Sample viewer

vx.netlux.org/Virus.DOS.Lauren.652

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:38:55.919479366Z 26 PC: 12e5e | Set disk transfer address
2018-12-17T22:38:55.920602074Z 71 PC: 12e68 | Get current directory
2018-12-17T22:38:55.924954218Z 53 PC: 12e6d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:38:55.926289709Z 37 PC: 12e7f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:38:55.927580193Z 78 PC: 12e9b | Find first file
2018-12-17T22:38:55.935030631Z 67 PC: 12f7b | Get or set file attributes
2018-12-17T22:38:55.941129781Z 67 PC: 12f7b | Get or set file attributes
2018-12-17T22:38:56.324504227Z 61 PC: 12ee9 | Open file (Filename = ' Access denied  Memory allocation error& Cannot load COMMAND, system halted ! Cannot start COMMAND, exiting . Top level process aborted, cannot continue  � ')
2018-12-17T22:38:56.333531189Z 63 PC: 12ef5 | Read file or device (Read 7 bytes on handle 5)
2018-12-17T22:38:56.340780977Z 66 PC: 12f72 | Move file pointer
2018-12-17T22:38:56.342367456Z 64 PC: 12f33 | Write file or device (Write 652 bytes on handle 5)
2018-12-17T22:38:56.353765429Z 66 PC: 12f72 | Move file pointer
2018-12-17T22:38:56.355416055Z 64 PC: 12f43 | Write file or device (Write 7 bytes on handle 5)
2018-12-17T22:38:56.363201926Z 87 PC: 12f57 | Get or set file date and time
2018-12-17T22:38:56.366279128Z 62 PC: 12f5b | Close file
2018-12-17T22:38:56.375577878Z 67 PC: 12f7b | Get or set file attributes
2018-12-17T22:38:56.387337546Z 79 PC: 12e9b | Find next file
2018-12-17T22:38:56.390882354Z 67 PC: 12f7b | Get or set file attributes
2018-12-17T22:38:56.399236136Z 67 PC: 12f7b | Get or set file attributes
2018-12-17T22:38:56.410526886Z 61 PC: 12ee9 | Open file (Filename = ' Access denied  Memory allocation error& Cannot load COMMAND, system halted ! Cannot start COMMAND, exiting . Top level process aborted, cannot continue  � ')
2018-12-17T22:38:56.424242369Z 63 PC: 12ef5 | Read file or device (Read 7 bytes on handle 5)
2018-12-17T22:38:56.433068256Z 66 PC: 12f72 | Move file pointer
2018-12-17T22:38:56.435143935Z 64 PC: 12f33 | Write file or device (Write 652 bytes on handle 5)
2018-12-17T22:38:56.44447009Z 66 PC: 12f72 | Move file pointer
2018-12-17T22:38:56.447485421Z 64 PC: 12f43 | Write file or device (Write 7 bytes on handle 5)
2018-12-17T22:38:56.456173811Z 87 PC: 12f57 | Get or set file date and time
2018-12-17T22:38:56.458314858Z 62 PC: 12f5b | Close file
2018-12-17T22:38:56.468343106Z 67 PC: 12f7b | Get or set file attributes
2018-12-17T22:38:56.480169726Z 79 PC: 12e9b | Find next file
2018-12-17T22:38:56.483638346Z 67 PC: 12f7b | Get or set file attributes
2018-12-17T22:38:56.490953211Z 67 PC: 12f7b | Get or set file attributes
2018-12-17T22:38:56.50278138Z 61 PC: 12ee9 | Open file (Filename = ' Access denied  Memory allocation error& Cannot load COMMAND, system halted ! Cannot start COMMAND, exiting . Top level process aborted, cannot continue  � ')
2018-12-17T22:38:56.510522148Z 63 PC: 12ef5 | Read file or device (Read 7 bytes on handle 5)
2018-12-17T22:38:56.517073286Z 66 PC: 12f72 | Move file pointer
2018-12-17T22:38:56.522969305Z 64 PC: 12f33 | Write file or device (Write 652 bytes on handle 5)
2018-12-17T22:38:56.533660696Z 66 PC: 12f72 | Move file pointer
2018-12-17T22:38:56.535273673Z 64 PC: 12f43 | Write file or device (Write 7 bytes on handle 5)
2018-12-17T22:38:56.544192712Z 87 PC: 12f57 | Get or set file date and time
2018-12-17T22:38:56.546396877Z 62 PC: 12f5b | Close file
2018-12-17T22:38:56.555877102Z 67 PC: 12f7b | Get or set file attributes
2018-12-17T22:38:56.569410008Z 37 PC: 12f8d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:38:56.570941425Z 26 PC: 12f98 | Set disk transfer address
2018-12-17T22:38:56.572331729Z 59 PC: 12fa0 | Change current directory
2018-12-17T22:38:56.577524005Z 42 PC: 12fa4 | Get date 0x12fa4: cmp dx, 0x520
0x12fa8: jne 0x12fb9
0x12faa: mov ax, 3
0x12fad: int 0x10
0x12faf: mov ah, 9
0x12fb1: lea dx, word ptr [bp + 0x301]
0x12fb5: int 0x21
0x12fb7: jmp 0x12fb7
0x12fb9: cmp byte ptr ds:[bp + 0x37a], 1
0x12fc0: je 0x12fcd
0x12fc2: mov bx, 0xfeff
0x12fc5: mov ax, bx
0x12fc7: xor bx, bx
0x12fc9: not ax
0x12fcb: jmp ax
0x12fcd: mov word ptr cs:[0x2ef], 0x9090
0x12fd4: mov word ptr cs:[0x2f1], 0x9090
0x12fdb: mov word ptr cs:[0x2f3], 0x20cd
0x12fe2: mov dx, word ptr cs:[bp + 0x3d3]
0x12fe7: mov ax, word ptr cs:[bp + 0x3d5]