Sample viewer

vx.netlux.org/Virus.DOS.Corea.783

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:36:40.162779518Z 42 PC: 12c2d | Get date 0x12c2d: ret
0x12c2e: dec bp
0x12c2f: inc bp
0x12c30: dec bp
0x12c31: inc bx
0x12c33: dec di
0x12c34: dec bp
0x12c35: add byte ptr [bx + di + 0x6e], cl
0x12c38: arpl word ptr [bx + 0x72], bp
0x12c3b: jb 0x12ca2
0x12c3d: arpl word ptr [si + 0x20], si
0x12c40: inc sp
0x12c41: dec di
0x12c42: push bx
0x12c43: and byte ptr [bp + 0x65], dh
0x12c46: jb 0x12cbb
0x12c48: imul bp, word ptr [bx + 0x6e], 0xd0a
0x12c4d: and al, 0
0x12c4f: add byte ptr [bx + si], al
0x12c51: add byte ptr [bp + si], ch
2018-12-17T22:36:40.165415013Z 78 PC: 12c2d | Find first file
2018-12-17T22:36:40.172552354Z 67 PC: 12c2d | Get or set file attributes
2018-12-17T22:36:40.19018934Z 61 PC: 12c2d | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:36:40.197467989Z 63 PC: 12c2d | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:36:40.204362426Z 66 PC: 12ab6 | Move file pointer
2018-12-17T22:36:40.205619991Z 66 PC: 12c2d | Move file pointer
2018-12-17T22:36:40.206814049Z 44 PC: 12acc | Get time 0x12acc: mov byte ptr [0x3da], dl
0x12ad0: mov byte ptr [0x3e2], dl
0x12ad4: mov byte ptr [0x3eb], dl
0x12ad8: mov byte ptr [0x3f8], dl
0x12adc: mov byte ptr [0x3fe], dl
0x12ae0: mov byte ptr [0x407], dl
0x12ae4: mov byte ptr [0x40d], dl
0x12ae8: mov byte ptr [0x3b7], dl
0x12aec: mov byte ptr [0x3cb], dl
0x12af0: mov byte ptr [0x3d3], dl
0x12af4: mov byte ptr [0x403], dl
0x12af8: mov byte ptr [0x3f3], dl
0x12afc: mov byte ptr [0x3ec], dl
0x12b00: mov byte ptr [0x3e3], dl
0x12b04: mov byte ptr [0x3db], dl
0x12b08: mov byte ptr [0x3a4], dl
0x12b0c: mov byte ptr [0x3ab], dl
0x12b10: mov byte ptr [0x3b1], dl
0x12b14: mov byte ptr [0x3be], dl
0x12b18: mov byte ptr [0xc5], dl
2018-12-17T22:36:40.209460968Z 64 PC: 12d08 | Write file or device (Write 783 bytes on handle 5)
2018-12-17T22:36:40.218540164Z 62 PC: 12c2d | Close file
2018-12-17T22:36:40.227092135Z 62 PC: 12b2d | Close file
2018-12-17T22:36:40.229927989Z 79 PC: 12c2d | Find next file
2018-12-17T22:36:40.232753808Z 67 PC: 12c2d | Get or set file attributes
2018-12-17T22:36:40.243555814Z 61 PC: 12c2d | Open file (Filename = 'PRINT.COM')
2018-12-17T22:36:40.250878955Z 63 PC: 12c2d | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:36:40.257554083Z 66 PC: 12ab6 | Move file pointer
2018-12-17T22:36:40.258952903Z 66 PC: 12c2d | Move file pointer
2018-12-17T22:36:40.260596512Z 44 PC: 12acc | Get time 0x12acc: mov byte ptr [0x3da], dl
0x12ad0: mov byte ptr [0x3e2], dl
0x12ad4: mov byte ptr [0x3eb], dl
0x12ad8: mov byte ptr [0x3f8], dl
0x12adc: mov byte ptr [0x3fe], dl
0x12ae0: mov byte ptr [0x407], dl
0x12ae4: mov byte ptr [0x40d], dl
0x12ae8: mov byte ptr [0x3b7], dl
0x12aec: mov byte ptr [0x3cb], dl
0x12af0: mov byte ptr [0x3d3], dl
0x12af4: mov byte ptr [0x403], dl
0x12af8: mov byte ptr [0x3f3], dl
0x12afc: mov byte ptr [0x3ec], dl
0x12b00: mov byte ptr [0x3e3], dl
0x12b04: mov byte ptr [0x3db], dl
0x12b08: mov byte ptr [0x3a4], dl
0x12b0c: mov byte ptr [0x3ab], dl
0x12b10: mov byte ptr [0x3b1], dl
0x12b14: mov byte ptr [0x3be], dl
0x12b18: mov byte ptr [0xc5], dl
2018-12-17T22:36:40.263210357Z 64 PC: 12d08 | Write file or device (Write 783 bytes on handle 5)
2018-12-17T22:36:40.271875754Z 62 PC: 12c2d | Close file
2018-12-17T22:36:40.280574316Z 62 PC: 12b2d | Close file
2018-12-17T22:36:40.282035051Z 79 PC: 12c2d | Find next file
2018-12-17T22:36:40.284675521Z 67 PC: 12c2d | Get or set file attributes
2018-12-17T22:36:40.294627736Z 61 PC: 12c2d | Open file (Filename = 'HELLO.COM')
2018-12-17T22:36:40.30248861Z 63 PC: 12c2d | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:36:40.309127246Z 66 PC: 12ab6 | Move file pointer
2018-12-17T22:36:40.310579752Z 66 PC: 12c2d | Move file pointer
2018-12-17T22:36:40.312337382Z 44 PC: 12acc | Get time 0x12acc: mov byte ptr [0x3da], dl
0x12ad0: mov byte ptr [0x3e2], dl
0x12ad4: mov byte ptr [0x3eb], dl
0x12ad8: mov byte ptr [0x3f8], dl
0x12adc: mov byte ptr [0x3fe], dl
0x12ae0: mov byte ptr [0x407], dl
0x12ae4: mov byte ptr [0x40d], dl
0x12ae8: mov byte ptr [0x3b7], dl
0x12aec: mov byte ptr [0x3cb], dl
0x12af0: mov byte ptr [0x3d3], dl
0x12af4: mov byte ptr [0x403], dl
0x12af8: mov byte ptr [0x3f3], dl
0x12afc: mov byte ptr [0x3ec], dl
0x12b00: mov byte ptr [0x3e3], dl
0x12b04: mov byte ptr [0x3db], dl
0x12b08: mov byte ptr [0x3a4], dl
0x12b0c: mov byte ptr [0x3ab], dl
0x12b10: mov byte ptr [0x3b1], dl
0x12b14: mov byte ptr [0x3be], dl
0x12b18: mov byte ptr [0xc5], dl
2018-12-17T22:36:40.314936951Z 64 PC: 12d08 | Write file or device (Write 783 bytes on handle 5)
2018-12-17T22:36:40.32362304Z 62 PC: 12c2d | Close file
2018-12-17T22:36:40.333472302Z 62 PC: 12b2d | Close file
2018-12-17T22:36:40.335071229Z 79 PC: 12c2d | Find next file
2018-12-17T22:36:40.338274936Z 67 PC: 12c2d | Get or set file attributes
2018-12-17T22:36:40.350592023Z 61 PC: 12c2d | Open file (Filename = 'PHANG.COM')
2018-12-17T22:36:40.358775987Z 63 PC: 12c2d | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:36:40.366905527Z 66 PC: 12ab6 | Move file pointer
2018-12-17T22:36:40.368724055Z 66 PC: 12c2d | Move file pointer
2018-12-17T22:36:40.370305723Z 44 PC: 12acc | Get time 0x12acc: mov byte ptr [0x3da], dl
0x12ad0: mov byte ptr [0x3e2], dl
0x12ad4: mov byte ptr [0x3eb], dl
0x12ad8: mov byte ptr [0x3f8], dl
0x12adc: mov byte ptr [0x3fe], dl
0x12ae0: mov byte ptr [0x407], dl
0x12ae4: mov byte ptr [0x40d], dl
0x12ae8: mov byte ptr [0x3b7], dl
0x12aec: mov byte ptr [0x3cb], dl
0x12af0: mov byte ptr [0x3d3], dl
0x12af4: mov byte ptr [0x403], dl
0x12af8: mov byte ptr [0x3f3], dl
0x12afc: mov byte ptr [0x3ec], dl
0x12b00: mov byte ptr [0x3e3], dl
0x12b04: mov byte ptr [0x3db], dl
0x12b08: mov byte ptr [0x3a4], dl
0x12b0c: mov byte ptr [0x3ab], dl
0x12b10: mov byte ptr [0x3b1], dl
0x12b14: mov byte ptr [0x3be], dl
0x12b18: mov byte ptr [0xc5], dl
2018-12-17T22:36:40.373132954Z 64 PC: 12d08 | Write file or device (Write 783 bytes on handle 5)
2018-12-17T22:36:40.383666898Z 62 PC: 12c2d | Close file
2018-12-17T22:36:40.393792547Z 62 PC: 12b2d | Close file
2018-12-17T22:36:40.395395097Z 79 PC: 12c2d | Find next file
2018-12-17T22:36:40.39933406Z 67 PC: 12c2d | Get or set file attributes
2018-12-17T22:36:40.410389176Z 61 PC: 12c2d | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:36:40.41756099Z 63 PC: 12c2d | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:36:40.425247052Z 66 PC: 12ab6 | Move file pointer
2018-12-17T22:36:40.426769564Z 66 PC: 12c2d | Move file pointer
2018-12-17T22:36:40.42814941Z 44 PC: 12acc | Get time 0x12acc: mov byte ptr [0x3da], dl
0x12ad0: mov byte ptr [0x3e2], dl
0x12ad4: mov byte ptr [0x3eb], dl
0x12ad8: mov byte ptr [0x3f8], dl
0x12adc: mov byte ptr [0x3fe], dl
0x12ae0: mov byte ptr [0x407], dl
0x12ae4: mov byte ptr [0x40d], dl
0x12ae8: mov byte ptr [0x3b7], dl
0x12aec: mov byte ptr [0x3cb], dl
0x12af0: mov byte ptr [0x3d3], dl
0x12af4: mov byte ptr [0x403], dl
0x12af8: mov byte ptr [0x3f3], dl
0x12afc: mov byte ptr [0x3ec], dl
0x12b00: mov byte ptr [0x3e3], dl
0x12b04: mov byte ptr [0x3db], dl
0x12b08: mov byte ptr [0x3a4], dl
0x12b0c: mov byte ptr [0x3ab], dl
0x12b10: mov byte ptr [0x3b1], dl
0x12b14: mov byte ptr [0x3be], dl
0x12b18: mov byte ptr [0xc5], dl
2018-12-17T22:36:40.43102889Z 64 PC: 12d08 | Write file or device (Write 783 bytes on handle 5)
2018-12-17T22:36:40.44071283Z 62 PC: 12c2d | Close file
2018-12-17T22:36:40.449410317Z 62 PC: 12b2d | Close file
2018-12-17T22:36:40.450866588Z 79 PC: 12c2d | Find next file
2018-12-17T22:36:40.454180435Z 67 PC: 12c2d | Get or set file attributes
2018-12-17T22:36:40.46472672Z 61 PC: 12c2d | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:36:40.471756004Z 63 PC: 12c2d | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:36:40.479041129Z 66 PC: 12ab6 | Move file pointer
2018-12-17T22:36:40.480535868Z 66 PC: 12c2d | Move file pointer
2018-12-17T22:36:40.481912951Z 44 PC: 12acc | Get time 0x12acc: mov byte ptr [0x3da], dl
0x12ad0: mov byte ptr [0x3e2], dl
0x12ad4: mov byte ptr [0x3eb], dl
0x12ad8: mov byte ptr [0x3f8], dl
0x12adc: mov byte ptr [0x3fe], dl
0x12ae0: mov byte ptr [0x407], dl
0x12ae4: mov byte ptr [0x40d], dl
0x12ae8: mov byte ptr [0x3b7], dl
0x12aec: mov byte ptr [0x3cb], dl
0x12af0: mov byte ptr [0x3d3], dl
0x12af4: mov byte ptr [0x403], dl
0x12af8: mov byte ptr [0x3f3], dl
0x12afc: mov byte ptr [0x3ec], dl
0x12b00: mov byte ptr [0x3e3], dl
0x12b04: mov byte ptr [0x3db], dl
0x12b08: mov byte ptr [0x3a4], dl
0x12b0c: mov byte ptr [0x3ab], dl
0x12b10: mov byte ptr [0x3b1], dl
0x12b14: mov byte ptr [0x3be], dl
0x12b18: mov byte ptr [0xc5], dl
2018-12-17T22:36:40.485041904Z 64 PC: 12d08 | Write file or device (Write 783 bytes on handle 5)
2018-12-17T22:36:40.494825433Z 62 PC: 12c2d | Close file
2018-12-17T22:36:40.503761865Z 62 PC: 12b2d | Close file
2018-12-17T22:36:40.506130246Z 79 PC: 12c2d | Find next file
2018-12-17T22:36:40.508923825Z 67 PC: 12c2d | Get or set file attributes
2018-12-17T22:36:40.519577296Z 61 PC: 12c2d | Open file (Filename = 'PAH.COM')
2018-12-17T22:36:40.527233151Z 63 PC: 12c2d | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:36:40.531933914Z 66 PC: 12ab6 | Move file pointer
2018-12-17T22:36:40.533067265Z 66 PC: 12c2d | Move file pointer
2018-12-17T22:36:40.534536386Z 44 PC: 12acc | Get time 0x12acc: mov byte ptr [0x3da], dl
0x12ad0: mov byte ptr [0x3e2], dl
0x12ad4: mov byte ptr [0x3eb], dl
0x12ad8: mov byte ptr [0x3f8], dl
0x12adc: mov byte ptr [0x3fe], dl
0x12ae0: mov byte ptr [0x407], dl
0x12ae4: mov byte ptr [0x40d], dl
0x12ae8: mov byte ptr [0x3b7], dl
0x12aec: mov byte ptr [0x3cb], dl
0x12af0: mov byte ptr [0x3d3], dl
0x12af4: mov byte ptr [0x403], dl
0x12af8: mov byte ptr [0x3f3], dl
0x12afc: mov byte ptr [0x3ec], dl
0x12b00: mov byte ptr [0x3e3], dl
0x12b04: mov byte ptr [0x3db], dl
0x12b08: mov byte ptr [0x3a4], dl
0x12b0c: mov byte ptr [0x3ab], dl
0x12b10: mov byte ptr [0x3b1], dl
0x12b14: mov byte ptr [0x3be], dl
0x12b18: mov byte ptr [0xc5], dl
2018-12-17T22:36:40.537211631Z 64 PC: 12d08 | Write file or device (Write 783 bytes on handle 5)
2018-12-17T22:36:40.545903649Z 62 PC: 12c2d | Close file
2018-12-17T22:36:40.554948491Z 62 PC: 12b2d | Close file
2018-12-17T22:36:40.55664563Z 79 PC: 12c2d | Find next file
2018-12-17T22:36:40.55933913Z 67 PC: 12c2d | Get or set file attributes
2018-12-17T22:36:40.569571997Z 61 PC: 12c2d | Open file (Filename = 'TEST.COM')
2018-12-17T22:36:40.576713394Z 63 PC: 12c2d | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:36:40.579397366Z 62 PC: 12b2d | Close file
2018-12-17T22:36:40.581236283Z 79 PC: 12c2d | Find next file
2018-12-17T22:36:40.584394554Z 78 PC: 12b53 | Find first file
2018-12-17T22:36:40.591320257Z 53 PC: 12b5e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:36:40.592990875Z 37 PC: 12b6e | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:36:40.594606362Z 53 PC: 12c2d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:36:40.596198587Z 37 PC: 12c2d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:36:40.59752325Z 9 PC: 12c2d | Display string (Could not find end pointer)
2018-12-17T22:36:40.602399764Z 37 PC: 12ba1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:36:40.603540658Z 49 PC: 12c2d | Terminate and stay resident (Return code = '36' | Memory size = '65')