Sample viewer

vx.netlux.org/Virus.DOS.ExeHeader.Ming.359

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:58:49.056995949Z 44 PC: 12aa6 | Get time 0x12aa6: cmp dl, 2
0x12aa9: jne 0x12ab2
0x12aab: mov ah, 9
0x12aad: mov dx, 0x297
0x12ab0: int 0x21
0x12ab2: mov ah, 0xd
0x12ab4: int 0x21
0x12ab6: cld
0x12ab7: mov ax, 0x12
0x12aba: mov es, ax
0x12abc: push es
0x12abd: mov di, 0x100
0x12ac0: mov si, di
0x12ac2: mov cx, 0x1c9
0x12ac5: rep movsb byte ptr es:[di], byte ptr [si]
0x12ac7: xor ax, ax
0x12ac9: mov ds, ax
0x12acb: mov ax, 0x1f5
0x12ace: xchg word ptr [0x4c], ax
0x12ad2: mov word ptr es:[0x1fd], ax
2018-12-17T21:58:49.059287673Z 13 PC: 12ab6 | Disk reset
2018-12-17T21:58:49.060614025Z 74 PC: 12b17 | Reallocate memory
2018-12-17T21:58:49.062059927Z 75 PC: 12b1f | Execute program
2018-12-17T21:58:49.073414931Z 88 PC: 19cc8 | case 0xGet or set allocation strateg:
2018-12-17T21:58:49.074455713Z 88 PC: 19cd0 | case 0xGet or set allocation strateg:
2018-12-17T21:58:49.075604779Z 88 PC: 19cfa | case 0xGet or set allocation strateg:
2018-12-17T21:58:49.077433487Z 88 PC: 19d69 | case 0xGet or set allocation strateg:
2018-12-17T21:58:49.07852587Z 88 PC: 19d73 | case 0xGet or set allocation strateg:
2018-12-17T21:58:49.079480973Z 48 PC: 197b4 | Get DOS version
2018-12-17T21:58:49.080961658Z 56 PC: 1b410 | Get or set country info
2018-12-17T21:58:49.085961406Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.08750246Z 68 PC: 1b47b | I/O control for devices (Set for = '')
2018-12-17T21:58:49.090698884Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.092202927Z 68 PC: 1b47b | I/O control for devices (Set for = '')
2018-12-17T21:58:49.094625559Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.096994921Z 68 PC: 1b47b | I/O control for devices (Set for = '')
2018-12-17T21:58:49.099244661Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.100198653Z 68 PC: 1b47b | I/O control for devices (Set for = '')
2018-12-17T21:58:49.1022964Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.103290319Z 68 PC: 1b47b | I/O control for devices (Set for = '”')
2018-12-17T21:58:49.104689681Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.106668261Z 68 PC: 1b47b | I/O control for devices (Set for = '”')
2018-12-17T21:58:49.108592566Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.109638221Z 68 PC: 1b47b | I/O control for devices (Set for = 'W”')
2018-12-17T21:58:49.111738851Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.112808932Z 68 PC: 1b47b | I/O control for devices (Set for = 'W”')
2018-12-17T21:58:49.114411285Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.116139979Z 68 PC: 1b47b | I/O control for devices (Set for = 'UW”')
2018-12-17T21:58:49.117569426Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.118467569Z 68 PC: 1b47b | I/O control for devices (Set for = 'UW”')
2018-12-17T21:58:49.120320816Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.121373863Z 68 PC: 1b47b | I/O control for devices (Set for = 'WUW”')
2018-12-17T21:58:49.122847955Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.124505398Z 68 PC: 1b47b | I/O control for devices (Set for = 'WUW”')
2018-12-17T21:58:49.126003549Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.126944565Z 68 PC: 1b47b | I/O control for devices (Set for = 'JWUW”')
2018-12-17T21:58:49.128998716Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.129988125Z 68 PC: 1b47b | I/O control for devices (Set for = 'JWUW”')
2018-12-17T21:58:49.131490047Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.132938325Z 68 PC: 1b47b | I/O control for devices (Set for = '”JWUW”')
2018-12-17T21:58:49.134489895Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.13548149Z 68 PC: 1b47b | I/O control for devices (Set for = '”JWUW”')
2018-12-17T21:58:49.137498673Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.138486189Z 68 PC: 1b47b | I/O control for devices (Set for = 'ί”JWUW”')
2018-12-17T21:58:49.139925097Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.141463265Z 68 PC: 1b47b | I/O control for devices (Set for = 'πί”JWUW”')
2018-12-17T21:58:49.142897393Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.143772642Z 68 PC: 1b47b | I/O control for devices (Set for = 'πί”JWUW”')
2018-12-17T21:58:49.145864162Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.146793521Z 68 PC: 1b47b | I/O control for devices (Set for = 'ώπί”JWUW”')
2018-12-17T21:58:49.148656869Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.150172193Z 68 PC: 1b47b | I/O control for devices (Set for = 'πώπί”JWUW”')
2018-12-17T21:58:49.151615679Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.15285891Z 68 PC: 1b47b | I/O control for devices (Set for = 'šπώπί”JWUW”')
2018-12-17T21:58:49.155126652Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.158047274Z 68 PC: 1b47b | I/O control for devices (Set for = '')
2018-12-17T21:58:49.160515237Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.16242107Z 68 PC: 1b47b | I/O control for devices (Set for = 'Ÿ')
2018-12-17T21:58:49.163921125Z 68 PC: 1b528 | I/O control for devices (Set for = 'Ÿ')
2018-12-17T21:58:49.172193159Z 82 PC: 19e67 | Get DOS internal pointers (SYSVARS)
2018-12-17T21:58:49.175148848Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.176436203Z 68 PC: 1b47b | I/O control for devices (Set for = 'ΐŸ')
2018-12-17T21:58:49.178189441Z 68 PC: 1b528 | I/O control for devices (Set for = 'ΐŸ')
2018-12-17T21:58:49.181693044Z 48 PC: 1b46e | Get DOS version
2018-12-17T21:58:49.183834744Z 68 PC: 1b47b | I/O control for devices (Set for = ' ΐŸ')
2018-12-17T21:58:49.185333411Z 68 PC: 1b528 | I/O control for devices (Set for = ' ΐŸ')
2018-12-17T21:58:49.187704416Z 82 PC: 1b5ed | Get DOS internal pointers (SYSVARS)
2018-12-17T21:58:49.189892256Z 43 PC: 19ec5 | Set date
2018-12-17T21:58:49.191420515Z 88 PC: 1ba31 | case 0xGet or set allocation strateg:
2018-12-17T21:58:49.192977149Z 88 PC: 1ba3f | case 0xGet or set allocation strateg:
2018-12-17T21:58:49.194288902Z 82 PC: 1ba43 | Get DOS internal pointers (SYSVARS)
2018-12-17T21:58:49.19547425Z 88 PC: 1bb06 | case 0xGet or set allocation strateg:
2018-12-17T21:58:49.19794235Z 9 PC: 197a0 | Display string (String= 'SMARTDrive cannot be loaded because the XMS driver, HIMEM.SYS is not loaded. Check the CONFIG.SYS file for a device=himem.sys command line. ')
2018-12-17T21:58:49.20587001Z 76 PC: 1994e | Terminate with return code (Return code = '1')
2018-12-17T21:58:49.209316756Z 77 PC: 12b23 | Get program return code
2018-12-17T21:58:49.211004927Z 76 PC: 12b27 | Terminate with return code (Return code = '1')