Sample viewer

vx.netlux.org/Virus.DOS.Vole.499

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:56.386525643Z 26 PC: 12a98 | Set disk transfer address
2018-12-17T22:43:56.388361614Z 37 PC: 12aa6 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:43:56.389927283Z 37 PC: 12aaa | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:43:56.391354469Z 78 PC: 12af6 | Find first file
2018-12-17T22:43:56.397660091Z 61 PC: 12bc7 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:43:56.404164876Z 63 PC: 12bd6 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:43:56.410406222Z 66 PC: 12be5 | Move file pointer
2018-12-17T22:43:56.412229381Z 66 PC: 12bf4 | Move file pointer
2018-12-17T22:43:56.414238075Z 64 PC: 12c00 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:43:56.416692403Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:43:56.418083051Z 44 PC: 12c10 | Get time 0x12c10: mov byte ptr [bp + 0x1f3], dl
0x12c14: call 0x12c2a
0x12c17: mov ah, 0x40
0x12c19: mov cx, 0x1f3
0x12c1c: lea dx, word ptr [bp + 6]
0x12c20: int 0x21
0x12c22: call 0x12c2a
0x12c25: mov ah, 0x3e
0x12c27: int 0x21
0x12c29: ret
0x12c2a: lea si, word ptr [bp + 0x33]
0x12c2e: mov cx, 0x1a1
0x12c31: xor byte ptr [si], 0
0x12c34: inc si
0x12c35: dec cx
0x12c36: jne 0x12c31
0x12c38: ret
0x12c39: add word ptr [bx], di
0x12c3b: aas
0x12c3c: aas
2018-12-17T22:43:56.420704793Z 64 PC: 12c22 | Write file or device (Write 499 bytes on handle 5)
2018-12-17T22:43:56.434352274Z 62 PC: 12c29 | Close file
2018-12-17T22:43:56.439634703Z 79 PC: 12af6 | Find next file
2018-12-17T22:43:56.441858285Z 61 PC: 12bc7 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:43:56.445879212Z 63 PC: 12bd6 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:43:56.450155589Z 66 PC: 12be5 | Move file pointer
2018-12-17T22:43:56.451579813Z 66 PC: 12bf4 | Move file pointer
2018-12-17T22:43:56.452636085Z 64 PC: 12c00 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:43:56.455154722Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:43:56.457306911Z 44 PC: 12c10 | Get time 0x12c10: mov byte ptr [bp + 0x1f3], dl
0x12c14: call 0x12c2a
0x12c17: mov ah, 0x40
0x12c19: mov cx, 0x1f3
0x12c1c: lea dx, word ptr [bp + 6]
0x12c20: int 0x21
0x12c22: call 0x12c2a
0x12c25: mov ah, 0x3e
0x12c27: int 0x21
0x12c29: ret
0x12c2a: lea si, word ptr [bp + 0x33]
0x12c2e: mov cx, 0x1a1
0x12c31: xor byte ptr [si], 0x3d
0x12c34: inc si
0x12c35: dec cx
0x12c36: jne 0x12c31
0x12c38: ret
0x12c39: add word ptr [bx], di
0x12c3b: aas
0x12c3c: aas
2018-12-17T22:43:56.45964768Z 64 PC: 12c22 | Write file or device (Write 499 bytes on handle 5)
2018-12-17T22:43:56.467543812Z 62 PC: 12c29 | Close file
2018-12-17T22:43:56.476797472Z 26 PC: 12b10 | Set disk transfer address
2018-12-17T22:43:56.477969071Z 9 PC: 12b1c | Display string (Could not find end pointer)
2018-12-17T22:43:56.48804339Z 9 PC: 12b31 | Display string (String= ' Inherit the Wind !!! ')