Sample viewer

vx.netlux.org/Virus.DOS.LionKing.3531

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:14.534454302Z 82 PC: 13c51 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:45:14.536107252Z 75 PC: 13c86 | Execute program
2018-12-17T22:45:14.537321438Z 53 PC: 9e54c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:14.538322208Z 37 PC: 9e55c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:14.540006921Z 42 PC: 9e7b5 | Get date 0x9e7b5: ret
0x9e7b6: push es
0x9e7b7: push bx
0x9e7b8: push ax
0x9e7b9: mov ah, 0x2f
0x9e7bb: call 0xae7ae
0x9e7be: pop ax
0x9e7bf: call 0xae7ae
0x9e7c2: pushf
0x9e7c3: cmp di, 0x16
0x9e7c6: jne 0x9e7cc
0x9e7c8: jb 0x9e80a
0x9e7ca: jmp 0x9e7d0
0x9e7cc: cmp al, 0xff
0x9e7ce: je 0x9e80a
0x9e7d0: push ax
0x9e7d1: push ds
0x9e7d2: push dx
0x9e7d3: push cx
0x9e7d4: push es
2018-12-17T22:45:14.541763517Z 98 PC: 9e7b5 | Get current PSP
2018-12-17T22:45:14.543160701Z 67 PC: 9e7b5 | Get or set file attributes
2018-12-17T22:45:14.548614859Z 61 PC: 9e7b5 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:45:14.554744621Z 66 PC: 9e7b5 | Move file pointer
2018-12-17T22:45:14.556170782Z 66 PC: 9e7b5 | Move file pointer
2018-12-17T22:45:14.557670733Z 87 PC: 9e7b5 | Get or set file date and time
2018-12-17T22:45:14.563282848Z 63 PC: 9e7b5 | Read file or device (Read 100 bytes on handle 5)
2018-12-17T22:45:14.565991265Z 66 PC: 9e7b5 | Move file pointer
2018-12-17T22:45:14.567534765Z 66 PC: 9e7b5 | Move file pointer
2018-12-17T22:45:14.569513635Z 44 PC: 9e7b5 | Get time 0x9e7b5: ret
0x9e7b6: push es
0x9e7b7: push bx
0x9e7b8: push ax
0x9e7b9: mov ah, 0x2f
0x9e7bb: call 0xae7ae
0x9e7be: pop ax
0x9e7bf: call 0xae7ae
0x9e7c2: pushf
0x9e7c3: cmp di, 0x16
0x9e7c6: jne 0x9e7cc
0x9e7c8: jb 0x9e80a
0x9e7ca: jmp 0x9e7d0
0x9e7cc: cmp al, 0xff
0x9e7ce: je 0x9e80a
0x9e7d0: push ax
0x9e7d1: push ds
0x9e7d2: push dx
0x9e7d3: push cx
0x9e7d4: push es
2018-12-17T22:45:14.572576942Z 64 PC: 9f5eb | Write file or device (Write 3531 bytes on handle 5)
2018-12-17T22:45:15.176115033Z 66 PC: 9e7b5 | Move file pointer
2018-12-17T22:45:15.178516859Z 64 PC: 9e7b5 | Write file or device (Write 32 bytes on handle 5)
2018-12-17T22:45:15.181227462Z 66 PC: 9e7b5 | Move file pointer
2018-12-17T22:45:15.182722457Z 87 PC: 9e7b5 | Get or set file date and time
2018-12-17T22:45:15.1855189Z 62 PC: 9e7b5 | Close file
2018-12-17T22:45:15.192631934Z 67 PC: 9e7b5 | Get or set file attributes
2018-12-17T22:45:15.202433591Z 44 PC: 12a45 | Get time 0x12a45: add byte ptr [bx + si], al
0x12a47: add byte ptr [bx + si], al
0x12a49: add byte ptr [bx + si], al
0x12a4b: add byte ptr [bx + si], al
0x12a4d: add byte ptr [bx + si], al
0x12a4f: add byte ptr [bx + si], al
0x12a51: add byte ptr [bx + si], al
0x12a53: add byte ptr [bx + si], al
0x12a55: add byte ptr [bx + si], al
0x12a57: add byte ptr [bx + si], al
0x12a59: add byte ptr [bx + si], al
0x12a5b: add byte ptr [bx + si], al
0x12a5d: add byte ptr [bx + si], al
0x12a5f: add byte ptr [bx + si], al
0x12a61: add byte ptr [bx + si], al
0x12a63: add byte ptr [bx + si], al
0x12a65: add byte ptr [bx + si], al
0x12a67: add byte ptr [bx + si], al
0x12a69: add byte ptr [bx + si], al
0x12a6b: add byte ptr [bx + si], al
2018-12-17T22:45:15.214568525Z 162 PC: 13c51 | UNKNOWN!