Sample viewer

vx.netlux.org/Virus.DOS.Gobot.4005

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:48:23.048383598Z 53 PC: 12a56 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:48:23.050755596Z 37 PC: 12a66 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:48:23.052086061Z 78 PC: 12a75 | Find first file
2018-12-17T22:48:23.058204545Z 61 PC: 12a7f | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:48:23.068100372Z 63 PC: 12a8a | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:48:23.074945664Z 44 PC: 12ade | Get time 0x12ade: xor dh, dh
0x12ae0: and dl, 7
0x12ae3: cmp dx, 6
0x12ae7: jg 0x12ada
0x12ae9: push dx
0x12aea: add dx, 0x347
0x12aee: mov si, dx
0x12af0: mov dl, byte ptr cs:[si]
0x12af3: mov byte ptr [0x103], dl
0x12af7: pop dx
0x12af8: push dx
0x12af9: add dx, 0x35c
0x12afd: mov si, dx
0x12aff: mov dl, byte ptr cs:[si]
0x12b02: mov byte ptr [0x100], dl
0x12b06: mov ah, 0x2c
0x12b08: int 0x21
0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
2018-12-17T22:48:23.077543811Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34e
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x355
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T22:48:23.090339003Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34e
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x355
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T22:48:23.092758073Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34e
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x355
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T22:48:23.094940723Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34e
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x355
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T22:48:23.0976031Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34e
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x355
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T22:48:23.100691029Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34e
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x355
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T22:48:23.103750818Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34e
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x355
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T22:48:23.106787801Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34e
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x355
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T22:48:23.109824116Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34e
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x355
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T22:48:23.112756152Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34e
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x355
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T22:48:23.115149228Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34e
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x355
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T22:48:23.118051928Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34e
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x355
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T22:48:23.120626618Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34e
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x355
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T22:48:23.123251082Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x34e
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x355
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
0x12b38: mov ax, 0x4200
2018-12-17T22:48:23.126923952Z 66 PC: 12b41 | Move file pointer
2018-12-17T22:48:23.128672109Z 44 PC: 12b46 | Get time 0x12b46: mov word ptr [0x10a1], dx
0x12b4a: mov si, 0x2f2
0x12b4d: mov di, 0x10a9
0x12b50: mov cx, 0x1a
0x12b53: rep movsb byte ptr es:[di], byte ptr [si]
0x12b55: call 0x139e9
0x12b58: mov ah, 0x3e
0x12b5a: int 0x21
0x12b5c: mov ah, 0x2c
0x12b5e: int 0x21
0x12b60: xor dh, dh
0x12b62: and dl, 0x3f
0x12b65: cmp dx, 0x69
0x12b69: jg 0x12b5c
0x12b6b: mov ah, 9
0x12b6d: add dx, dx
0x12b6f: add dx, 0x363
0x12b73: mov si, dx
0x12b75: mov dx, word ptr cs:[si]
0x12b78: int 0x21
2018-12-17T22:48:23.132148923Z 64 PC: 139fb | Write file or device (Write 4005 bytes on handle 5)
2018-12-17T22:48:23.152398526Z 62 PC: 12b5c | Close file
2018-12-17T22:48:23.16044663Z 44 PC: 12b60 | Get time 0x12b60: xor dh, dh
0x12b62: and dl, 0x3f
0x12b65: cmp dx, 0x69
0x12b69: jg 0x12b5c
0x12b6b: mov ah, 9
0x12b6d: add dx, dx
0x12b6f: add dx, 0x363
0x12b73: mov si, dx
0x12b75: mov dx, word ptr cs:[si]
0x12b78: int 0x21
0x12b7a: int 0x20
0x12b7c: mov ah, 0xf
0x12b7e: int 0x10
0x12b80: xor ah, ah
0x12b82: int 0x10
0x12b84: mov ah, 1
0x12b86: mov cx, 0x2607
0x12b89: int 0x10
0x12b8b: mov ax, 0xb800
0x12b8e: mov es, ax
2018-12-17T22:48:23.163051123Z 9 PC: 12b7a | Display string (String= 'Bad command or file name ')