Sample viewer

vx.netlux.org/Virus.DOS.Livio.818

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:53:53.367132689Z 42 PC: 12bb0 | Get date 0x12bb0: mov byte ptr [0x26a], dh
0x12bb4: mov byte ptr [0x26b], dl
0x12bb8: mov ah, 0x2c
0x12bba: int 0x21
0x12bbc: cmp byte ptr [0x106], 0
0x12bc1: je 0x12bc8
0x12bc3: cmp dh, 0xf
0x12bc6: jg 0x12bd5
0x12bc8: cmp dl, 0
0x12bcb: je 0x12bac
0x12bcd: mov byte ptr [0x106], dl
0x12bd1: mov byte ptr [0x107], dh
0x12bd5: mov byte ptr [0x25f], 0
0x12bda: mov byte ptr [0x260], 4
0x12bdf: mov byte ptr [0x269], 0
0x12be4: mov cx, 0x27
0x12be7: mov dx, 0x14d
0x12bea: mov ah, 0x4e
0x12bec: int 0x21
0x12bee: cmp ax, 0x12
2018-12-17T21:53:53.369555294Z 44 PC: 12bbc | Get time 0x12bbc: cmp byte ptr [0x106], 0
0x12bc1: je 0x12bc8
0x12bc3: cmp dh, 0xf
0x12bc6: jg 0x12bd5
0x12bc8: cmp dl, 0
0x12bcb: je 0x12bac
0x12bcd: mov byte ptr [0x106], dl
0x12bd1: mov byte ptr [0x107], dh
0x12bd5: mov byte ptr [0x25f], 0
0x12bda: mov byte ptr [0x260], 4
0x12bdf: mov byte ptr [0x269], 0
0x12be4: mov cx, 0x27
0x12be7: mov dx, 0x14d
0x12bea: mov ah, 0x4e
0x12bec: int 0x21
0x12bee: cmp ax, 0x12
0x12bf1: je 0x12bf6
0x12bf3: call 0x12c18
0x12bf6: mov cx, 0x27
0x12bf9: mov dx, 0x153
2018-12-17T21:53:53.371511247Z 78 PC: 12bee | Find first file
2018-12-17T21:53:53.376368353Z 78 PC: 12c00 | Find first file
2018-12-17T21:53:53.381398163Z 67 PC: 12c69 | Get or set file attributes
2018-12-17T21:53:53.397322196Z 61 PC: 12c6f | Open file (Filename = 'SLEEP.COM')
2018-12-17T21:53:53.406667646Z 63 PC: 12c7e | Read file or device (Read 20 bytes on handle 5)
2018-12-17T21:53:53.411712249Z 62 PC: 12cdc | Close file
2018-12-17T21:53:53.413993348Z 61 PC: 12ce5 | Open file (Filename = 'SLEEP.COM')
2018-12-17T21:53:53.419472013Z 64 PC: 12a5b | Write file or device (Write 818 bytes on handle 5)
2018-12-17T21:53:53.426327452Z 87 PC: 12d0d | Get or set file date and time
2018-12-17T21:53:53.430082239Z 62 PC: 12d15 | Close file
2018-12-17T21:53:53.438250201Z 67 PC: 12d22 | Get or set file attributes
2018-12-17T21:53:53.442945826Z 79 PC: 12ca9 | Find next file
2018-12-17T21:53:53.446677396Z 67 PC: 12c69 | Get or set file attributes
2018-12-17T21:53:53.457074805Z 61 PC: 12c6f | Open file (Filename = 'PRINT.COM')
2018-12-17T21:53:53.468907283Z 63 PC: 12c7e | Read file or device (Read 20 bytes on handle 5)
2018-12-17T21:53:53.476648425Z 62 PC: 12cdc | Close file
2018-12-17T21:53:53.479259544Z 61 PC: 12ce5 | Open file (Filename = 'PRINT.COM')
2018-12-17T21:53:53.486955822Z 64 PC: 12a5b | Write file or device (Write 818 bytes on handle 5)
2018-12-17T21:53:53.496607676Z 87 PC: 12d0d | Get or set file date and time
2018-12-17T21:53:53.499754796Z 62 PC: 12d15 | Close file
2018-12-17T21:53:53.507455458Z 67 PC: 12d22 | Get or set file attributes
2018-12-17T21:53:53.513691985Z 79 PC: 12ca9 | Find next file
2018-12-17T21:53:53.517190057Z 67 PC: 12c69 | Get or set file attributes
2018-12-17T21:53:53.526749206Z 61 PC: 12c6f | Open file (Filename = 'HELLO.COM')
2018-12-17T21:53:53.539956231Z 63 PC: 12c7e | Read file or device (Read 20 bytes on handle 5)
2018-12-17T21:53:53.546546786Z 62 PC: 12cdc | Close file
2018-12-17T21:53:53.548586312Z 61 PC: 12ce5 | Open file (Filename = 'HELLO.COM')
2018-12-17T21:53:53.555930784Z 64 PC: 12a5b | Write file or device (Write 818 bytes on handle 5)
2018-12-17T21:53:53.570462092Z 87 PC: 12d0d | Get or set file date and time
2018-12-17T21:53:53.572125159Z 62 PC: 12d15 | Close file
2018-12-17T21:53:53.580201614Z 67 PC: 12d22 | Get or set file attributes
2018-12-17T21:53:53.592088779Z 79 PC: 12ca9 | Find next file
2018-12-17T21:53:53.594737603Z 67 PC: 12c69 | Get or set file attributes
2018-12-17T21:53:53.604655153Z 61 PC: 12c6f | Open file (Filename = 'PHANG.COM')
2018-12-17T21:53:53.618204327Z 63 PC: 12c7e | Read file or device (Read 20 bytes on handle 5)
2018-12-17T21:53:53.624736871Z 62 PC: 12cdc | Close file
2018-12-17T21:53:53.626661885Z 61 PC: 12ce5 | Open file (Filename = 'PHANG.COM')
2018-12-17T21:53:53.634489052Z 64 PC: 12a5b | Write file or device (Write 818 bytes on handle 5)
2018-12-17T21:53:53.642812646Z 87 PC: 12d0d | Get or set file date and time
2018-12-17T21:53:53.644368713Z 62 PC: 12d15 | Close file
2018-12-17T21:53:53.652385662Z 67 PC: 12d22 | Get or set file attributes
2018-12-17T21:53:53.657223204Z 9 PC: 12d66 | Display string (String= ' Pack file corrupted')
2018-12-17T21:53:53.661256832Z 76 PC: 12d6a | Terminate with return code (Return code = '36')