Sample viewer

vx.netlux.org/Virus.DOS.PS-MPC.570.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:20:28.94360461Z 26 PC: 1469c | Set disk transfer address
2018-12-17T22:20:28.945968923Z 78 PC: 14701 | Find first file
2018-12-17T22:20:28.951900177Z 78 PC: 14701 | Find first file
2018-12-17T22:20:28.957888116Z 67 PC: 14860 | Get or set file attributes
2018-12-17T22:20:28.976362654Z 61 PC: 1470d | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:20:28.989405002Z 63 PC: 14719 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:20:28.995863738Z 66 PC: 14721 | Move file pointer
2018-12-17T22:20:28.997544022Z 44 PC: 14806 | Get time 0x14806: mov word ptr [bp + 0x118], dx
0x1480a: lea di, word ptr [bp + 0x33d]
0x1480e: mov al, 0x53
0x14810: stosb byte ptr es:[di], al
0x14811: lea si, word ptr [bp + 0x103]
0x14815: mov cx, 0x24
0x14818: push si
0x14819: push cx
0x1481a: rep movsb byte ptr es:[di], byte ptr [si]
0x1481c: lea si, word ptr [bp + 0x324]
0x14820: mov cx, 0xd
0x14823: rep movsb byte ptr es:[di], byte ptr [si]
0x14825: pop cx
0x14826: pop si
0x14827: pop ax
0x14828: push di
0x14829: push si
0x1482a: push cx
0x1482b: rep movsb byte ptr es:[di], byte ptr [si]
0x1482d: mov word ptr [bp + 0x104], ax
2018-12-17T22:20:29.005552729Z 64 PC: 148ab | Write file or device (Write 570 bytes on handle 5)
2018-12-17T22:20:29.014407412Z 66 PC: 14847 | Move file pointer
2018-12-17T22:20:29.016108128Z 64 PC: 14850 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:20:29.024849737Z 87 PC: 14756 | Get or set file date and time
2018-12-17T22:20:29.02669703Z 62 PC: 1475a | Close file
2018-12-17T22:20:29.034705099Z 67 PC: 14860 | Get or set file attributes
2018-12-17T22:20:29.046073363Z 79 PC: 14701 | Find next file
2018-12-17T22:20:29.049028693Z 67 PC: 14860 | Get or set file attributes
2018-12-17T22:20:29.059114122Z 61 PC: 1470d | Open file (Filename = 'PRINT.COM')
2018-12-17T22:20:29.073814703Z 63 PC: 14719 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:20:29.080385349Z 66 PC: 14721 | Move file pointer
2018-12-17T22:20:29.08174767Z 44 PC: 14806 | Get time 0x14806: mov word ptr [bp + 0x118], dx
0x1480a: lea di, word ptr [bp + 0x33d]
0x1480e: mov al, 0x53
0x14810: stosb byte ptr es:[di], al
0x14811: lea si, word ptr [bp + 0x103]
0x14815: mov cx, 0x24
0x14818: push si
0x14819: push cx
0x1481a: rep movsb byte ptr es:[di], byte ptr [si]
0x1481c: lea si, word ptr [bp + 0x324]
0x14820: mov cx, 0xd
0x14823: rep movsb byte ptr es:[di], byte ptr [si]
0x14825: pop cx
0x14826: pop si
0x14827: pop ax
0x14828: push di
0x14829: push si
0x1482a: push cx
0x1482b: rep movsb byte ptr es:[di], byte ptr [si]
0x1482d: mov word ptr [bp + 0x104], ax
2018-12-17T22:20:29.084310013Z 64 PC: 148ab | Write file or device (Write 570 bytes on handle 5)
2018-12-17T22:20:29.092750569Z 66 PC: 14847 | Move file pointer
2018-12-17T22:20:29.093968796Z 64 PC: 14850 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:20:29.100549896Z 87 PC: 14756 | Get or set file date and time
2018-12-17T22:20:29.102467446Z 62 PC: 1475a | Close file
2018-12-17T22:20:29.110053341Z 67 PC: 14860 | Get or set file attributes
2018-12-17T22:20:29.120473502Z 79 PC: 14701 | Find next file
2018-12-17T22:20:29.133545825Z 67 PC: 14860 | Get or set file attributes
2018-12-17T22:20:29.14354908Z 61 PC: 1470d | Open file (Filename = 'HELLO.COM')
2018-12-17T22:20:29.150189879Z 63 PC: 14719 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:20:29.15684102Z 66 PC: 14721 | Move file pointer
2018-12-17T22:20:29.158553517Z 44 PC: 14806 | Get time 0x14806: mov word ptr [bp + 0x118], dx
0x1480a: lea di, word ptr [bp + 0x33d]
0x1480e: mov al, 0x53
0x14810: stosb byte ptr es:[di], al
0x14811: lea si, word ptr [bp + 0x103]
0x14815: mov cx, 0x24
0x14818: push si
0x14819: push cx
0x1481a: rep movsb byte ptr es:[di], byte ptr [si]
0x1481c: lea si, word ptr [bp + 0x324]
0x14820: mov cx, 0xd
0x14823: rep movsb byte ptr es:[di], byte ptr [si]
0x14825: pop cx
0x14826: pop si
0x14827: pop ax
0x14828: push di
0x14829: push si
0x1482a: push cx
0x1482b: rep movsb byte ptr es:[di], byte ptr [si]
0x1482d: mov word ptr [bp + 0x104], ax
2018-12-17T22:20:29.162006805Z 64 PC: 148ab | Write file or device (Write 570 bytes on handle 5)
2018-12-17T22:20:29.170992743Z 66 PC: 14847 | Move file pointer
2018-12-17T22:20:29.172349936Z 64 PC: 14850 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:20:29.178726227Z 87 PC: 14756 | Get or set file date and time
2018-12-17T22:20:29.181072728Z 62 PC: 1475a | Close file
2018-12-17T22:20:29.18893392Z 67 PC: 14860 | Get or set file attributes
2018-12-17T22:20:29.26433142Z 26 PC: 146b7 | Set disk transfer address
2018-12-17T22:20:29.441075874Z 76 PC: 13e98 | Terminate with return code (Return code = '0')