Sample viewer

vx.netlux.org/Virus.DOS.Champaigne.446

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:25:01.128899179Z 42 PC: 140f8 | Get date 0x140f8: mov byte ptr ds:[bp + 0x273], dl
0x140fd: mov byte ptr ds:[bp + 0x272], dh
0x14102: mov byte ptr ds:[bp + 0x271], al
0x14107: cmp al, 0
0x14109: je 0x14115
0x1410b: mov di, 0x100
0x1410e: lea si, word ptr [bp + 0x27e]
0x14112: push di
0x14113: movsw word ptr es:[di], word ptr [si]
0x14114: movsw word ptr es:[di], word ptr [si]
0x14115: lea dx, word ptr [bp + 0x2c2]
0x14119: call 0x14219
0x1411c: jmp 0x14204
0x1411f: cmp byte ptr ds:[bp + 0x273], 0x1b
0x14125: jne 0x14132
0x14127: call 0x14159
0x1412a: cmp byte ptr ds:[bp + 0x272], 6
0x14130: je 0x14150
0x14132: mov dx, 0x80
0x14135: call 0x14219
2018-12-17T22:25:01.131734187Z 26 PC: 1421d | Set disk transfer address
2018-12-17T22:25:01.132701985Z 78 PC: 1420f | Find first file
2018-12-17T22:25:01.138461666Z 61 PC: 14176 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:25:01.146007691Z 87 PC: 1417c | Get or set file date and time
2018-12-17T22:25:01.147036974Z 63 PC: 14189 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:25:01.150948271Z 66 PC: 14223 | Move file pointer
2018-12-17T22:25:01.152455562Z 66 PC: 14223 | Move file pointer
2018-12-17T22:25:01.153447792Z 64 PC: 1424b | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:25:01.155086573Z 66 PC: 14223 | Move file pointer
2018-12-17T22:25:01.156601348Z 44 PC: 141ba | Get time 0x141ba: mov word ptr ds:[bp + 0x2ad], dx
0x141bf: mov cx, 0x12
0x141c2: lea di, word ptr [bp + 0x2c3]
0x141c6: lea si, word ptr [bp + 0x2af]
0x141ca: push cx
0x141cb: push si
0x141cc: rep movsb byte ptr es:[di], byte ptr [si]
0x141ce: cmp byte ptr ds:[bp + 0x271], 0
0x141d4: jne 0x141e2
0x141d6: mov cx, 0xb
0x141d9: lea si, word ptr [bp + 0x2a2]
0x141dd: rep movsb byte ptr es:[di], byte ptr [si]
0x141df: jmp 0x141eb
0x141e1: nop
0x141e2: mov cx, 0xb
0x141e5: lea si, word ptr [bp + 0x164]
0x141e9: rep movsb byte ptr es:[di], byte ptr [si]
0x141eb: pop si
0x141ec: pop cx
0x141ed: rep movsb byte ptr es:[di], byte ptr [si]
2018-12-17T22:25:01.158138796Z 64 PC: 142c1 | Write file or device (Write 446 bytes on handle 5)
2018-12-17T22:25:01.170118272Z 87 PC: 141fc | Get or set file date and time
2018-12-17T22:25:01.171613528Z 62 PC: 14200 | Close file
2018-12-17T22:25:01.17683052Z 79 PC: 1420f | Find next file
2018-12-17T22:25:01.178223567Z 81 PC: 122cc | Get current PSP
2018-12-17T22:25:01.179310779Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:25:01.181298223Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T22:25:01.184745565Z 2 PC: 1268d | Character output (Char = '46')
2018-12-17T22:25:01.187009464Z 2 PC: 1268d | Character output (Char = '69')
2018-12-17T22:25:01.189375975Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:25:01.190829658Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:25:01.192350438Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:25:01.194647683Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:25:01.196609788Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:25:01.198858554Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:25:01.200744187Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:25:01.202504759Z 2 PC: 1268d | Character output (Char = '63')
2018-12-17T22:25:01.204667802Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:25:01.209908528Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:25:01.212340388Z 2 PC: 1268d | Character output (Char = '69')
2018-12-17T22:25:01.214745069Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:25:01.217917209Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:25:01.220251361Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:25:01.22253165Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:25:01.225482689Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:25:01.227420499Z 2 PC: 1268d | Character output (Char = '62')
2018-12-17T22:25:01.229247974Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:25:01.233689563Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:25:01.243318144Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:25:01.245535051Z 2 PC: 1268d | Character output (Char = '62')
2018-12-17T22:25:01.248482667Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:25:01.250823294Z 2 PC: 1268d | Character output (Char = '64')
2018-12-17T22:25:01.253102266Z 2 PC: 1268d | Character output (Char = '2c')
2018-12-17T22:25:01.257966174Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:25:01.259958924Z 2 PC: 1268d | Character output (Char = '64')
2018-12-17T22:25:01.261920292Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:25:01.264344779Z 2 PC: 1268d | Character output (Char = '69')
2018-12-17T22:25:01.266600513Z 2 PC: 1268d | Character output (Char = '76')
2018-12-17T22:25:01.268633841Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:25:01.271285204Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:25:01.273569781Z 2 PC: 126ce | Character output (Char = '41')
2018-12-17T22:25:01.275622328Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:25:01.278258672Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T22:25:01.281706593Z 81 PC: 122f4 | Get current PSP