Sample viewer

vx.netlux.org/Virus.DOS.CyberTech.Caco.668.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:39:21.665572251Z 48 PC: 12a99 | Get DOS version
2018-12-17T22:39:21.667794719Z 26 PC: 12aa7 | Set disk transfer address
2018-12-17T22:39:21.67039616Z 78 PC: 12ab1 | Find first file
2018-12-17T22:39:21.67713152Z 67 PC: 12abe | Get or set file attributes
2018-12-17T22:39:21.683209952Z 67 PC: 12ac6 | Get or set file attributes
2018-12-17T22:39:21.700673915Z 61 PC: 12acb | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:39:21.70762356Z 87 PC: 12ad1 | Get or set file date and time
2018-12-17T22:39:21.709251807Z 63 PC: 12ade | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:39:21.716887734Z 66 PC: 12b04 | Move file pointer
2018-12-17T22:39:21.71962949Z 66 PC: 12ba3 | Move file pointer
2018-12-17T22:39:21.722222535Z 63 PC: 12bad | Read file or device (Read 52 bytes on handle 5)
2018-12-17T22:39:21.72617963Z 66 PC: 12b04 | Move file pointer
2018-12-17T22:39:21.728714777Z 44 PC: 12bfa | Get time 0x12bfa: cmp dl, 0
0x12bfd: jne 0x12c01
0x12bff: jmp 0x12bf6
0x12c01: mov byte ptr cs:[bp + 0x18], dl
0x12c06: lea si, word ptr [bp + 4]
0x12c0a: mov di, 0xfb00
0x12c0d: mov cx, 0x18
0x12c10: rep movsb byte ptr es:[di], byte ptr [si]
0x12c12: lea si, word ptr [bp + 0x1c]
0x12c16: mov cx, 0x284
0x12c19: lodsb al, byte ptr [si]
0x12c1a: xor al, dl
0x12c1c: stosb byte ptr es:[di], al
0x12c1d: loop 0x12c19
0x12c1f: mov ah, 0x40
0x12c21: mov dx, 0xfb00
0x12c24: mov cx, 0x29c
0x12c27: int 0x21
0x12c29: mov ax, 0x4200
0x12c2c: call 0x22afe
2018-12-17T22:39:21.731183609Z 64 PC: 12c29 | Write file or device (Write 668 bytes on handle 5)
2018-12-17T22:39:21.740486356Z 66 PC: 12b04 | Move file pointer
2018-12-17T22:39:21.74244202Z 64 PC: 12c3a | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:39:21.750055014Z 87 PC: 12c89 | Get or set file date and time
2018-12-17T22:39:21.751961516Z 62 PC: 12c8d | Close file
2018-12-17T22:39:21.770140847Z 67 PC: 12c96 | Get or set file attributes
2018-12-17T22:39:21.775543355Z 26 PC: 12c44 | Set disk transfer address