Sample viewer

vx.netlux.org/Virus.DOS.Grog.1603

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:19:27.033438849Z 53 PC: 12a46 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:19:27.035291095Z 37 PC: 12a50 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:19:27.036961905Z 26 PC: 12f56 | Set disk transfer address
2018-12-17T22:19:27.038713786Z 78 PC: 12f56 | Find first file
2018-12-17T22:19:27.04774849Z 61 PC: 12f56 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:19:27.0570847Z 63 PC: 12f56 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:19:27.064638385Z 66 PC: 12f56 | Move file pointer
2018-12-17T22:19:27.066728861Z 87 PC: 12f56 | Get or set file date and time
2018-12-17T22:19:27.069627143Z 62 PC: 12f56 | Close file
2018-12-17T22:19:27.072090432Z 79 PC: 12f56 | Find next file
2018-12-17T22:19:27.07714748Z 61 PC: 12f56 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:19:27.0852767Z 63 PC: 12f56 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:19:27.092503142Z 66 PC: 12f56 | Move file pointer
2018-12-17T22:19:27.094244145Z 87 PC: 12f56 | Get or set file date and time
2018-12-17T22:19:27.111605742Z 62 PC: 12f56 | Close file
2018-12-17T22:19:27.114481667Z 79 PC: 12f56 | Find next file
2018-12-17T22:19:27.119007667Z 61 PC: 12f56 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:19:27.130142114Z 63 PC: 12f56 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:19:27.137117813Z 66 PC: 12f56 | Move file pointer
2018-12-17T22:19:27.13910572Z 87 PC: 12f56 | Get or set file date and time
2018-12-17T22:19:27.141902684Z 62 PC: 12f56 | Close file
2018-12-17T22:19:27.144359068Z 79 PC: 12f56 | Find next file
2018-12-17T22:19:27.149320071Z 61 PC: 12f56 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:19:27.157268307Z 63 PC: 12f56 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:19:27.165031433Z 66 PC: 12f56 | Move file pointer
2018-12-17T22:19:27.167862933Z 87 PC: 12f56 | Get or set file date and time
2018-12-17T22:19:27.170112429Z 62 PC: 12f56 | Close file
2018-12-17T22:19:27.173168553Z 79 PC: 12f56 | Find next file
2018-12-17T22:19:27.177788892Z 61 PC: 12f56 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:19:27.185108983Z 63 PC: 12f56 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:19:27.193383963Z 66 PC: 12f56 | Move file pointer
2018-12-17T22:19:27.195396346Z 87 PC: 12f56 | Get or set file date and time
2018-12-17T22:19:27.197357486Z 62 PC: 12f56 | Close file
2018-12-17T22:19:27.210415964Z 79 PC: 12f56 | Find next file
2018-12-17T22:19:27.216428173Z 61 PC: 12f56 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:19:27.224545042Z 63 PC: 12f56 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:19:27.233215179Z 66 PC: 12f56 | Move file pointer
2018-12-17T22:19:27.235894041Z 87 PC: 12f56 | Get or set file date and time
2018-12-17T22:19:27.238133501Z 62 PC: 12f56 | Close file
2018-12-17T22:19:27.241231639Z 79 PC: 12f56 | Find next file
2018-12-17T22:19:27.246762848Z 61 PC: 12f56 | Open file (Filename = 'PAH.COM')
2018-12-17T22:19:27.255303632Z 63 PC: 12f56 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:19:27.262640107Z 66 PC: 12f56 | Move file pointer
2018-12-17T22:19:27.264880018Z 87 PC: 12f56 | Get or set file date and time
2018-12-17T22:19:27.266702457Z 62 PC: 12f56 | Close file
2018-12-17T22:19:27.268900941Z 79 PC: 12f56 | Find next file
2018-12-17T22:19:27.278175928Z 61 PC: 12f56 | Open file (Filename = 'TEST.COM')
2018-12-17T22:19:27.285929867Z 63 PC: 12f56 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:19:27.289433526Z 66 PC: 12f56 | Move file pointer
2018-12-17T22:19:27.292405364Z 87 PC: 12f56 | Get or set file date and time
2018-12-17T22:19:27.294543022Z 62 PC: 12f56 | Close file
2018-12-17T22:19:27.297283217Z 79 PC: 12f56 | Find next file
2018-12-17T22:19:27.301313711Z 42 PC: 12f56 | Get date 0x12f56: push ax
0x12f57: pushf
0x12f58: pop ax
0x12f59: or ah, 1
0x12f5c: mov word ptr [bp + 4], ax
0x12f5f: inc word ptr [bp]
0x12f62: pop ax
0x12f63: jmp 0x12f2a
0x12f65: cmp ax, 0x20cd
0x12f68: jne 0x12f71
0x12f6a: add word ptr [bp], 2
0x12f6e: pop ax
0x12f6f: jmp 0x12f2a
0x12f71: cmp al, 0x62
0x12f73: jne 0x12f79
0x12f75: push cs
0x12f76: pop ds
0x12f77: jmp 0x12f5f
0x12f79: cmp al, 0x63
0x12f7b: jne 0x12f81
2018-12-17T22:19:27.304097772Z 26 PC: 12f56 | Set disk transfer address
2018-12-17T22:19:27.305774339Z 67 PC: 12f56 | Get or set file attributes
2018-12-17T22:19:27.318562612Z 61 PC: 12f56 | Open file (Filename = 'A:\CC.EXE')
2018-12-17T22:19:27.327245615Z 37 PC: 12f46 | Set interrupt vector (Interrupt = '1' AKA 'Character input')