Sample viewer

vx.netlux.org/Virus.DOS.Kondrat.666

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:33.753307285Z 37 PC: 13e7c | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:45:33.755097595Z 37 PC: 13e80 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:45:33.756451405Z 42 PC: 13e84 | Get date 0x13e84: mov al, dl
0x13e86: cwde
0x13e87: cmp ax, 0xd
0x13e8a: je 0x13ea0
0x13e8c: cmp ax, 6
0x13e8f: jne 0x13ebc
0x13e91: mov ah, 0x2a
0x13e93: int 0x21
0x13e95: mov al, dh
0x13e97: cwde
0x13e98: cmp ax, 0xa
0x13e9b: jne 0x13ebc
0x13e9d: jmp 0x13ea8
0x13e9f: nop
0x13ea0: mov ax, 0x1010
0x13ea3: out 0x70, ax
0x13ea5: jmp 0x13ebc
0x13ea7: nop
0x13ea8: mov ax, 0x301
0x13eab: xor dx, dx
2018-12-17T22:45:33.758933899Z 26 PC: 13ed1 | Set disk transfer address
2018-12-17T22:45:33.760764925Z 78 PC: 13f19 | Find first file
2018-12-17T22:45:33.766792439Z 61 PC: 13f27 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:45:33.773304596Z 63 PC: 13f36 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:45:33.780987888Z 66 PC: 13f50 | Move file pointer
2018-12-17T22:45:33.782670324Z 64 PC: 13f65 | Write file or device (Write 5 bytes on handle 5)
2018-12-17T22:45:33.78593943Z 64 PC: 13e60 | Write file or device (Write 661 bytes on handle 5)
2018-12-17T22:45:33.800610246Z 66 PC: 13f89 | Move file pointer
2018-12-17T22:45:33.802944005Z 64 PC: 13fa1 | Write file or device (Write 5 bytes on handle 5)
2018-12-17T22:45:33.813633775Z 62 PC: 13f05 | Close file
2018-12-17T22:45:33.822317342Z 79 PC: 13f19 | Find next file
2018-12-17T22:45:33.826321873Z 61 PC: 13f27 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:45:33.833447697Z 63 PC: 13f36 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:45:33.840295645Z 66 PC: 13f50 | Move file pointer
2018-12-17T22:45:33.844421086Z 64 PC: 13f65 | Write file or device (Write 5 bytes on handle 5)
2018-12-17T22:45:33.847714141Z 64 PC: 13e60 | Write file or device (Write 661 bytes on handle 5)
2018-12-17T22:45:33.856163086Z 66 PC: 13f89 | Move file pointer
2018-12-17T22:45:33.858174165Z 64 PC: 13fa1 | Write file or device (Write 5 bytes on handle 5)
2018-12-17T22:45:33.864707642Z 62 PC: 13f05 | Close file
2018-12-17T22:45:33.87292271Z 26 PC: 13ee7 | Set disk transfer address
2018-12-17T22:45:33.876294367Z 9 PC: 12a85 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ')
2018-12-17T22:45:33.882112513Z 0 PC: 12a89 | Program terminate