Sample viewer

vx.netlux.org/Virus.DOS.VCC.Thespian.401

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:42:15.811910106Z 26 PC: 12a64 | Set disk transfer address
2018-12-17T22:42:15.813528956Z 37 PC: 12a6f | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:42:15.816417101Z 37 PC: 12a73 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:42:15.817967092Z 78 PC: 12aba | Find first file
2018-12-17T22:42:15.825231917Z 61 PC: 12b65 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:42:15.833106427Z 63 PC: 12b74 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:42:15.841206641Z 66 PC: 12b83 | Move file pointer
2018-12-17T22:42:15.843196297Z 66 PC: 12b92 | Move file pointer
2018-12-17T22:42:15.845701482Z 64 PC: 12b9e | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:42:15.848827494Z 66 PC: 12baa | Move file pointer
2018-12-17T22:42:15.850591337Z 44 PC: 12bae | Get time 0x12bae: mov byte ptr [bp + 0x191], dl
0x12bb2: call 0x12bc8
0x12bb5: mov ah, 0x40
0x12bb7: mov cx, 0x191
0x12bba: lea dx, word ptr [bp + 6]
0x12bbe: int 0x21
0x12bc0: call 0x12bc8
0x12bc3: mov ah, 0x3e
0x12bc5: int 0x21
0x12bc7: ret
0x12bc8: lea si, word ptr [bp + 0x11]
0x12bcc: mov cx, 0x161
0x12bcf: xor byte ptr [si], 0
0x12bd2: inc si
0x12bd3: dec cx
0x12bd4: jne 0x12bcf
0x12bd6: ret
0x12bd7: add word ptr [bx], di
0x12bd9: aas
0x12bda: aas
2018-12-17T22:42:15.854079127Z 64 PC: 12bc0 | Write file or device (Write 401 bytes on handle 5)
2018-12-17T22:42:15.869775378Z 62 PC: 12bc7 | Close file
2018-12-17T22:42:15.878256437Z 79 PC: 12aba | Find next file
2018-12-17T22:42:15.8822619Z 61 PC: 12b65 | Open file (Filename = 'PRINT.S')
2018-12-17T22:42:15.888058557Z 63 PC: 12b74 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:42:15.894439281Z 66 PC: 12b83 | Move file pointer
2018-12-17T22:42:15.896063532Z 66 PC: 12b92 | Move file pointer
2018-12-17T22:42:15.897613784Z 64 PC: 12b9e | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:42:15.899724548Z 66 PC: 12baa | Move file pointer
2018-12-17T22:42:15.900903973Z 44 PC: 12bae | Get time 0x12bae: mov byte ptr [bp + 0x191], dl
0x12bb2: call 0x12bc8
0x12bb5: mov ah, 0x40
0x12bb7: mov cx, 0x191
0x12bba: lea dx, word ptr [bp + 6]
0x12bbe: int 0x21
0x12bc0: call 0x12bc8
0x12bc3: mov ah, 0x3e
0x12bc5: int 0x21
0x12bc7: ret
0x12bc8: lea si, word ptr [bp + 0x11]
0x12bcc: mov cx, 0x161
0x12bcf: xor byte ptr [si], 0x3d
0x12bd2: inc si
0x12bd3: dec cx
0x12bd4: jne 0x12bcf
0x12bd6: ret
0x12bd7: add word ptr [bx], di
0x12bd9: aas
0x12bda: aas
2018-12-17T22:42:15.903386756Z 64 PC: 12bc0 | Write file or device (Write 401 bytes on handle 5)
2018-12-17T22:42:15.905645318Z 62 PC: 12bc7 | Close file
2018-12-17T22:42:15.911616844Z 79 PC: 12aba | Find next file
2018-12-17T22:42:15.914471566Z 61 PC: 12b65 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:42:15.920179676Z 63 PC: 12b74 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:42:15.927365493Z 66 PC: 12b83 | Move file pointer
2018-12-17T22:42:15.930301527Z 66 PC: 12b92 | Move file pointer
2018-12-17T22:42:15.932715882Z 64 PC: 12b9e | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:42:15.936020198Z 66 PC: 12baa | Move file pointer
2018-12-17T22:42:15.938644587Z 44 PC: 12bae | Get time 0x12bae: mov byte ptr [bp + 0x191], dl
0x12bb2: call 0x12bc8
0x12bb5: mov ah, 0x40
0x12bb7: mov cx, 0x191
0x12bba: lea dx, word ptr [bp + 6]
0x12bbe: int 0x21
0x12bc0: call 0x12bc8
0x12bc3: mov ah, 0x3e
0x12bc5: int 0x21
0x12bc7: ret
0x12bc8: lea si, word ptr [bp + 0x11]
0x12bcc: mov cx, 0x161
0x12bcf: xor byte ptr [si], 0x42
0x12bd2: inc si
0x12bd3: dec cx
0x12bd4: jne 0x12bcf
0x12bd6: ret
0x12bd7: add word ptr [bx], di
0x12bd9: aas
0x12bda: aas
2018-12-17T22:42:15.941225464Z 64 PC: 12bc0 | Write file or device (Write 401 bytes on handle 5)
2018-12-17T22:42:15.944311771Z 62 PC: 12bc7 | Close file
2018-12-17T22:42:15.954879309Z 79 PC: 12aba | Find next file
2018-12-17T22:42:15.958126759Z 61 PC: 12b65 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:42:15.965123199Z 63 PC: 12b74 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:42:15.973130068Z 66 PC: 12b83 | Move file pointer
2018-12-17T22:42:15.974996032Z 66 PC: 12b92 | Move file pointer
2018-12-17T22:42:15.976828904Z 64 PC: 12b9e | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:42:15.98023388Z 66 PC: 12baa | Move file pointer
2018-12-17T22:42:15.982710942Z 44 PC: 12bae | Get time 0x12bae: mov byte ptr [bp + 0x191], dl
0x12bb2: call 0x12bc8
0x12bb5: mov ah, 0x40
0x12bb7: mov cx, 0x191
0x12bba: lea dx, word ptr [bp + 6]
0x12bbe: int 0x21
0x12bc0: call 0x12bc8
0x12bc3: mov ah, 0x3e
0x12bc5: int 0x21
0x12bc7: ret
0x12bc8: lea si, word ptr [bp + 0x11]
0x12bcc: mov cx, 0x161
0x12bcf: xor byte ptr [si], 0x42
0x12bd2: inc si
0x12bd3: dec cx
0x12bd4: jne 0x12bcf
0x12bd6: ret
0x12bd7: add word ptr [bx], di
0x12bd9: aas
0x12bda: aas
2018-12-17T22:42:15.985096142Z 64 PC: 12bc0 | Write file or device (Write 401 bytes on handle 5)
2018-12-17T22:42:15.988052394Z 62 PC: 12bc7 | Close file
2018-12-17T22:42:15.996284035Z 79 PC: 12aba | Find next file
2018-12-17T22:42:15.999139378Z 61 PC: 12b65 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:42:16.005821558Z 63 PC: 12b74 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:42:16.013154912Z 66 PC: 12b83 | Move file pointer
2018-12-17T22:42:16.014857049Z 66 PC: 12b92 | Move file pointer
2018-12-17T22:42:16.016443738Z 64 PC: 12b9e | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:42:16.019971174Z 66 PC: 12baa | Move file pointer
2018-12-17T22:42:16.021563114Z 44 PC: 12bae | Get time 0x12bae: mov byte ptr [bp + 0x191], dl
0x12bb2: call 0x12bc8
0x12bb5: mov ah, 0x40
0x12bb7: mov cx, 0x191
0x12bba: lea dx, word ptr [bp + 6]
0x12bbe: int 0x21
0x12bc0: call 0x12bc8
0x12bc3: mov ah, 0x3e
0x12bc5: int 0x21
0x12bc7: ret
0x12bc8: lea si, word ptr [bp + 0x11]
0x12bcc: mov cx, 0x161
0x12bcf: xor byte ptr [si], 0x48
0x12bd2: inc si
0x12bd3: dec cx
0x12bd4: jne 0x12bcf
0x12bd6: ret
0x12bd7: add word ptr [bx], di
0x12bd9: aas
0x12bda: aas
2018-12-17T22:42:16.023947903Z 64 PC: 12bc0 | Write file or device (Write 401 bytes on handle 5)
2018-12-17T22:42:16.027493011Z 62 PC: 12bc7 | Close file
2018-12-17T22:42:16.035959172Z 79 PC: 12aba | Find next file
2018-12-17T22:42:16.03913637Z 61 PC: 12b65 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:42:16.048243324Z 63 PC: 12b74 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:42:16.054899105Z 66 PC: 12b83 | Move file pointer
2018-12-17T22:42:16.05652057Z 66 PC: 12b92 | Move file pointer
2018-12-17T22:42:16.059205463Z 64 PC: 12b9e | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:42:16.062030279Z 66 PC: 12baa | Move file pointer
2018-12-17T22:42:16.06357514Z 44 PC: 12bae | Get time 0x12bae: mov byte ptr [bp + 0x191], dl
0x12bb2: call 0x12bc8
0x12bb5: mov ah, 0x40
0x12bb7: mov cx, 0x191
0x12bba: lea dx, word ptr [bp + 6]
0x12bbe: int 0x21
0x12bc0: call 0x12bc8
0x12bc3: mov ah, 0x3e
0x12bc5: int 0x21
0x12bc7: ret
0x12bc8: lea si, word ptr [bp + 0x11]
0x12bcc: mov cx, 0x161
0x12bcf: xor byte ptr [si], 0x48
0x12bd2: inc si
0x12bd3: dec cx
0x12bd4: jne 0x12bcf
0x12bd6: ret
0x12bd7: add word ptr [bx], di
0x12bd9: aas
0x12bda: aas
2018-12-17T22:42:16.06601913Z 64 PC: 12bc0 | Write file or device (Write 401 bytes on handle 5)
2018-12-17T22:42:16.069207499Z 62 PC: 12bc7 | Close file
2018-12-17T22:42:16.077085014Z 79 PC: 12aba | Find next file
2018-12-17T22:42:16.079815924Z 61 PC: 12b65 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:42:16.087571901Z 63 PC: 12b74 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:42:16.094201462Z 66 PC: 12b83 | Move file pointer
2018-12-17T22:42:16.095779777Z 66 PC: 12b92 | Move file pointer
2018-12-17T22:42:16.098280734Z 64 PC: 12b9e | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:42:16.101526871Z 66 PC: 12baa | Move file pointer
2018-12-17T22:42:16.103243665Z 44 PC: 12bae | Get time 0x12bae: mov byte ptr [bp + 0x191], dl
0x12bb2: call 0x12bc8
0x12bb5: mov ah, 0x40
0x12bb7: mov cx, 0x191
0x12bba: lea dx, word ptr [bp + 6]
0x12bbe: int 0x21
0x12bc0: call 0x12bc8
0x12bc3: mov ah, 0x3e
0x12bc5: int 0x21
0x12bc7: ret
0x12bc8: lea si, word ptr [bp + 0x11]
0x12bcc: mov cx, 0x161
0x12bcf: xor byte ptr [si], 0x4d
0x12bd2: inc si
0x12bd3: dec cx
0x12bd4: jne 0x12bcf
0x12bd6: ret
0x12bd7: add word ptr [bx], di
0x12bd9: aas
0x12bda: aas
2018-12-17T22:42:16.109979306Z 64 PC: 12bc0 | Write file or device (Write 401 bytes on handle 5)
2018-12-17T22:42:16.119099525Z 62 PC: 12bc7 | Close file
2018-12-17T22:42:16.12776438Z 79 PC: 12aba | Find next file
2018-12-17T22:42:16.13149686Z 61 PC: 12b65 | Open file (Filename = 'PAH.COM')
2018-12-17T22:42:16.138620309Z 63 PC: 12b74 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:42:16.145503227Z 66 PC: 12b83 | Move file pointer
2018-12-17T22:42:16.147628398Z 66 PC: 12b92 | Move file pointer
2018-12-17T22:42:16.149751395Z 64 PC: 12b9e | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:42:16.152674425Z 66 PC: 12baa | Move file pointer
2018-12-17T22:42:16.154285732Z 44 PC: 12bae | Get time 0x12bae: mov byte ptr [bp + 0x191], dl
0x12bb2: call 0x12bc8
0x12bb5: mov ah, 0x40
0x12bb7: mov cx, 0x191
0x12bba: lea dx, word ptr [bp + 6]
0x12bbe: int 0x21
0x12bc0: call 0x12bc8
0x12bc3: mov ah, 0x3e
0x12bc5: int 0x21
0x12bc7: ret
0x12bc8: lea si, word ptr [bp + 0x11]
0x12bcc: mov cx, 0x161
0x12bcf: xor byte ptr [si], 0x4d
0x12bd2: inc si
0x12bd3: dec cx
0x12bd4: jne 0x12bcf
0x12bd6: ret
0x12bd7: add word ptr [bx], di
0x12bd9: aas
0x12bda: aas
2018-12-17T22:42:16.157393078Z 64 PC: 12bc0 | Write file or device (Write 401 bytes on handle 5)
2018-12-17T22:42:16.160653612Z 62 PC: 12bc7 | Close file
2018-12-17T22:42:16.169100036Z 79 PC: 12aba | Find next file
2018-12-17T22:42:16.173132529Z 61 PC: 12b65 | Open file (Filename = 'TEST.COM')
2018-12-17T22:42:16.18018732Z 63 PC: 12b74 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:42:16.183109598Z 62 PC: 12bc7 | Close file
2018-12-17T22:42:16.186657883Z 79 PC: 12aba | Find next file
2018-12-17T22:42:16.189230895Z 26 PC: 12aca | Set disk transfer address
2018-12-17T22:42:16.190899239Z 9 PC: 12adc | Display string (String= ' The Truth IS Out There! ')