Sample viewer

vx.netlux.org/Virus.DOS.Slovakia.1351

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:38:57.645851873Z 44 PC: 12d71 | Get time 0x12d71: ret
0x12d72: adc ch, 0xe8
0x12d75: pop sp
0x12d76: add al, ch
0x12d78: jmp 0x12d79
0x12d7a: mov si, 0xd580
0x12d7d: mov si, di
0x12d7f: lodsb al, byte ptr [si]
0x12d80: xor al, ah
0x12d82: add ah, 0x11
0x12d85: stosb byte ptr es:[di], al
0x12d86: loop 0x12d7f
0x12d88: ret
0x12d89: adc ch, 0x8b
0x12d8c: cli
0x12d8d: mov ah, byte ptr [di - 0x303]
0x12d91: add di, 0xfafe
0x12d95: mov cx, 0x3af
0x12d98: mov cx, 0x1b0
0x12d9b: call 0x22d7a
2018-12-17T22:38:57.648855722Z 37 PC: 12d71 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:38:57.649869923Z 47 PC: 12d71 | Get disk transfer address
2018-12-17T22:38:57.650946459Z 26 PC: 12d71 | Set disk transfer address
2018-12-17T22:38:57.652542013Z 71 PC: 12d71 | Get current directory
2018-12-17T22:38:57.665668511Z 78 PC: 12d71 | Find first file
2018-12-17T22:38:57.673990042Z 67 PC: 12d71 | Get or set file attributes
2018-12-17T22:38:57.680001301Z 67 PC: 12d71 | Get or set file attributes
2018-12-17T22:38:59.028744876Z 61 PC: 12d71 | Open file (Filename = 'C:\DOS\EDIT.COM')
2018-12-17T22:38:59.040634125Z 87 PC: 12d71 | Get or set file date and time
2018-12-17T22:38:59.043295085Z 63 PC: 12d71 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:38:59.049125744Z 66 PC: 12d71 | Move file pointer
2018-12-17T22:38:59.050808322Z 44 PC: 12d71 | Get time 0x12d71: ret
0x12d72: adc ch, 0xe8
0x12d75: pop sp
0x12d76: add al, ch
0x12d78: jmp 0x12d79
0x12d7a: mov si, 0xd580
0x12d7d: mov si, di
0x12d7f: lodsb al, byte ptr [si]
0x12d80: xor al, ah
0x12d82: add ah, 0x11
0x12d85: stosb byte ptr es:[di], al
0x12d86: loop 0x12d7f
0x12d88: ret
0x12d89: adc ch, 0x8b
0x12d8c: cli
0x12d8d: mov ah, byte ptr [di - 0x303]
0x12d91: add di, 0xfafe
0x12d95: mov cx, 0x3af
0x12d98: mov cx, 0x1b0
0x12d9b: call 0x22d7a
2018-12-17T22:38:59.053021658Z 64 PC: 12d71 | Write file or device (Write 120 bytes on handle 5)
2018-12-17T22:38:59.060591834Z 44 PC: 12d71 | Get time 0x12d71: ret
0x12d72: adc ch, 0xe8
0x12d75: pop sp
0x12d76: add al, ch
0x12d78: jmp 0x12d79
0x12d7a: mov si, 0xd580
0x12d7d: mov si, di
0x12d7f: lodsb al, byte ptr [si]
0x12d80: xor al, ah
0x12d82: add ah, 0x11
0x12d85: stosb byte ptr es:[di], al
0x12d86: loop 0x12d7f
0x12d88: ret
0x12d89: adc ch, 0x8b
0x12d8c: cli
0x12d8d: mov ah, byte ptr [di - 0x303]
0x12d91: add di, 0xfafe
0x12d95: mov cx, 0x3af
0x12d98: mov cx, 0x1b0
0x12d9b: call 0x22d7a
2018-12-17T22:38:59.062850788Z 64 PC: 12d71 | Write file or device (Write 1384 bytes on handle 5)
2018-12-17T22:38:59.071322059Z 66 PC: 12d71 | Move file pointer
2018-12-17T22:38:59.073950328Z 64 PC: 12d71 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:38:59.079714964Z 87 PC: 12d71 | Get or set file date and time
2018-12-17T22:38:59.081206238Z 62 PC: 12d71 | Close file
2018-12-17T22:38:59.088009038Z 67 PC: 12d71 | Get or set file attributes
2018-12-17T22:38:59.097423263Z 26 PC: 12d71 | Set disk transfer address
2018-12-17T22:38:59.098516658Z 37 PC: 12d71 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:38:59.100348975Z 42 PC: 12d71 | Get date 0x12d71: ret
0x12d72: adc ch, 0xe8
0x12d75: pop sp
0x12d76: add al, ch
0x12d78: jmp 0x12d79
0x12d7a: mov si, 0xd580
0x12d7d: mov si, di
0x12d7f: lodsb al, byte ptr [si]
0x12d80: xor al, ah
0x12d82: add ah, 0x11
0x12d85: stosb byte ptr es:[di], al
0x12d86: loop 0x12d7f
0x12d88: ret
0x12d89: adc ch, 0x8b
0x12d8c: cli
0x12d8d: mov ah, byte ptr [di - 0x303]
0x12d91: add di, 0xfafe
0x12d95: mov cx, 0x3af
0x12d98: mov cx, 0x1b0
0x12d9b: call 0x22d7a
2018-12-17T22:38:59.102526081Z 44 PC: 12d71 | Get time 0x12d71: ret
0x12d72: adc ch, 0xe8
0x12d75: pop sp
0x12d76: add al, ch
0x12d78: jmp 0x12d79
0x12d7a: mov si, 0xd580
0x12d7d: mov si, di
0x12d7f: lodsb al, byte ptr [si]
0x12d80: xor al, ah
0x12d82: add ah, 0x11
0x12d85: stosb byte ptr es:[di], al
0x12d86: loop 0x12d7f
0x12d88: ret
0x12d89: adc ch, 0x8b
0x12d8c: cli
0x12d8d: mov ah, byte ptr [di - 0x303]
0x12d91: add di, 0xfafe
0x12d95: mov cx, 0x3af
0x12d98: mov cx, 0x1b0
0x12d9b: call 0x22d7a
2018-12-17T22:38:59.104910763Z 76 PC: 12a44 | Terminate with return code (Return code = '0')