Sample viewer

vx.netlux.org/Virus.DOS.Devil.941

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:32:50.92507754Z 53 PC: 130d8 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:50.926882828Z 78 PC: 13436 | Find first file
2018-12-17T22:32:50.933269966Z 67 PC: 133cc | Get or set file attributes
2018-12-17T22:32:50.948766917Z 61 PC: 133d4 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:32:50.960853566Z 63 PC: 133e6 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:50.967082729Z 66 PC: 133f6 | Move file pointer
2018-12-17T22:32:50.968314779Z 64 PC: 1340e | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:50.972573077Z 66 PC: 1341b | Move file pointer
2018-12-17T22:32:50.973860892Z 64 PC: 13424 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:32:50.981946591Z 62 PC: 13428 | Close file
2018-12-17T22:32:50.989829393Z 79 PC: 13442 | Find next file
2018-12-17T22:32:50.994648201Z 67 PC: 133cc | Get or set file attributes
2018-12-17T22:32:51.007277539Z 61 PC: 133d4 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:32:51.013613152Z 63 PC: 133e6 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:51.021795278Z 66 PC: 133f6 | Move file pointer
2018-12-17T22:32:51.023061758Z 64 PC: 1340e | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:51.025862675Z 66 PC: 1341b | Move file pointer
2018-12-17T22:32:51.028109604Z 64 PC: 13424 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:32:51.036226703Z 62 PC: 13428 | Close file
2018-12-17T22:32:51.045078832Z 79 PC: 13442 | Find next file
2018-12-17T22:32:51.048656372Z 67 PC: 133cc | Get or set file attributes
2018-12-17T22:32:51.058806267Z 61 PC: 133d4 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:32:51.065741203Z 63 PC: 133e6 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:51.073998694Z 66 PC: 133f6 | Move file pointer
2018-12-17T22:32:51.075703838Z 64 PC: 1340e | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:51.078635145Z 66 PC: 1341b | Move file pointer
2018-12-17T22:32:51.080950881Z 64 PC: 13424 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:32:51.089697173Z 62 PC: 13428 | Close file
2018-12-17T22:32:51.101067746Z 79 PC: 13442 | Find next file
2018-12-17T22:32:51.105498669Z 67 PC: 133cc | Get or set file attributes
2018-12-17T22:32:51.115268975Z 61 PC: 133d4 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:32:51.121673028Z 63 PC: 133e6 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:51.12901341Z 66 PC: 133f6 | Move file pointer
2018-12-17T22:32:51.130381582Z 64 PC: 1340e | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:51.132959954Z 66 PC: 1341b | Move file pointer
2018-12-17T22:32:51.134933679Z 64 PC: 13424 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:32:51.142716465Z 62 PC: 13428 | Close file
2018-12-17T22:32:51.150553128Z 79 PC: 13442 | Find next file
2018-12-17T22:32:51.153434355Z 67 PC: 133cc | Get or set file attributes
2018-12-17T22:32:51.16304441Z 61 PC: 133d4 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:32:51.170127819Z 63 PC: 133e6 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:51.176869888Z 66 PC: 133f6 | Move file pointer
2018-12-17T22:32:51.178123214Z 64 PC: 1340e | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:51.1809641Z 66 PC: 1341b | Move file pointer
2018-12-17T22:32:51.182496364Z 64 PC: 13424 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:32:51.190505685Z 62 PC: 13428 | Close file
2018-12-17T22:32:51.198470344Z 79 PC: 13442 | Find next file
2018-12-17T22:32:51.201330695Z 67 PC: 133cc | Get or set file attributes
2018-12-17T22:32:51.212364179Z 61 PC: 133d4 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:32:51.218864714Z 63 PC: 133e6 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:51.225005814Z 66 PC: 133f6 | Move file pointer
2018-12-17T22:32:51.226630135Z 64 PC: 1340e | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:51.229231204Z 66 PC: 1341b | Move file pointer
2018-12-17T22:32:51.230537091Z 64 PC: 13424 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:32:51.240319575Z 62 PC: 13428 | Close file
2018-12-17T22:32:51.248149074Z 79 PC: 13442 | Find next file
2018-12-17T22:32:51.250704692Z 67 PC: 133cc | Get or set file attributes
2018-12-17T22:32:51.260955844Z 61 PC: 133d4 | Open file (Filename = 'PAH.COM')
2018-12-17T22:32:51.267467808Z 63 PC: 133e6 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:51.273599609Z 66 PC: 133f6 | Move file pointer
2018-12-17T22:32:51.276002437Z 64 PC: 1340e | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:51.278617799Z 66 PC: 1341b | Move file pointer
2018-12-17T22:32:51.279874742Z 64 PC: 13424 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:32:51.28798483Z 62 PC: 13428 | Close file
2018-12-17T22:32:51.295667056Z 79 PC: 13442 | Find next file
2018-12-17T22:32:51.298418496Z 67 PC: 133cc | Get or set file attributes
2018-12-17T22:32:51.309741437Z 61 PC: 133d4 | Open file (Filename = 'TEST.COM')
2018-12-17T22:32:51.316492745Z 63 PC: 133e6 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:51.322860065Z 66 PC: 133f6 | Move file pointer
2018-12-17T22:32:51.325333938Z 64 PC: 1340e | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:51.328528838Z 66 PC: 1341b | Move file pointer
2018-12-17T22:32:51.329912899Z 64 PC: 13424 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:32:51.339088457Z 62 PC: 13428 | Close file
2018-12-17T22:32:51.34705092Z 79 PC: 13442 | Find next file
2018-12-17T22:32:51.34938764Z 74 PC: 130fb | Reallocate memory
2018-12-17T22:32:51.351504845Z 72 PC: 13103 | Allocate memory
2018-12-17T22:32:51.353003094Z 53 PC: 13131 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:51.354775003Z 37 PC: 13141 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:51.356110681Z 53 PC: 13146 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:32:51.358171806Z 37 PC: 13161 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:32:51.359311427Z 255 PC: 12ada | UNKNOWN!
2018-12-17T22:32:51.360137402Z 255 PC: 12b2d | UNKNOWN!
2018-12-17T22:32:51.361822353Z 74 PC: 12bae | Reallocate memory
2018-12-17T22:32:51.363189343Z 53 PC: 12bb3 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:51.36444775Z 37 PC: 12bc7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:51.367276996Z 42 PC: 12bf7 | Get date 0x12bf7: mov byte ptr cs:[0xe], 0
0x12bfd: cmp cx, 0x7c5
0x12c01: je 0x12c2f
0x12c03: cmp al, 7
0x12c05: jne 0x12c10
0x12c07: inc byte ptr cs:[0xe]
0x12c0c: jmp 0x12c2f
0x12c0e: nop
0x12c0f: nop
0x12c10: mov ax, 0x3508
0x12c13: int 0x21
0x12c15: mov word ptr cs:[0x13], bx
0x12c1a: mov word ptr cs:[0x15], es
0x12c1f: push cs
0x12c20: pop ds
0x12c21: mov word ptr [0x1f], 0x7e90
0x12c27: mov ax, 0x2508
0x12c2a: mov dx, 0x216
0x12c2d: int 0x21
0x12c2f: pop dx
2018-12-17T22:32:51.370076595Z 53 PC: 12c15 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:32:51.371395938Z 37 PC: 12c2f | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:32:51.373643972Z 47 PC: 22d37 | Get disk transfer address
2018-12-17T22:32:51.374856855Z 26 PC: 22d44 | Set disk transfer address
2018-12-17T22:32:51.3759132Z 78 PC: 22d4d | Find first file
2018-12-17T22:32:51.38298873Z 67 PC: 22d79 | Get or set file attributes
2018-12-17T22:32:51.392530363Z 61 PC: 22d81 | Open file (Filename = 'TEST.COM')
2018-12-17T22:32:51.398981195Z 63 PC: 22d93 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:51.402083871Z 66 PC: 22da3 | Move file pointer
2018-12-17T22:32:51.403623865Z 64 PC: 22dbb | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:51.406560114Z 66 PC: 22dc8 | Move file pointer
2018-12-17T22:32:51.409380836Z 64 PC: 22dd1 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:32:51.417826682Z 62 PC: 22dd5 | Close file
2018-12-17T22:32:51.427766691Z 26 PC: 22d5e | Set disk transfer address
2018-12-17T22:32:51.429685154Z 75 PC: 12c3b | Execute program
2018-12-17T22:32:51.444037218Z 53 PC: 23eeb | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:51.446254811Z 78 PC: 24249 | Find first file
2018-12-17T22:32:51.453660008Z 67 PC: 241df | Get or set file attributes
2018-12-17T22:32:51.463584451Z 61 PC: 241e7 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:32:51.470470867Z 63 PC: 241f9 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:51.478014929Z 66 PC: 24209 | Move file pointer
2018-12-17T22:32:51.480207908Z 64 PC: 24221 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:51.483107212Z 66 PC: 2422e | Move file pointer
2018-12-17T22:32:51.485760048Z 64 PC: 24237 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:32:51.494173192Z 62 PC: 2423b | Close file
2018-12-17T22:32:51.502310488Z 79 PC: 24255 | Find next file
2018-12-17T22:32:51.506035954Z 67 PC: 241df | Get or set file attributes
2018-12-17T22:32:51.51648447Z 61 PC: 241e7 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:32:51.523316738Z 63 PC: 241f9 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:51.530484918Z 66 PC: 24209 | Move file pointer
2018-12-17T22:32:51.532600281Z 64 PC: 24221 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:51.53560863Z 66 PC: 2422e | Move file pointer
2018-12-17T22:32:51.538230313Z 64 PC: 24237 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:32:51.547290941Z 62 PC: 2423b | Close file
2018-12-17T22:32:51.55559493Z 79 PC: 24255 | Find next file
2018-12-17T22:32:51.559369312Z 67 PC: 241df | Get or set file attributes
2018-12-17T22:32:51.569666164Z 61 PC: 241e7 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:32:51.576563264Z 63 PC: 241f9 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:51.583827489Z 66 PC: 24209 | Move file pointer
2018-12-17T22:32:51.58656065Z 64 PC: 24221 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:51.589576633Z 66 PC: 2422e | Move file pointer
2018-12-17T22:32:51.591328622Z 64 PC: 24237 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:32:51.599853495Z 62 PC: 2423b | Close file
2018-12-17T22:32:51.607986053Z 79 PC: 24255 | Find next file
2018-12-17T22:32:51.61083053Z 67 PC: 241df | Get or set file attributes
2018-12-17T22:32:51.620633248Z 61 PC: 241e7 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:32:51.62709168Z 63 PC: 241f9 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:51.633349049Z 66 PC: 24209 | Move file pointer
2018-12-17T22:32:51.635242965Z 64 PC: 24221 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:51.637723849Z 66 PC: 2422e | Move file pointer
2018-12-17T22:32:51.639085331Z 64 PC: 24237 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:32:51.648134757Z 62 PC: 2423b | Close file
2018-12-17T22:32:51.656255177Z 79 PC: 24255 | Find next file
2018-12-17T22:32:51.659130222Z 67 PC: 241df | Get or set file attributes
2018-12-17T22:32:51.669206849Z 61 PC: 241e7 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:32:51.675714923Z 63 PC: 241f9 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:51.681889857Z 66 PC: 24209 | Move file pointer
2018-12-17T22:32:51.684258122Z 64 PC: 24221 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:51.68682394Z 66 PC: 2422e | Move file pointer
2018-12-17T22:32:51.688180519Z 64 PC: 24237 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:32:51.697492347Z 62 PC: 2423b | Close file
2018-12-17T22:32:51.705627537Z 79 PC: 24255 | Find next file
2018-12-17T22:32:51.709372821Z 67 PC: 241df | Get or set file attributes
2018-12-17T22:32:51.719947486Z 61 PC: 241e7 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:32:51.726697884Z 63 PC: 241f9 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:51.733766033Z 66 PC: 24209 | Move file pointer
2018-12-17T22:32:51.736264583Z 64 PC: 24221 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:51.739359678Z 66 PC: 2422e | Move file pointer
2018-12-17T22:32:51.741084248Z 64 PC: 24237 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:32:51.750594892Z 62 PC: 2423b | Close file
2018-12-17T22:32:51.759205301Z 79 PC: 24255 | Find next file
2018-12-17T22:32:51.761917644Z 67 PC: 241df | Get or set file attributes
2018-12-17T22:32:51.772458269Z 61 PC: 241e7 | Open file (Filename = 'PAH.COM')
2018-12-17T22:32:51.779322585Z 63 PC: 241f9 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:51.785901851Z 66 PC: 24209 | Move file pointer
2018-12-17T22:32:51.787892281Z 64 PC: 24221 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:51.790934725Z 66 PC: 2422e | Move file pointer
2018-12-17T22:32:51.792653341Z 64 PC: 24237 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:32:51.801837884Z 62 PC: 2423b | Close file
2018-12-17T22:32:51.821640212Z 79 PC: 24255 | Find next file
2018-12-17T22:32:51.824244516Z 67 PC: 241df | Get or set file attributes
2018-12-17T22:32:51.835016947Z 61 PC: 241e7 | Open file (Filename = 'TEST.COM')
2018-12-17T22:32:51.842278781Z 63 PC: 241f9 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:51.84479756Z 66 PC: 24209 | Move file pointer
2018-12-17T22:32:51.846945436Z 64 PC: 24221 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:51.84956018Z 66 PC: 2422e | Move file pointer
2018-12-17T22:32:51.850921772Z 64 PC: 24237 | Write file or device (Write 941 bytes on handle 5)
2018-12-17T22:32:51.859956589Z 62 PC: 2423b | Close file
2018-12-17T22:32:51.868382918Z 79 PC: 24255 | Find next file
2018-12-17T22:32:51.87124303Z 74 PC: 23f0e | Reallocate memory
2018-12-17T22:32:51.873399788Z 72 PC: 23f16 | Allocate memory
2018-12-17T22:32:51.874999427Z 53 PC: 23f44 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:51.876156146Z 37 PC: 23f54 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:51.878028796Z 53 PC: 23f59 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:32:51.879382482Z 37 PC: 23f74 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:32:51.880595634Z 53 PC: 23b3e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:51.88296748Z 53 PC: 235b8 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:51.884429831Z 0 PC: 22f22 | Program terminate
2018-12-17T22:32:51.8876769Z 73 PC: 12c41 | Release memory
2018-12-17T22:32:51.890408878Z 77 PC: 12c45 | Get program return code
2018-12-17T22:32:51.892631343Z 49 PC: 12c53 | Terminate and stay resident (Return code = '0' | Memory size = '117')