Sample viewer

vx.netlux.org/Virus.DOS.TPE.Ecl.3191

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:48:03.396383081Z 47 PC: 12aa6 | Get disk transfer address
2018-12-17T22:48:03.399256821Z 71 PC: 12abc | Get current directory
2018-12-17T22:48:03.402776916Z 26 PC: 12ac3 | Set disk transfer address
2018-12-17T22:48:03.404214066Z 78 PC: 12d55 | Find first file
2018-12-17T22:48:03.410708499Z 78 PC: 12ad3 | Find first file
2018-12-17T22:48:03.417783634Z 61 PC: 12c11 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:48:03.424661698Z 63 PC: 12c1e | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:48:03.431480902Z 66 PC: 12c32 | Move file pointer
2018-12-17T22:48:03.434142804Z 66 PC: 12c46 | Move file pointer
2018-12-17T22:48:03.43572166Z 63 PC: 12c51 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:48:03.438657507Z 62 PC: 12c55 | Close file
2018-12-17T22:48:03.441426901Z 67 PC: 12c6c | Get or set file attributes
2018-12-17T22:48:03.462206046Z 61 PC: 12c71 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:48:03.469688246Z 64 PC: 12c7f | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:48:03.477874799Z 66 PC: 12c88 | Move file pointer
2018-12-17T22:48:03.479789186Z 74 PC: 12c9f | Reallocate memory
2018-12-17T22:48:03.481778454Z 72 PC: 12caa | Allocate memory
2018-12-17T22:48:03.488349611Z 64 PC: 12cd4 | Write file or device (Write 3247 bytes on handle 5)
2018-12-17T22:48:03.497884498Z 73 PC: 12cd8 | Release memory
2018-12-17T22:48:03.499289568Z 64 PC: 12ce7 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:48:03.502796778Z 87 PC: 12cf2 | Get or set file date and time
2018-12-17T22:48:03.505092823Z 62 PC: 12cf6 | Close file
2018-12-17T22:48:03.514025948Z 67 PC: 12d03 | Get or set file attributes
2018-12-17T22:48:03.525458802Z 79 PC: 12ad3 | Find next file
2018-12-17T22:48:03.529588792Z 61 PC: 12c11 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:48:03.537043299Z 63 PC: 12c1e | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:48:03.544288243Z 66 PC: 12c32 | Move file pointer
2018-12-17T22:48:03.546742295Z 66 PC: 12c46 | Move file pointer
2018-12-17T22:48:03.548887175Z 63 PC: 12c51 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:48:03.552094772Z 62 PC: 12c55 | Close file
2018-12-17T22:48:03.555037802Z 67 PC: 12c6c | Get or set file attributes
2018-12-17T22:48:03.566311806Z 61 PC: 12c71 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:48:03.573960759Z 64 PC: 12c7f | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:48:03.578651764Z 66 PC: 12c88 | Move file pointer
2018-12-17T22:48:03.580896862Z 74 PC: 12c9f | Reallocate memory
2018-12-17T22:48:03.582926316Z 72 PC: 12caa | Allocate memory
2018-12-17T22:48:03.58990543Z 64 PC: 12cd4 | Write file or device (Write 3249 bytes on handle 5)
2018-12-17T22:48:03.600313628Z 73 PC: 12cd8 | Release memory
2018-12-17T22:48:03.601975901Z 64 PC: 12ce7 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:48:03.60559429Z 87 PC: 12cf2 | Get or set file date and time
2018-12-17T22:48:03.607477048Z 62 PC: 12cf6 | Close file
2018-12-17T22:48:03.616010533Z 67 PC: 12d03 | Get or set file attributes
2018-12-17T22:48:03.626678208Z 79 PC: 12ad3 | Find next file
2018-12-17T22:48:03.63083537Z 61 PC: 12c11 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:48:03.638119256Z 63 PC: 12c1e | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:48:03.64774825Z 66 PC: 12c32 | Move file pointer
2018-12-17T22:48:03.650616029Z 66 PC: 12c46 | Move file pointer
2018-12-17T22:48:03.652653868Z 63 PC: 12c51 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:48:03.655681577Z 62 PC: 12c55 | Close file
2018-12-17T22:48:03.658968844Z 67 PC: 12c6c | Get or set file attributes
2018-12-17T22:48:03.670846252Z 61 PC: 12c71 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:48:03.678256426Z 64 PC: 12c7f | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:48:03.682421463Z 66 PC: 12c88 | Move file pointer
2018-12-17T22:48:03.684121317Z 74 PC: 12c9f | Reallocate memory
2018-12-17T22:48:03.688395728Z 72 PC: 12caa | Allocate memory
2018-12-17T22:48:03.695189394Z 64 PC: 12cd4 | Write file or device (Write 3248 bytes on handle 5)
2018-12-17T22:48:03.70824162Z 73 PC: 12cd8 | Release memory
2018-12-17T22:48:03.709809436Z 64 PC: 12ce7 | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:48:03.712703033Z 87 PC: 12cf2 | Get or set file date and time
2018-12-17T22:48:03.71574021Z 62 PC: 12cf6 | Close file
2018-12-17T22:48:03.728707006Z 67 PC: 12d03 | Get or set file attributes
2018-12-17T22:48:03.739546313Z 59 PC: 12af3 | Change current directory
2018-12-17T22:48:03.744614296Z 26 PC: 12afa | Set disk transfer address
2018-12-17T22:48:03.746024315Z 42 PC: 12d75 | Get date 0x12d75: xor ah, ah
0x12d77: mov al, dl
0x12d79: ret
0x12d7a: push si
0x12d7b: push di
0x12d7c: mov ax, di
0x12d7e: mov cx, 3
0x12d81: lea si, word ptr [di + 0x467]
0x12d85: xchg di, si
0x12d87: push cx
0x12d88: mov cx, word ptr cs:[di]
0x12d8b: add di, 2
0x12d8e: mov si, word ptr cs:[di]
0x12d91: add si, ax
0x12d93: add di, 2
0x12d96: push ax
0x12d97: mov ax, word ptr cs:[di]
0x12d9a: add di, 2
0x12d9d: call 0x12db9
0x12da0: pop ax