Sample viewer

vx.netlux.org/Virus.DOS.Search.198

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:34:01.158501742Z 26 PC: 12ab4 | Set disk transfer address
2018-12-17T22:34:01.160017607Z 78 PC: 12ac0 | Find first file
2018-12-17T22:34:01.166726857Z 61 PC: 12ad0 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:34:01.173666242Z 63 PC: 12ae1 | Read file or device (Read 13 bytes on handle 5)
2018-12-17T22:34:01.180549262Z 66 PC: 12af0 | Move file pointer
2018-12-17T22:34:01.182545792Z 64 PC: 12aff | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:34:01.185718422Z 66 PC: 12b08 | Move file pointer
2018-12-17T22:34:01.187510406Z 64 PC: 12b18 | Write file or device (Write 185 bytes on handle 5)
2018-12-17T22:34:01.204808339Z 64 PC: 12b24 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:34:01.207679254Z 62 PC: 12b28 | Close file
2018-12-17T22:34:01.21629353Z 79 PC: 12ac0 | Find next file
2018-12-17T22:34:01.219535017Z 61 PC: 12ad0 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:34:01.227306003Z 63 PC: 12ae1 | Read file or device (Read 13 bytes on handle 5)
2018-12-17T22:34:01.234293656Z 66 PC: 12af0 | Move file pointer
2018-12-17T22:34:01.236049003Z 64 PC: 12aff | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:34:01.238795516Z 66 PC: 12b08 | Move file pointer
2018-12-17T22:34:01.240017602Z 64 PC: 12b18 | Write file or device (Write 185 bytes on handle 5)
2018-12-17T22:34:01.243155001Z 64 PC: 12b24 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:34:01.246240157Z 62 PC: 12b28 | Close file
2018-12-17T22:34:01.254920463Z 79 PC: 12ac0 | Find next file
2018-12-17T22:34:01.258060255Z 61 PC: 12ad0 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:34:01.265412636Z 63 PC: 12ae1 | Read file or device (Read 13 bytes on handle 5)
2018-12-17T22:34:01.272973805Z 66 PC: 12af0 | Move file pointer
2018-12-17T22:34:01.274394641Z 64 PC: 12aff | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:34:01.277693834Z 66 PC: 12b08 | Move file pointer
2018-12-17T22:34:01.27921696Z 64 PC: 12b18 | Write file or device (Write 185 bytes on handle 5)
2018-12-17T22:34:01.282057764Z 64 PC: 12b24 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:34:01.286038586Z 62 PC: 12b28 | Close file
2018-12-17T22:34:01.295034169Z 79 PC: 12ac0 | Find next file
2018-12-17T22:34:01.297938091Z 61 PC: 12ad0 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:34:01.305508413Z 63 PC: 12ae1 | Read file or device (Read 13 bytes on handle 5)
2018-12-17T22:34:01.312409598Z 66 PC: 12af0 | Move file pointer
2018-12-17T22:34:01.314064202Z 64 PC: 12aff | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:34:01.317489072Z 66 PC: 12b08 | Move file pointer
2018-12-17T22:34:01.319048017Z 64 PC: 12b18 | Write file or device (Write 185 bytes on handle 5)
2018-12-17T22:34:01.321808318Z 64 PC: 12b24 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:34:01.325158193Z 62 PC: 12b28 | Close file
2018-12-17T22:34:01.333437653Z 79 PC: 12ac0 | Find next file
2018-12-17T22:34:01.336108207Z 61 PC: 12ad0 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:34:01.343595791Z 63 PC: 12ae1 | Read file or device (Read 13 bytes on handle 5)
2018-12-17T22:34:01.350307395Z 66 PC: 12af0 | Move file pointer
2018-12-17T22:34:01.352456442Z 64 PC: 12aff | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:34:01.355628715Z 66 PC: 12b08 | Move file pointer
2018-12-17T22:34:01.357212964Z 64 PC: 12b18 | Write file or device (Write 185 bytes on handle 5)
2018-12-17T22:34:01.360176467Z 64 PC: 12b24 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:34:01.363570381Z 62 PC: 12b28 | Close file
2018-12-17T22:34:01.372893939Z 79 PC: 12ac0 | Find next file
2018-12-17T22:34:01.375736732Z 61 PC: 12ad0 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:34:01.382784815Z 63 PC: 12ae1 | Read file or device (Read 13 bytes on handle 5)
2018-12-17T22:34:01.390147251Z 66 PC: 12af0 | Move file pointer
2018-12-17T22:34:01.391790678Z 64 PC: 12aff | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:34:01.394680496Z 66 PC: 12b08 | Move file pointer
2018-12-17T22:34:01.396834166Z 64 PC: 12b18 | Write file or device (Write 185 bytes on handle 5)
2018-12-17T22:34:01.405467468Z 64 PC: 12b24 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:34:01.408340679Z 62 PC: 12b28 | Close file
2018-12-17T22:34:01.417463019Z 79 PC: 12ac0 | Find next file
2018-12-17T22:34:01.421120123Z 61 PC: 12ad0 | Open file (Filename = 'PAH.COM')
2018-12-17T22:34:01.428113164Z 63 PC: 12ae1 | Read file or device (Read 13 bytes on handle 5)
2018-12-17T22:34:01.435622604Z 66 PC: 12af0 | Move file pointer
2018-12-17T22:34:01.437130739Z 64 PC: 12aff | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:34:01.439896804Z 66 PC: 12b08 | Move file pointer
2018-12-17T22:34:01.44216799Z 64 PC: 12b18 | Write file or device (Write 185 bytes on handle 5)
2018-12-17T22:34:01.445353785Z 64 PC: 12b24 | Write file or device (Write 13 bytes on handle 5)
2018-12-17T22:34:01.448212649Z 62 PC: 12b28 | Close file
2018-12-17T22:34:01.457215161Z 79 PC: 12ac0 | Find next file
2018-12-17T22:34:01.460500951Z 61 PC: 12ad0 | Open file (Filename = 'TEST.COM')
2018-12-17T22:34:01.468145751Z 63 PC: 12ae1 | Read file or device (Read 13 bytes on handle 5)
2018-12-17T22:34:01.472051715Z 62 PC: 12b28 | Close file
2018-12-17T22:34:01.47395835Z 79 PC: 12ac0 | Find next file
2018-12-17T22:34:01.476496089Z 26 PC: 12b33 | Set disk transfer address
2018-12-17T22:34:01.478186119Z 42 PC: 12b49 | Get date 0x12b49: or al, al
0x12b4b: jne 0x12b52
0x12b4d: ljmp 0xffff:0
0x12b52: mov ax, 0x100
0x12b55: jmp ax
0x12b57: sub ch, byte ptr [0x4f43]
0x12b5b: dec bp
0x12b5c: add bl, ch
0x12b5e: pop cx
0x12b5f: nop
0x12b60: dec ax
0x12b61: insb byte ptr es:[di], dx
0x12b63: insb byte ptr es:[di], dx
0x12b64: outsw dx, word ptr [si]
0x12b65: and byte ptr [di], ch
0x12b67: and byte ptr [bp + di + 0x6f], al
0x12b6a: mov ax, 0x10d
0x12b6d: add ax, word ptr [0x109]
0x12b71: jmp ax
0x12b73: push di
2018-12-17T22:34:01.480435233Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')