Sample viewer

vx.netlux.org/Virus.DOS.Champaigne.445

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:19:50.065464459Z 42 PC: 12e3b | Get date 0x12e3b: mov byte ptr ds:[bp + 0x272], dl
0x12e40: mov byte ptr ds:[bp + 0x271], dh
0x12e45: mov byte ptr ds:[bp + 0x270], al
0x12e4a: cmp al, 0
0x12e4c: je 0x12e58
0x12e4e: mov di, 0x100
0x12e51: lea si, word ptr [bp + 0x27d]
0x12e55: push di
0x12e56: movsw word ptr es:[di], word ptr [si]
0x12e57: movsw word ptr es:[di], word ptr [si]
0x12e58: lea dx, word ptr [bp + 0x2c1]
0x12e5c: call 0x12f5b
0x12e5f: jmp 0x12f46
0x12e62: cmp byte ptr ds:[bp + 0x272], 0x1b
0x12e68: jne 0x12e75
0x12e6a: call 0x12e9c
0x12e6d: cmp byte ptr ds:[bp + 0x271], 6
0x12e73: je 0x12e93
0x12e75: mov dx, 0x80
0x12e78: call 0x12f5b
2018-12-17T22:19:50.068088465Z 26 PC: 12f5f | Set disk transfer address
2018-12-17T22:19:50.070076828Z 78 PC: 12f51 | Find first file
2018-12-17T22:19:50.076770348Z 61 PC: 12eb9 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:19:50.084753246Z 87 PC: 12ebf | Get or set file date and time
2018-12-17T22:19:50.087331814Z 63 PC: 12ecc | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:19:50.094378574Z 66 PC: 12f65 | Move file pointer
2018-12-17T22:19:50.096199034Z 66 PC: 12f65 | Move file pointer
2018-12-17T22:19:50.099010247Z 64 PC: 12f8d | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:19:50.102088554Z 66 PC: 12f65 | Move file pointer
2018-12-17T22:19:50.103906843Z 44 PC: 12efd | Get time 0x12efd: mov word ptr ds:[bp + 0x2ac], dx
0x12f02: mov cx, 0x12
0x12f05: lea di, word ptr [bp + 0x2c2]
0x12f09: lea si, word ptr [bp + 0x2ae]
0x12f0d: push cx
0x12f0e: push si
0x12f0f: rep movsb byte ptr es:[di], byte ptr [si]
0x12f11: cmp byte ptr ds:[bp + 0x270], 0
0x12f17: jne 0x12f24
0x12f19: mov cx, 0xb
0x12f1c: lea si, word ptr [bp + 0x2a1]
0x12f20: rep movsb byte ptr es:[di], byte ptr [si]
0x12f22: jmp 0x12f2d
0x12f24: mov cx, 0xb
0x12f27: lea si, word ptr [bp + 0x164]
0x12f2b: rep movsb byte ptr es:[di], byte ptr [si]
0x12f2d: pop si
0x12f2e: pop cx
0x12f2f: rep movsb byte ptr es:[di], byte ptr [si]
0x12f31: mov al, 0xc3
2018-12-17T22:19:50.107105929Z 64 PC: 13003 | Write file or device (Write 445 bytes on handle 5)
2018-12-17T22:19:50.12284691Z 87 PC: 12f3e | Get or set file date and time
2018-12-17T22:19:50.124598659Z 62 PC: 12f42 | Close file
2018-12-17T22:19:50.133214579Z 79 PC: 12f51 | Find next file
2018-12-17T22:19:50.136723809Z 81 PC: 122cc | Get current PSP
2018-12-17T22:19:50.138282856Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:19:50.140887651Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T22:19:50.146364232Z 2 PC: 1268d | Character output (Char = '46')
2018-12-17T22:19:50.149040814Z 2 PC: 1268d | Character output (Char = '69')
2018-12-17T22:19:50.151698282Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:19:50.166111781Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:19:50.168705934Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:19:50.171617554Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:19:50.174532583Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:19:50.181226834Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:19:50.183818246Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:19:50.186388163Z 2 PC: 1268d | Character output (Char = '63')
2018-12-17T22:19:50.19027318Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:19:50.192534779Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:19:50.194989813Z 2 PC: 1268d | Character output (Char = '69')
2018-12-17T22:19:50.198182379Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:19:50.200677805Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:19:50.203247363Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:19:50.206558284Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:19:50.209379187Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:19:50.211960914Z 2 PC: 1268d | Character output (Char = '62')
2018-12-17T22:19:50.215220511Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:19:50.217892996Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:19:50.220525102Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:19:50.224133672Z 2 PC: 1268d | Character output (Char = '62')
2018-12-17T22:19:50.226878916Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:19:50.229517319Z 2 PC: 1268d | Character output (Char = '64')
2018-12-17T22:19:50.232390806Z 2 PC: 1268d | Character output (Char = '2c')
2018-12-17T22:19:50.235559563Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:19:50.238421429Z 2 PC: 1268d | Character output (Char = '64')
2018-12-17T22:19:50.240999558Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:19:50.244236209Z 2 PC: 1268d | Character output (Char = '69')
2018-12-17T22:19:50.246628817Z 2 PC: 1268d | Character output (Char = '76')
2018-12-17T22:19:50.249075362Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:19:50.25200287Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:19:50.254802229Z 2 PC: 126ce | Character output (Char = '41')
2018-12-17T22:19:50.257547928Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:19:50.261566065Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T22:19:50.267495537Z 81 PC: 122f4 | Get current PSP