Sample viewer

vx.netlux.org/Virus.DOS.Mainman.357

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:47.604965192Z 26 PC: 1a5ba | Set disk transfer address
2018-12-17T22:46:47.607052083Z 71 PC: 1a684 | Get current directory
2018-12-17T22:46:47.621335028Z 78 PC: 1a5d5 | Find first file
2018-12-17T22:46:47.62888285Z 61 PC: 1a5e6 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:46:47.637421422Z 63 PC: 1a5f2 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:46:47.644955036Z 66 PC: 1a612 | Move file pointer
2018-12-17T22:46:47.647826411Z 64 PC: 1a629 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:46:47.651831927Z 66 PC: 1a639 | Move file pointer
2018-12-17T22:46:47.653902447Z 64 PC: 1a646 | Write file or device (Write 357 bytes on handle 5)
2018-12-17T22:46:47.669427827Z 62 PC: 1a64a | Close file
2018-12-17T22:46:47.679275027Z 78 PC: 1a663 | Find first file
2018-12-17T22:46:47.7083264Z 78 PC: 1a5d5 | Find first file
2018-12-17T22:46:47.718568944Z 61 PC: 1a5e6 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:46:47.726102418Z 63 PC: 1a5f2 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:46:47.734735709Z 62 PC: 1a64a | Close file
2018-12-17T22:46:47.737175112Z 59 PC: 1a670 | Change current directory
2018-12-17T22:46:47.739524656Z 26 PC: 1a679 | Set disk transfer address
2018-12-17T22:46:47.741795633Z 48 PC: 1a0e4 | Get DOS version
2018-12-17T22:46:47.743984856Z 44 PC: 17144 | Get time 0x17144: pop bp
0x17145: pop di
0x17146: pop si
0x17147: pop bx
0x17148: ret
0x17149: mov bx, 1
0x1714c: mov ah, 0x40
0x1714e: call 0x2711d
0x17151: jb 0x17157
0x17153: cmp ax, cx
0x17155: je 0x17148
0x17157: mov ax, 0x468c
0x1715a: jmp 0x1322d
0x1715d: mov bx, 2
0x17160: jmp 0x1714c
0x17162: sub si, si
0x17164: mov dx, bx
0x17166: call 0x27107
0x17169: jb 0x17157
0x1716b: xchg ax, bx
2018-12-17T22:46:47.747125667Z 42 PC: 17144 | Get date 0x17144: pop bp
0x17145: pop di
0x17146: pop si
0x17147: pop bx
0x17148: ret
0x17149: mov bx, 1
0x1714c: mov ah, 0x40
0x1714e: call 0x2711d
0x17151: jb 0x17157
0x17153: cmp ax, cx
0x17155: je 0x17148
0x17157: mov ax, 0x468c
0x1715a: jmp 0x1322d
0x1715d: mov bx, 2
0x17160: jmp 0x1714c
0x17162: sub si, si
0x17164: mov dx, bx
0x17166: call 0x27107
0x17169: jb 0x17157
0x1716b: xchg ax, bx
2018-12-17T22:46:47.750949011Z 25 PC: 17144 | Get default drive
2018-12-17T22:46:47.759047997Z 71 PC: 17144 | Get current directory
2018-12-17T22:46:47.765874172Z 64 PC: 17144 | Write file or device (Write 57 bytes on handle 1)
2018-12-17T22:46:47.777106275Z 64 PC: 17144 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:46:47.779494783Z 64 PC: 17144 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:46:47.79034572Z 64 PC: 17144 | Write file or device (Write 77 bytes on handle 1)
2018-12-17T22:46:47.806069702Z 64 PC: 17144 | Write file or device (Write 54 bytes on handle 1)
2018-12-17T22:46:47.812758921Z 64 PC: 17144 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:46:47.817902995Z 64 PC: 17144 | Write file or device (Write 81 bytes on handle 1)
2018-12-17T22:46:47.825337774Z 64 PC: 17144 | Write file or device (Write 75 bytes on handle 1)
2018-12-17T22:46:47.832807478Z 64 PC: 17144 | Write file or device (Write 52 bytes on handle 1)
2018-12-17T22:46:47.840192644Z 64 PC: 17144 | Write file or device (Write 54 bytes on handle 1)
2018-12-17T22:46:47.847140748Z 64 PC: 17144 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:46:47.854224036Z 64 PC: 17144 | Write file or device (Write 74 bytes on handle 1)
2018-12-17T22:46:47.86129971Z 64 PC: 17144 | Write file or device (Write 13 bytes on handle 1)
2018-12-17T22:46:47.866572236Z 64 PC: 17144 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:46:47.883674208Z 64 PC: 17144 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:46:47.886635021Z 64 PC: 17144 | Write file or device (Write 70 bytes on handle 1)
2018-12-17T22:46:47.894075881Z 64 PC: 17144 | Write file or device (Write 61 bytes on handle 1)
2018-12-17T22:46:47.90608831Z 64 PC: 17144 | Write file or device (Write 34 bytes on handle 1)
2018-12-17T22:46:47.913235569Z 64 PC: 17144 | Write file or device (Write 34 bytes on handle 1)
2018-12-17T22:46:47.919320291Z 64 PC: 17144 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:46:47.922460981Z 76 PC: 17144 | Terminate with return code (Return code = '1')