Sample viewer

vx.netlux.org/Virus.DOS.Tie.710

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:27:25.04135267Z 61 PC: 141e5 | Open file (Filename = 'Í ÀŸ')
2018-12-17T22:27:25.047523397Z 44 PC: 1420a | Get time 0x1420a: mov byte ptr cs:[bp + 0x11], dl
0x1420e: mov di, bp
0x14210: add di, 6
0x14213: mov cx, 0xb
0x14216: xor byte ptr [di], dl
0x14218: inc di
0x14219: loop 0x14216
0x1421b: mov ah, 0x4a
0x1421d: mov bx, 0x1000
0x14220: int 0x21
0x14222: jae 0x14227
0x14224: jmp 0x1444a
0x14227: mov ah, 0x48
0x14229: mov bx, 0x2d
0x1422c: nop
0x1422d: int 0x21
0x1422f: jae 0x14234
0x14231: jmp 0x1444a
0x14234: push ax
0x14235: dec ax
2018-12-17T22:27:25.049906581Z 74 PC: 14222 | Reallocate memory
2018-12-17T22:27:25.058185849Z 72 PC: 1422f | Allocate memory
2018-12-17T22:27:25.061296606Z 9 PC: 12a86 | Display string (String= 'Goat file (COM/k...). Size=00001770h/0000006000d bytes. ')
2018-12-17T22:27:25.067355537Z 48 PC: 12a8f | Get DOS version
2018-12-17T22:27:25.068725092Z 67 PC: 22a9c | Get or set file attributes
2018-12-17T22:27:25.085724242Z 61 PC: 22aa5 | Open file (Filename = 'A:\TEST.COM')
2018-12-17T22:27:25.09798393Z 87 PC: 22ab1 | Get or set file date and time
2018-12-17T22:27:25.100127793Z 63 PC: 22acb | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:27:25.106867319Z 66 PC: 22af8 | Move file pointer
2018-12-17T22:27:25.108856905Z 63 PC: 22b06 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:27:25.117533396Z 63 PC: 22b14 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:27:25.120550936Z 66 PC: 22b54 | Move file pointer
2018-12-17T22:27:25.124331203Z 64 PC: 22b95 | Write file or device (Write 710 bytes on handle 5)
2018-12-17T22:27:25.133333869Z 66 PC: 22ba3 | Move file pointer
2018-12-17T22:27:25.135577704Z 64 PC: 22bb1 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:27:25.139337416Z 87 PC: 22bc5 | Get or set file date and time
2018-12-17T22:27:25.141292624Z 62 PC: 22bcd | Close file
2018-12-17T22:27:25.148872312Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-17T22:27:25.171127926Z 93 PC: 12afe | File sharing functions
2018-12-17T22:27:25.177782294Z 9 PC: 12a86 | Display string (String= 'Size change=058Ch/01420d. ')
2018-12-17T22:27:25.183273982Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')