Sample viewer

vx.netlux.org/Virus.DOS.T_Power.Sodo.4600

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:52:41.718692998Z 74 PC: 12b37 | Reallocate memory
2018-12-17T21:52:41.721738665Z 53 PC: 1317a | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T21:52:41.723281005Z 53 PC: 1317a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:52:41.724928652Z 74 PC: 12bc4 | Reallocate memory
2018-12-17T21:52:41.726917805Z 88 PC: 12bcc | case 0xGet or set allocation strateg:
2018-12-17T21:52:41.728884159Z 88 PC: 12bd5 | case 0xGet or set allocation strateg:
2018-12-17T21:52:41.730101616Z 72 PC: 12be0 | Allocate memory
2018-12-17T21:52:41.73189677Z 88 PC: 12bf9 | case 0xGet or set allocation strateg:
2018-12-17T21:52:41.738187989Z 42 PC: 12c17 | Get date 0x12c17: test dh, 1
0x12c1a: jne 0x12c25
0x12c1c: test al, 1
0x12c1e: je 0x12c25
0x12c20: or byte ptr [bp + 0x129f], 0x80
0x12c25: push cs
0x12c26: pop ds
0x12c27: pop ax
0x12c28: push ax
0x12c29: mov si, bp
0x12c2b: mov es, ax
0x12c2d: xor di, di
0x12c2f: mov cx, 0x1397
0x12c32: rep movsb byte ptr es:[di], byte ptr [si]
0x12c34: mov al, 0x1c
0x12c36: call 0x13176
0x12c39: pop ds
0x12c3a: mov word ptr [0x7a1], bx
0x12c3e: mov word ptr [0x7a3], es
0x12c42: mov word ptr [0x572], 0x9e5
2018-12-17T21:52:41.740994686Z 53 PC: 1317a | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T21:52:41.742885571Z 37 PC: 1317f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:52:41.745457482Z 37 PC: 1317f | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T21:52:41.747138579Z 37 PC: 1317f | Set interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T21:52:41.748831254Z 37 PC: 1317f | Set interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-17T21:52:41.751513791Z 74 PC: 12c78 | Reallocate memory
2018-12-17T21:52:41.753545304Z 88 PC: 12c84 | case 0xGet or set allocation strateg:
2018-12-17T21:52:41.755623811Z 88 PC: 14044 | case 0xGet or set allocation strateg:
2018-12-17T21:52:41.76315623Z 47 PC: 14066 | Get disk transfer address
2018-12-17T21:52:41.765879942Z 26 PC: 14075 | Set disk transfer address
2018-12-17T21:52:41.78308719Z 71 PC: 1407e | Get current directory
2018-12-17T21:52:41.787481731Z 53 PC: 1470a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:52:41.788869364Z 37 PC: 1453f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:52:41.790137444Z 59 PC: 14544 | Change current directory
2018-12-17T21:52:41.792761849Z 67 PC: 1454d | Get or set file attributes
2018-12-17T21:52:42.134643693Z 61 PC: 14106 | Open file (Filename = '')
2018-12-17T21:52:42.141480215Z 87 PC: 1416c | Get or set file date and time
2018-12-17T21:52:42.144153158Z 63 PC: 1417f | Read file or device (Read 24 bytes on handle 5)
2018-12-17T21:52:42.147956219Z 66 PC: 14528 | Move file pointer
2018-12-17T21:52:42.156395008Z 64 PC: 15057 | Write file or device (Write 4600 bytes on handle 5)
2018-12-17T21:52:42.167736891Z 66 PC: 14528 | Move file pointer
2018-12-17T21:52:42.170061546Z 64 PC: 14535 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:52:42.173452254Z 87 PC: 142b3 | Get or set file date and time
2018-12-17T21:52:42.175638926Z 87 PC: 142be | Get or set file date and time
2018-12-17T21:52:42.179192853Z 62 PC: 142c6 | Close file
2018-12-17T21:52:42.18640359Z 78 PC: 142e0 | Find first file
2018-12-17T21:52:42.192761776Z 78 PC: 142e0 | Find first file
2018-12-17T21:52:42.199178454Z 78 PC: 142e0 | Find first file
2018-12-17T21:52:42.204025512Z 78 PC: 142e0 | Find first file
2018-12-17T21:52:42.209194149Z 78 PC: 142e0 | Find first file
2018-12-17T21:52:42.215497843Z 78 PC: 142e0 | Find first file
2018-12-17T21:52:42.220834659Z 78 PC: 142e0 | Find first file
2018-12-17T21:52:42.227208009Z 78 PC: 142e0 | Find first file
2018-12-17T21:52:42.234469568Z 78 PC: 142e0 | Find first file
2018-12-17T21:52:42.240316293Z 78 PC: 142e0 | Find first file
2018-12-17T21:52:42.246865526Z 59 PC: 14544 | Change current directory
2018-12-17T21:52:42.251731349Z 59 PC: 14544 | Change current directory
2018-12-17T21:52:42.254156424Z 37 PC: 1453f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:52:42.255463134Z 26 PC: 1431c | Set disk transfer address
2018-12-17T21:52:42.257388236Z 61 PC: 1470a | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T21:52:42.264795056Z 62 PC: 1470a | Close file
2018-12-17T21:52:42.267065915Z 0 PC: 12942 | Program terminate