Sample viewer

vx.netlux.org/Virus.DOS.Lightning.2366

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:56:21.99764706Z 42 PC: 9f893 | Get date 0x9f893: add dl, dh
0x9f895: mov byte ptr [0x93e], dl
0x9f899: push cs
0x9f89a: pop es
0x9f89b: mov cx, 3
0x9f89e: call 0x9fa67
0x9f8a1: call 0x9fa73
0x9f8a4: add bp, 9
0x9f8a7: loop 0x9f89e
0x9f8a9: retf
0x9f8aa: add sp, 6
0x9f8ad: push ax
0x9f8ae: push bp
0x9f8af: xor bp, bp
0x9f8b1: call 0x9fa0d
0x9f8b4: cmp ah, 0x3e
0x9f8b7: jne 0x9f8c3
0x9f8b9: cmp bx, word ptr cs:[0x59b]
0x9f8be: jne 0x9f8c3
0x9f8c0: call 0xaf2d0
2018-12-17T21:56:22.001953598Z 99 PC: 9f8cf | Get DBCS lead byte table pointer
2018-12-17T21:56:22.003787855Z 68 PC: 9f8cf | I/O control for devices (Set for = '')
2018-12-17T21:56:22.005781458Z 68 PC: 9f8cf | I/O control for devices (Set for = '')
2018-12-17T21:56:22.008707899Z 68 PC: 9f8cf | I/O control for devices (Set for = '')
2018-12-17T21:56:22.011701486Z 68 PC: 9f8cf | I/O control for devices (Set for = 'bgtS3[r2W<t<u6u>>W')
2018-12-17T21:56:22.014696531Z 48 PC: 9f8cf | Get DOS version
2018-12-17T21:56:22.017732776Z 64 PC: 9f8cf | Write file or device (Write 23 bytes on handle 2)
2018-12-17T21:56:22.024120082Z 76 PC: 9f8cf | Terminate with return code (Return code = '4')
2018-12-17T21:56:22.028007664Z 77 PC: 9f8cf | Get program return code
2018-12-17T21:56:22.029826915Z 72 PC: 9f8cf | Allocate memory
2018-12-17T21:56:22.032191423Z 72 PC: 9f8cf | Allocate memory
2018-12-17T21:56:22.039108813Z 37 PC: 9f8cf | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T21:56:22.041018416Z 37 PC: 9f8cf | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T21:56:22.042968767Z 37 PC: 9f8cf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:56:22.047847634Z 44 PC: 9f6f7 | Get time 0x9f6f7: mov word ptr [0x4f2], cx
0x9f6fb: mov word ptr [0x4f4], dx
0x9f6ff: ret
0x9f700: push bx
0x9f701: push cx
0x9f702: push dx
0x9f703: push ax
0x9f704: call 0x9f71d
0x9f707: pop bx
0x9f708: mov cx, dx
0x9f70a: mul bx
0x9f70c: mov ax, cx
0x9f70e: mov cx, dx
0x9f710: mul bx
0x9f712: add ax, cx
0x9f714: adc dx, 0
0x9f717: mov ax, dx
0x9f719: pop dx
0x9f71a: pop cx
0x9f71b: pop bx
2018-12-17T21:56:22.050502697Z 87 PC: 9f351 | Get or set file date and time
2018-12-17T21:56:22.052251419Z 66 PC: 9f36c | Move file pointer
2018-12-17T21:56:22.055084511Z 63 PC: 9f376 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T21:56:22.057873519Z 66 PC: 9f386 | Move file pointer
2018-12-17T21:56:22.06035687Z 62 PC: 9f8cf | Close file
2018-12-17T21:56:22.063566468Z 62 PC: 9f8cf | Close file
2018-12-17T21:56:22.066281795Z 62 PC: 9f8cf | Close file
2018-12-17T21:56:22.068970712Z 62 PC: 9f8cf | Close file
2018-12-17T21:56:22.072145531Z 62 PC: 9f8cf | Close file
2018-12-17T21:56:22.078629437Z 62 PC: 9f8cf | Close file
2018-12-17T21:56:22.081770211Z 62 PC: 9f8cf | Close file
2018-12-17T21:56:22.086563834Z 62 PC: 9f8cf | Close file
2018-12-17T21:56:22.09131097Z 62 PC: 9f8cf | Close file
2018-12-17T21:56:22.093495793Z 62 PC: 9f8cf | Close file
2018-12-17T21:56:22.09612695Z 62 PC: 9f8cf | Close file
2018-12-17T21:56:22.098961818Z 62 PC: 9f8cf | Close file
2018-12-17T21:56:22.101309603Z 62 PC: 9f8cf | Close file
2018-12-17T21:56:22.10368744Z 62 PC: 9f8cf | Close file
2018-12-17T21:56:22.108138911Z 62 PC: 9f8cf | Close file
2018-12-17T21:56:22.112115037Z 99 PC: 9f8cf | Get DBCS lead byte table pointer
2018-12-17T21:56:22.113980948Z 56 PC: 9f8cf | Get or set country info
2018-12-17T21:56:22.117037731Z 64 PC: 9f8cf | Write file or device (Write 2 bytes on handle 1)
2018-12-17T21:56:22.122143574Z 25 PC: 9f8cf | Get default drive
2018-12-17T21:56:22.124444727Z 71 PC: 9f8cf | Get current directory
2018-12-17T21:56:22.141087429Z 64 PC: 9f8cf | Write file or device (Write 3 bytes on handle 1)
2018-12-17T21:56:22.145877545Z 2 PC: 9f8cf | Character output (Char = '3e')
2018-12-17T21:56:22.14873902Z 93 PC: 9f8cf | File sharing functions
2018-12-17T21:56:22.151360509Z 93 PC: 9f8cf | File sharing functions
2018-12-17T21:56:22.15474192Z 10 PC: 9f8cf | Buffered keyboard input
2018-12-17T21:56:36.973963392Z 0 PC: 0 | Program terminate
2018-12-17T21:56:38.3272319Z 0 PC: 0 | Program terminate
2018-12-17T21:56:38.430478005Z 64 PC: 9f8cf | Write file or device (Write 2 bytes on handle 1)
2018-12-17T21:56:38.436429982Z 41 PC: 9f8cf | Parse filename
2018-12-17T21:56:38.43856946Z 41 PC: 9f8cf | Parse filename
2018-12-17T21:56:38.440328615Z 41 PC: 9f8cf | Parse filename
2018-12-17T21:56:38.44405568Z 26 PC: 9f8cf | Set disk transfer address
2018-12-17T21:56:38.446137524Z 71 PC: 9f8cf | Get current directory
2018-12-17T21:56:38.454256276Z 78 PC: 9f8cf | Find first file
2018-12-17T21:56:38.464126863Z 47 PC: 9f8cf | Get disk transfer address
2018-12-17T21:56:38.466189798Z 71 PC: 9f8cf | Get current directory
2018-12-17T21:56:38.469500991Z 73 PC: 9f8cf | Release memory
2018-12-17T21:56:38.471361538Z 75 PC: 9f8cf | Execute program
2018-12-17T21:56:38.485940135Z 9 PC: 9f8cf | Display string (String= 'Hello, World! ')
2018-12-17T21:56:38.490003394Z 76 PC: 9f8cf | Terminate with return code (Return code = '36')