Sample viewer

vx.netlux.org/Virus.DOS.Gobot.2102

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:33:26.111258006Z 53 PC: 12a56 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:33:26.113286746Z 37 PC: 12a66 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:33:26.114432362Z 78 PC: 12a75 | Find first file
2018-12-17T22:33:26.130980602Z 61 PC: 12a7f | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:33:26.139473458Z 63 PC: 12a8a | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:33:26.146136372Z 44 PC: 12ade | Get time 0x12ade: xor dh, dh
0x12ae0: and dl, 7
0x12ae3: cmp dx, 6
0x12ae6: nop
0x12ae7: jg 0x12ada
0x12ae9: push dx
0x12aea: add dx, 0x731
0x12aee: mov si, dx
0x12af0: mov dl, byte ptr cs:[si]
0x12af3: mov byte ptr [0x103], dl
0x12af7: pop dx
0x12af8: push dx
0x12af9: add dx, 0x746
0x12afd: mov si, dx
0x12aff: mov dl, byte ptr cs:[si]
0x12b02: mov byte ptr [0x100], dl
0x12b06: mov ah, 0x2c
0x12b08: int 0x21
0x12b0a: xor dh, dh
0x12b0c: and dl, 7
2018-12-17T22:33:26.148373035Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x738
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73f
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:33:26.151491008Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x738
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73f
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:33:26.154042446Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x738
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73f
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:33:26.156818586Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x738
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73f
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:33:26.159993578Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x738
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73f
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:33:26.162404476Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x738
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73f
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:33:26.164540324Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x738
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73f
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:33:26.166900805Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x738
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73f
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:33:26.169638285Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x738
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73f
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:33:26.171754797Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x738
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73f
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:33:26.173898138Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x738
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73f
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:33:26.176188626Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x738
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73f
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:33:26.178123327Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x738
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73f
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:33:26.180056282Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x738
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73f
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:33:26.182989572Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x738
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73f
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:33:26.185789231Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x738
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73f
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:33:26.187982945Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x738
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x73f
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:33:26.191257239Z 66 PC: 12b41 | Move file pointer
2018-12-17T22:33:26.192892316Z 44 PC: 12b46 | Get time 0x12b46: mov word ptr [0x932], dx
0x12b4a: mov si, 0x2dc
0x12b4d: mov di, 0x93a
0x12b50: mov cx, 0x1a
0x12b53: nop
0x12b54: rep movsb byte ptr es:[di], byte ptr [si]
0x12b56: call 0x1327a
0x12b59: mov ah, 0x3e
0x12b5b: int 0x21
0x12b5d: mov ah, 9
0x12b5f: mov dx, 0x74d
0x12b62: int 0x21
0x12b64: int 0x20
0x12b66: mov ah, 0xf
0x12b68: int 0x10
0x12b6a: xor ah, ah
0x12b6c: int 0x10
0x12b6e: mov ah, 1
0x12b70: mov cx, 0x2607
0x12b73: int 0x10
2018-12-17T22:33:26.195857491Z 64 PC: 1328c | Write file or device (Write 2102 bytes on handle 5)
2018-12-17T22:33:26.227825193Z 62 PC: 12b5d | Close file
2018-12-17T22:33:26.235730995Z 9 PC: 12b64 | Display string (String= 'Parameter value not in allowed range ')