Sample viewer

vx.netlux.org/Virus.DOS.VCC.Alert.736

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:09.143776294Z 26 PC: 12a6a | Set disk transfer address
2018-12-17T22:46:09.144889144Z 37 PC: 12a78 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:46:09.146525036Z 37 PC: 12a7c | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:46:09.147620303Z 78 PC: 12ac7 | Find first file
2018-12-17T22:46:09.152608913Z 61 PC: 12cb4 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:46:09.158105245Z 63 PC: 12cc3 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:46:09.163176129Z 66 PC: 12cd2 | Move file pointer
2018-12-17T22:46:09.164446746Z 66 PC: 12ce1 | Move file pointer
2018-12-17T22:46:09.166323401Z 64 PC: 12ced | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:46:09.168368021Z 66 PC: 12cf9 | Move file pointer
2018-12-17T22:46:09.16969346Z 44 PC: 12cfd | Get time 0x12cfd: mov byte ptr [bp + 0x2e0], dl
0x12d01: call 0x12d17
0x12d04: mov ah, 0x40
0x12d06: mov cx, 0x2e0
0x12d09: lea dx, word ptr [bp + 6]
0x12d0d: int 0x21
0x12d0f: call 0x12d17
0x12d12: mov ah, 0x3e
0x12d14: int 0x21
0x12d16: ret
0x12d17: lea si, word ptr [bp + 0x17]
0x12d1b: mov cx, 0x2aa
0x12d1e: xor byte ptr [si], 0
0x12d21: inc si
0x12d22: dec cx
0x12d23: jne 0x12d1e
0x12d25: ret
0x12d26: add word ptr [bx], di
0x12d28: aas
0x12d29: aas
2018-12-17T22:46:09.172230985Z 64 PC: 12d0f | Write file or device (Write 736 bytes on handle 5)
2018-12-17T22:46:09.187380308Z 62 PC: 12d16 | Close file
2018-12-17T22:46:09.195960222Z 79 PC: 12ac7 | Find next file
2018-12-17T22:46:09.199493659Z 61 PC: 12cb4 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:46:09.21697977Z 63 PC: 12cc3 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:46:09.226779635Z 66 PC: 12cd2 | Move file pointer
2018-12-17T22:46:09.229095195Z 66 PC: 12ce1 | Move file pointer
2018-12-17T22:46:09.231248068Z 64 PC: 12ced | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:46:09.234207837Z 66 PC: 12cf9 | Move file pointer
2018-12-17T22:46:09.23588657Z 44 PC: 12cfd | Get time 0x12cfd: mov byte ptr [bp + 0x2e0], dl
0x12d01: call 0x12d17
0x12d04: mov ah, 0x40
0x12d06: mov cx, 0x2e0
0x12d09: lea dx, word ptr [bp + 6]
0x12d0d: int 0x21
0x12d0f: call 0x12d17
0x12d12: mov ah, 0x3e
0x12d14: int 0x21
0x12d16: ret
0x12d17: lea si, word ptr [bp + 0x17]
0x12d1b: mov cx, 0x2aa
0x12d1e: xor byte ptr [si], 0x40
0x12d21: inc si
0x12d22: dec cx
0x12d23: jne 0x12d1e
0x12d25: ret
0x12d26: add word ptr [bx], di
0x12d28: aas
0x12d29: aas
2018-12-17T22:46:09.239769372Z 64 PC: 12d0f | Write file or device (Write 736 bytes on handle 5)
2018-12-17T22:46:09.248690597Z 62 PC: 12d16 | Close file
2018-12-17T22:46:09.257441533Z 79 PC: 12ac7 | Find next file
2018-12-17T22:46:09.2611514Z 61 PC: 12cb4 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:46:09.268193647Z 63 PC: 12cc3 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:46:09.274876207Z 66 PC: 12cd2 | Move file pointer
2018-12-17T22:46:09.277670135Z 66 PC: 12ce1 | Move file pointer
2018-12-17T22:46:09.27942981Z 64 PC: 12ced | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:46:09.283774149Z 66 PC: 12cf9 | Move file pointer
2018-12-17T22:46:09.286167594Z 44 PC: 12cfd | Get time 0x12cfd: mov byte ptr [bp + 0x2e0], dl
0x12d01: call 0x12d17
0x12d04: mov ah, 0x40
0x12d06: mov cx, 0x2e0
0x12d09: lea dx, word ptr [bp + 6]
0x12d0d: int 0x21
0x12d0f: call 0x12d17
0x12d12: mov ah, 0x3e
0x12d14: int 0x21
0x12d16: ret
0x12d17: lea si, word ptr [bp + 0x17]
0x12d1b: mov cx, 0x2aa
0x12d1e: xor byte ptr [si], 0x46
0x12d21: inc si
0x12d22: dec cx
0x12d23: jne 0x12d1e
0x12d25: ret
0x12d26: add word ptr [bx], di
0x12d28: aas
0x12d29: aas
2018-12-17T22:46:09.288727512Z 64 PC: 12d0f | Write file or device (Write 736 bytes on handle 5)
2018-12-17T22:46:09.297286277Z 62 PC: 12d16 | Close file
2018-12-17T22:46:09.30597697Z 79 PC: 12ac7 | Find next file
2018-12-17T22:46:09.309839123Z 61 PC: 12cb4 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:46:09.317968622Z 63 PC: 12cc3 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:46:09.325163103Z 66 PC: 12cd2 | Move file pointer
2018-12-17T22:46:09.32681734Z 66 PC: 12ce1 | Move file pointer
2018-12-17T22:46:09.328351933Z 64 PC: 12ced | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:46:09.331599853Z 66 PC: 12cf9 | Move file pointer
2018-12-17T22:46:09.334069281Z 44 PC: 12cfd | Get time 0x12cfd: mov byte ptr [bp + 0x2e0], dl
0x12d01: call 0x12d17
0x12d04: mov ah, 0x40
0x12d06: mov cx, 0x2e0
0x12d09: lea dx, word ptr [bp + 6]
0x12d0d: int 0x21
0x12d0f: call 0x12d17
0x12d12: mov ah, 0x3e
0x12d14: int 0x21
0x12d16: ret
0x12d17: lea si, word ptr [bp + 0x17]
0x12d1b: mov cx, 0x2aa
0x12d1e: xor byte ptr [si], 0x4b
0x12d21: inc si
0x12d22: dec cx
0x12d23: jne 0x12d1e
0x12d25: ret
0x12d26: add word ptr [bx], di
0x12d28: aas
0x12d29: aas
2018-12-17T22:46:09.336561882Z 64 PC: 12d0f | Write file or device (Write 736 bytes on handle 5)
2018-12-17T22:46:09.345107492Z 62 PC: 12d16 | Close file
2018-12-17T22:46:09.354865679Z 79 PC: 12ac7 | Find next file
2018-12-17T22:46:09.358082331Z 61 PC: 12cb4 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:46:09.365294055Z 63 PC: 12cc3 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:46:09.372904358Z 66 PC: 12cd2 | Move file pointer
2018-12-17T22:46:09.374949409Z 66 PC: 12ce1 | Move file pointer
2018-12-17T22:46:09.376786038Z 64 PC: 12ced | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:46:09.380866392Z 66 PC: 12cf9 | Move file pointer
2018-12-17T22:46:09.382437794Z 44 PC: 12cfd | Get time 0x12cfd: mov byte ptr [bp + 0x2e0], dl
0x12d01: call 0x12d17
0x12d04: mov ah, 0x40
0x12d06: mov cx, 0x2e0
0x12d09: lea dx, word ptr [bp + 6]
0x12d0d: int 0x21
0x12d0f: call 0x12d17
0x12d12: mov ah, 0x3e
0x12d14: int 0x21
0x12d16: ret
0x12d17: lea si, word ptr [bp + 0x17]
0x12d1b: mov cx, 0x2aa
0x12d1e: xor byte ptr [si], 0x4b
0x12d21: inc si
0x12d22: dec cx
0x12d23: jne 0x12d1e
0x12d25: ret
0x12d26: add word ptr [bx], di
0x12d28: aas
0x12d29: aas
2018-12-17T22:46:09.385006398Z 64 PC: 12d0f | Write file or device (Write 736 bytes on handle 5)
2018-12-17T22:46:09.394435357Z 62 PC: 12d16 | Close file
2018-12-17T22:46:09.403223101Z 79 PC: 12ac7 | Find next file
2018-12-17T22:46:09.40578374Z 61 PC: 12cb4 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:46:09.413115991Z 63 PC: 12cc3 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:46:09.420374013Z 66 PC: 12cd2 | Move file pointer
2018-12-17T22:46:09.422591057Z 66 PC: 12ce1 | Move file pointer
2018-12-17T22:46:09.424529918Z 64 PC: 12ced | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:46:09.427876293Z 66 PC: 12cf9 | Move file pointer
2018-12-17T22:46:09.429882842Z 44 PC: 12cfd | Get time 0x12cfd: mov byte ptr [bp + 0x2e0], dl
0x12d01: call 0x12d17
0x12d04: mov ah, 0x40
0x12d06: mov cx, 0x2e0
0x12d09: lea dx, word ptr [bp + 6]
0x12d0d: int 0x21
0x12d0f: call 0x12d17
0x12d12: mov ah, 0x3e
0x12d14: int 0x21
0x12d16: ret
0x12d17: lea si, word ptr [bp + 0x17]
0x12d1b: mov cx, 0x2aa
0x12d1e: xor byte ptr [si], 0x51
0x12d21: inc si
0x12d22: dec cx
0x12d23: jne 0x12d1e
0x12d25: ret
0x12d26: add word ptr [bx], di
0x12d28: aas
0x12d29: aas
2018-12-17T22:46:09.43316161Z 64 PC: 12d0f | Write file or device (Write 736 bytes on handle 5)
2018-12-17T22:46:09.44305987Z 62 PC: 12d16 | Close file
2018-12-17T22:46:09.451729753Z 79 PC: 12ac7 | Find next file
2018-12-17T22:46:09.454581569Z 61 PC: 12cb4 | Open file (Filename = 'PAH.COM')
2018-12-17T22:46:09.46227571Z 63 PC: 12cc3 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:46:09.468948723Z 66 PC: 12cd2 | Move file pointer
2018-12-17T22:46:09.470458558Z 66 PC: 12ce1 | Move file pointer
2018-12-17T22:46:09.472850682Z 64 PC: 12ced | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:46:09.475926979Z 66 PC: 12cf9 | Move file pointer
2018-12-17T22:46:09.477421777Z 44 PC: 12cfd | Get time 0x12cfd: mov byte ptr [bp + 0x2e0], dl
0x12d01: call 0x12d17
0x12d04: mov ah, 0x40
0x12d06: mov cx, 0x2e0
0x12d09: lea dx, word ptr [bp + 6]
0x12d0d: int 0x21
0x12d0f: call 0x12d17
0x12d12: mov ah, 0x3e
0x12d14: int 0x21
0x12d16: ret
0x12d17: lea si, word ptr [bp + 0x17]
0x12d1b: mov cx, 0x2aa
0x12d1e: xor byte ptr [si], 0x56
0x12d21: inc si
0x12d22: dec cx
0x12d23: jne 0x12d1e
0x12d25: ret
0x12d26: add word ptr [bx], di
0x12d28: aas
0x12d29: aas
2018-12-17T22:46:09.480853882Z 64 PC: 12d0f | Write file or device (Write 736 bytes on handle 5)
2018-12-17T22:46:09.489346102Z 62 PC: 12d16 | Close file
2018-12-17T22:46:09.498736649Z 79 PC: 12ac7 | Find next file
2018-12-17T22:46:09.503145419Z 61 PC: 12cb4 | Open file (Filename = 'TEST.COM')
2018-12-17T22:46:09.510570745Z 63 PC: 12cc3 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:46:09.513831409Z 62 PC: 12d16 | Close file
2018-12-17T22:46:09.516255211Z 79 PC: 12ac7 | Find next file
2018-12-17T22:46:09.520370591Z 26 PC: 12ad7 | Set disk transfer address
2018-12-17T22:46:09.521977559Z 9 PC: 12ae9 | Display string (Could not find end pointer)