Sample viewer

vx.netlux.org/Virus.DOS.Gobot.2097

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:29:05.50448866Z 53 PC: 12a56 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:05.506282006Z 37 PC: 12a66 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:05.507614838Z 78 PC: 12a75 | Find first file
2018-12-17T22:29:05.515649267Z 61 PC: 12a7f | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:29:05.524634357Z 63 PC: 12a8a | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:29:05.531745619Z 44 PC: 12ade | Get time 0x12ade: xor dh, dh
0x12ae0: and dl, 7
0x12ae3: cmp dx, 6
0x12ae6: jg 0x12ada
0x12ae8: push dx
0x12ae9: add dx, 0x72d
0x12aed: mov si, dx
0x12aef: mov dl, byte ptr cs:[si]
0x12af2: mov byte ptr [0x103], dl
0x12af6: pop dx
0x12af7: push dx
0x12af8: add dx, 0x742
0x12afc: mov si, dx
0x12afe: mov dl, byte ptr cs:[si]
0x12b01: mov byte ptr [0x100], dl
0x12b05: mov ah, 0x2c
0x12b07: int 0x21
0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
2018-12-17T22:29:05.534072151Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x734
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73b
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:29:05.536311477Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x734
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73b
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:29:05.539916117Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x734
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73b
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:29:05.542200123Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x734
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73b
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:29:05.544267308Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x734
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73b
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:29:05.546879121Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x734
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73b
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:29:05.54912292Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x734
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73b
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:29:05.551507115Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x734
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73b
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:29:05.554099989Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x734
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73b
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:29:05.556345727Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x734
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73b
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:29:05.558460363Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x734
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73b
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:29:05.561188438Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x734
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73b
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:29:05.563476227Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x734
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73b
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:29:05.565722444Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x734
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73b
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:29:05.56825433Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x734
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73b
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:29:05.570560768Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x734
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73b
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:29:05.572820331Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x734
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73b
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:29:05.575585602Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x734
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73b
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:29:05.57842416Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x734
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73b
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:29:05.580785641Z 44 PC: 12b09 | Get time 0x12b09: xor dh, dh
0x12b0b: and dl, 7
0x12b0e: cmp dx, 6
0x12b11: jg 0x12b05
0x12b13: pop ax
0x12b14: push ax
0x12b15: cmp ax, dx
0x12b17: je 0x12b05
0x12b19: pop ax
0x12b1a: push dx
0x12b1b: add dx, 0x734
0x12b1f: mov si, dx
0x12b21: mov dl, byte ptr cs:[si]
0x12b24: mov byte ptr [0x104], dl
0x12b28: pop dx
0x12b29: add dx, 0x73b
0x12b2d: mov si, dx
0x12b2f: mov dl, byte ptr cs:[si]
0x12b32: mov byte ptr [0x106], dl
0x12b36: mov ax, 0x4200
2018-12-17T22:29:05.584231952Z 66 PC: 12b3f | Move file pointer
2018-12-17T22:29:05.58602926Z 44 PC: 12b44 | Get time 0x12b44: mov word ptr [0x92d], dx
0x12b48: mov si, 0x2d8
0x12b4b: mov di, 0x935
0x12b4e: mov cx, 0x1a
0x12b51: rep movsb byte ptr es:[di], byte ptr [si]
0x12b53: call 0x13275
0x12b56: mov ah, 0x3e
0x12b58: int 0x21
0x12b5a: mov ah, 9
0x12b5c: mov dx, 0x749
0x12b5f: int 0x21
0x12b61: int 0x20
0x12b63: mov ah, 0xf
0x12b65: int 0x10
0x12b67: xor ah, ah
0x12b69: int 0x10
0x12b6b: mov ah, 1
0x12b6d: mov cx, 0x2607
0x12b70: int 0x10
0x12b72: mov ax, 0xb800
2018-12-17T22:29:05.588846001Z 64 PC: 13287 | Write file or device (Write 2097 bytes on handle 5)
2018-12-17T22:29:05.604945765Z 62 PC: 12b5a | Close file
2018-12-17T22:29:05.613929032Z 9 PC: 12b61 | Display string (String= 'Parameter value not in allowed range ')