2018-12-17T23:12:20.812371534Z 62 PC: 12c0f | Close file
2018-12-17T23:12:20.814342773Z 79 PC: 12bc0 | Find next file
2018-12-17T23:12:20.817389263Z 47 PC: 12bdd | Get disk transfer address
2018-12-17T23:12:20.818375464Z 61 PC: 12bf6 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:12:20.824721386Z 63 PC: 12c02 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:12:20.831291981Z 66 PC: 12c0a | Move file pointer
2018-12-17T23:12:20.832625601Z 62 PC: 12c0f | Close file
2018-12-17T23:12:20.834338316Z 67 PC: 12c2f | Get or set file attributes
2018-12-17T23:12:20.844098061Z 61 PC: 12c34 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:12:20.850502087Z 64 PC: 12c40 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:12:20.853120732Z 66 PC: 12c48 | Move file pointer
2018-12-17T23:12:20.855872235Z 64 PC: 12d23 | Write file or device (Write 716 bytes on handle 5)
2018-12-17T23:12:20.863817036Z 87 PC: 12c58 | Get or set file date and time
2018-12-17T23:12:20.865166052Z 62 PC: 12c5c | Close file
2018-12-17T23:12:20.872756546Z 67 PC: 12c69 | Get or set file attributes
2018-12-17T23:12:20.882789575Z 26 PC: 12bd2 | Set disk transfer address
2018-12-17T23:12:20.883787787Z 26 PC: 12b90 | Set disk transfer address
2018-12-17T23:12:20.885813927Z 59 PC: 12b34 | Change current directory
2018-12-17T23:12:20.887735138Z 42 PC: 12c7f | Get date 0x12c7f: cwde
0x12c80: ret
0x12c81: dec si
0x12c82: outsw dx, word ptr [si]
0x12c83: ja 0x12ca5
0x12c85: pop cx
0x12c86: dec di
0x12c87: push bp
0x12c88: and byte ptr [bx + di + 0x72], ah
0x12c8b: and byte ptr gs:[bx + di + 0x20], ah
0x12c8f: jo 0x12cf2
0x12c91: jb 0x12d07
0x12c93: and byte ptr [bx + 0x66], ch
0x12c96: and byte ptr [si + 0x68], dh
0x12c99: and byte ptr gs:[bp + si + 0x65], dl
0x12c9d: and byte ptr fs:[si + 0x65], dl
0x12ca1: popaw
0x12ca2: insw word ptr es:[di], dx
0x12ca3: and word ptr [di], cx
0x12ca5: or ah, byte ptr [bp + si + 0x79]
2018-12-17T23:12:20.889976479Z 26 PC: 12afd | Set disk transfer address