Sample viewer

vx.netlux.org/Virus.DOS.Corea.723

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:49:14.659343625Z 42 PC: 12c3c | Get date 0x12c3c: ret
0x12c3d: dec bp
0x12c3e: inc bp
0x12c3f: dec bp
0x12c40: inc bx
0x12c42: dec di
0x12c43: dec bp
0x12c44: add byte ptr [bx + di + 0x6e], cl
0x12c47: arpl word ptr [bx + 0x72], bp
0x12c4a: jb 0x12cb1
0x12c4c: arpl word ptr [si + 0x20], si
0x12c4f: inc sp
0x12c50: dec di
0x12c51: push bx
0x12c52: and byte ptr [bp + 0x65], dh
0x12c55: jb 0x12cca
0x12c57: imul bp, word ptr [bx + 0x6e], 0xd0a
0x12c5c: and al, 0x1d
0x12c5e: add dl, ch
0x12c60: or word ptr [bp + si], bp
2018-12-17T22:49:14.662295765Z 78 PC: 12c3c | Find first file
2018-12-17T22:49:14.668313775Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:49:14.86424969Z 61 PC: 12c3c | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:49:14.876614962Z 63 PC: 12c3c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:49:14.883087973Z 66 PC: 12ab4 | Move file pointer
2018-12-17T22:49:14.884650401Z 66 PC: 12c3c | Move file pointer
2018-12-17T22:49:14.887326386Z 44 PC: 12ac7 | Get time 0x12ac7: mov byte ptr [0x3a6], dl
0x12acb: mov byte ptr [0x3ad], dl
0x12acf: mov byte ptr [0x3b5], dl
0x12ad3: mov byte ptr [0x3c0], dl
0x12ad7: mov byte ptr [0x3c5], dl
0x12adb: mov byte ptr [0x3cc], dl
0x12adf: mov byte ptr [0x3d1], dl
0x12ae3: mov byte ptr [0x388], dl
0x12ae7: mov byte ptr [0x399], dl
0x12aeb: mov byte ptr [0x3a0], dl
0x12aef: mov byte ptr [0x3c9], dl
0x12af3: mov byte ptr [0x3bc], dl
0x12af7: mov byte ptr [0x3b6], dl
0x12afb: mov byte ptr [0x3ae], dl
0x12aff: mov byte ptr [0x3a7], dl
0x12b03: mov byte ptr [0x378], dl
0x12b07: mov byte ptr [0x37e], dl
0x12b0b: mov byte ptr [0x383], dl
0x12b0f: mov byte ptr [0x38e], dl
0x12b13: mov byte ptr [0x94], dl
2018-12-17T22:49:14.889978785Z 64 PC: 12cd7 | Write file or device (Write 723 bytes on handle 5)
2018-12-17T22:49:15.129171742Z 62 PC: 12c3c | Close file
2018-12-17T22:49:15.211640482Z 62 PC: 12b27 | Close file
2018-12-17T22:49:15.213154311Z 79 PC: 12c3c | Find next file
2018-12-17T22:49:15.215704919Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:49:15.227576947Z 61 PC: 12c3c | Open file (Filename = 'PRINT.COM')
2018-12-17T22:49:15.234514748Z 63 PC: 12c3c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:49:15.241062483Z 66 PC: 12ab4 | Move file pointer
2018-12-17T22:49:15.243837868Z 66 PC: 12c3c | Move file pointer
2018-12-17T22:49:15.245943547Z 44 PC: 12ac7 | Get time 0x12ac7: mov byte ptr [0x3a6], dl
0x12acb: mov byte ptr [0x3ad], dl
0x12acf: mov byte ptr [0x3b5], dl
0x12ad3: mov byte ptr [0x3c0], dl
0x12ad7: mov byte ptr [0x3c5], dl
0x12adb: mov byte ptr [0x3cc], dl
0x12adf: mov byte ptr [0x3d1], dl
0x12ae3: mov byte ptr [0x388], dl
0x12ae7: mov byte ptr [0x399], dl
0x12aeb: mov byte ptr [0x3a0], dl
0x12aef: mov byte ptr [0x3c9], dl
0x12af3: mov byte ptr [0x3bc], dl
0x12af7: mov byte ptr [0x3b6], dl
0x12afb: mov byte ptr [0x3ae], dl
0x12aff: mov byte ptr [0x3a7], dl
0x12b03: mov byte ptr [0x378], dl
0x12b07: mov byte ptr [0x37e], dl
0x12b0b: mov byte ptr [0x383], dl
0x12b0f: mov byte ptr [0x38e], dl
0x12b13: mov byte ptr [0x94], dl
2018-12-17T22:49:15.248757613Z 64 PC: 12cd7 | Write file or device (Write 723 bytes on handle 5)
2018-12-17T22:49:15.25757598Z 62 PC: 12c3c | Close file
2018-12-17T22:49:15.266354528Z 62 PC: 12b27 | Close file
2018-12-17T22:49:15.268245326Z 79 PC: 12c3c | Find next file
2018-12-17T22:49:15.271411486Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:49:15.282187733Z 61 PC: 12c3c | Open file (Filename = 'HELLO.COM')
2018-12-17T22:49:15.289002924Z 63 PC: 12c3c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:49:15.295837512Z 66 PC: 12ab4 | Move file pointer
2018-12-17T22:49:15.297721595Z 66 PC: 12c3c | Move file pointer
2018-12-17T22:49:15.299045297Z 44 PC: 12ac7 | Get time 0x12ac7: mov byte ptr [0x3a6], dl
0x12acb: mov byte ptr [0x3ad], dl
0x12acf: mov byte ptr [0x3b5], dl
0x12ad3: mov byte ptr [0x3c0], dl
0x12ad7: mov byte ptr [0x3c5], dl
0x12adb: mov byte ptr [0x3cc], dl
0x12adf: mov byte ptr [0x3d1], dl
0x12ae3: mov byte ptr [0x388], dl
0x12ae7: mov byte ptr [0x399], dl
0x12aeb: mov byte ptr [0x3a0], dl
0x12aef: mov byte ptr [0x3c9], dl
0x12af3: mov byte ptr [0x3bc], dl
0x12af7: mov byte ptr [0x3b6], dl
0x12afb: mov byte ptr [0x3ae], dl
0x12aff: mov byte ptr [0x3a7], dl
0x12b03: mov byte ptr [0x378], dl
0x12b07: mov byte ptr [0x37e], dl
0x12b0b: mov byte ptr [0x383], dl
0x12b0f: mov byte ptr [0x38e], dl
0x12b13: mov byte ptr [0x94], dl
2018-12-17T22:49:15.302099955Z 64 PC: 12cd7 | Write file or device (Write 723 bytes on handle 5)
2018-12-17T22:49:15.31048776Z 62 PC: 12c3c | Close file
2018-12-17T22:49:15.318132906Z 62 PC: 12b27 | Close file
2018-12-17T22:49:15.319707765Z 79 PC: 12c3c | Find next file
2018-12-17T22:49:15.322908596Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:49:15.332491839Z 61 PC: 12c3c | Open file (Filename = 'PHANG.COM')
2018-12-17T22:49:15.343837663Z 63 PC: 12c3c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:49:15.350868729Z 66 PC: 12ab4 | Move file pointer
2018-12-17T22:49:15.352575869Z 66 PC: 12c3c | Move file pointer
2018-12-17T22:49:15.354438567Z 44 PC: 12ac7 | Get time 0x12ac7: mov byte ptr [0x3a6], dl
0x12acb: mov byte ptr [0x3ad], dl
0x12acf: mov byte ptr [0x3b5], dl
0x12ad3: mov byte ptr [0x3c0], dl
0x12ad7: mov byte ptr [0x3c5], dl
0x12adb: mov byte ptr [0x3cc], dl
0x12adf: mov byte ptr [0x3d1], dl
0x12ae3: mov byte ptr [0x388], dl
0x12ae7: mov byte ptr [0x399], dl
0x12aeb: mov byte ptr [0x3a0], dl
0x12aef: mov byte ptr [0x3c9], dl
0x12af3: mov byte ptr [0x3bc], dl
0x12af7: mov byte ptr [0x3b6], dl
0x12afb: mov byte ptr [0x3ae], dl
0x12aff: mov byte ptr [0x3a7], dl
0x12b03: mov byte ptr [0x378], dl
0x12b07: mov byte ptr [0x37e], dl
0x12b0b: mov byte ptr [0x383], dl
0x12b0f: mov byte ptr [0x38e], dl
0x12b13: mov byte ptr [0x94], dl
2018-12-17T22:49:15.35771901Z 64 PC: 12cd7 | Write file or device (Write 723 bytes on handle 5)
2018-12-17T22:49:15.366014965Z 62 PC: 12c3c | Close file
2018-12-17T22:49:15.375829843Z 62 PC: 12b27 | Close file
2018-12-17T22:49:15.377888351Z 79 PC: 12c3c | Find next file
2018-12-17T22:49:15.380429392Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:49:15.390229759Z 61 PC: 12c3c | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:49:15.397615853Z 63 PC: 12c3c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:49:15.404695649Z 66 PC: 12ab4 | Move file pointer
2018-12-17T22:49:15.406394728Z 66 PC: 12c3c | Move file pointer
2018-12-17T22:49:15.408867968Z 44 PC: 12ac7 | Get time 0x12ac7: mov byte ptr [0x3a6], dl
0x12acb: mov byte ptr [0x3ad], dl
0x12acf: mov byte ptr [0x3b5], dl
0x12ad3: mov byte ptr [0x3c0], dl
0x12ad7: mov byte ptr [0x3c5], dl
0x12adb: mov byte ptr [0x3cc], dl
0x12adf: mov byte ptr [0x3d1], dl
0x12ae3: mov byte ptr [0x388], dl
0x12ae7: mov byte ptr [0x399], dl
0x12aeb: mov byte ptr [0x3a0], dl
0x12aef: mov byte ptr [0x3c9], dl
0x12af3: mov byte ptr [0x3bc], dl
0x12af7: mov byte ptr [0x3b6], dl
0x12afb: mov byte ptr [0x3ae], dl
0x12aff: mov byte ptr [0x3a7], dl
0x12b03: mov byte ptr [0x378], dl
0x12b07: mov byte ptr [0x37e], dl
0x12b0b: mov byte ptr [0x383], dl
0x12b0f: mov byte ptr [0x38e], dl
0x12b13: mov byte ptr [0x94], dl
2018-12-17T22:49:15.41153725Z 64 PC: 12cd7 | Write file or device (Write 723 bytes on handle 5)
2018-12-17T22:49:15.419942496Z 62 PC: 12c3c | Close file
2018-12-17T22:49:15.4290276Z 62 PC: 12b27 | Close file
2018-12-17T22:49:15.430511736Z 79 PC: 12c3c | Find next file
2018-12-17T22:49:15.433087724Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:49:15.448403986Z 61 PC: 12c3c | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:49:15.454793258Z 63 PC: 12c3c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:49:15.462085713Z 66 PC: 12ab4 | Move file pointer
2018-12-17T22:49:15.466653056Z 66 PC: 12c3c | Move file pointer
2018-12-17T22:49:15.468321093Z 44 PC: 12ac7 | Get time 0x12ac7: mov byte ptr [0x3a6], dl
0x12acb: mov byte ptr [0x3ad], dl
0x12acf: mov byte ptr [0x3b5], dl
0x12ad3: mov byte ptr [0x3c0], dl
0x12ad7: mov byte ptr [0x3c5], dl
0x12adb: mov byte ptr [0x3cc], dl
0x12adf: mov byte ptr [0x3d1], dl
0x12ae3: mov byte ptr [0x388], dl
0x12ae7: mov byte ptr [0x399], dl
0x12aeb: mov byte ptr [0x3a0], dl
0x12aef: mov byte ptr [0x3c9], dl
0x12af3: mov byte ptr [0x3bc], dl
0x12af7: mov byte ptr [0x3b6], dl
0x12afb: mov byte ptr [0x3ae], dl
0x12aff: mov byte ptr [0x3a7], dl
0x12b03: mov byte ptr [0x378], dl
0x12b07: mov byte ptr [0x37e], dl
0x12b0b: mov byte ptr [0x383], dl
0x12b0f: mov byte ptr [0x38e], dl
0x12b13: mov byte ptr [0x94], dl
2018-12-17T22:49:15.471162898Z 64 PC: 12cd7 | Write file or device (Write 723 bytes on handle 5)
2018-12-17T22:49:15.481325655Z 62 PC: 12c3c | Close file
2018-12-17T22:49:15.48924697Z 62 PC: 12b27 | Close file
2018-12-17T22:49:15.490770268Z 79 PC: 12c3c | Find next file
2018-12-17T22:49:15.494257436Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:49:15.504291012Z 61 PC: 12c3c | Open file (Filename = 'PAH.COM')
2018-12-17T22:49:15.511523261Z 63 PC: 12c3c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:49:15.519011268Z 66 PC: 12ab4 | Move file pointer
2018-12-17T22:49:15.520524786Z 66 PC: 12c3c | Move file pointer
2018-12-17T22:49:15.521897383Z 44 PC: 12ac7 | Get time 0x12ac7: mov byte ptr [0x3a6], dl
0x12acb: mov byte ptr [0x3ad], dl
0x12acf: mov byte ptr [0x3b5], dl
0x12ad3: mov byte ptr [0x3c0], dl
0x12ad7: mov byte ptr [0x3c5], dl
0x12adb: mov byte ptr [0x3cc], dl
0x12adf: mov byte ptr [0x3d1], dl
0x12ae3: mov byte ptr [0x388], dl
0x12ae7: mov byte ptr [0x399], dl
0x12aeb: mov byte ptr [0x3a0], dl
0x12aef: mov byte ptr [0x3c9], dl
0x12af3: mov byte ptr [0x3bc], dl
0x12af7: mov byte ptr [0x3b6], dl
0x12afb: mov byte ptr [0x3ae], dl
0x12aff: mov byte ptr [0x3a7], dl
0x12b03: mov byte ptr [0x378], dl
0x12b07: mov byte ptr [0x37e], dl
0x12b0b: mov byte ptr [0x383], dl
0x12b0f: mov byte ptr [0x38e], dl
0x12b13: mov byte ptr [0x94], dl
2018-12-17T22:49:15.525213044Z 64 PC: 12cd7 | Write file or device (Write 723 bytes on handle 5)
2018-12-17T22:49:15.534445579Z 62 PC: 12c3c | Close file
2018-12-17T22:49:15.543936452Z 62 PC: 12b27 | Close file
2018-12-17T22:49:15.546550474Z 79 PC: 12c3c | Find next file
2018-12-17T22:49:15.550405045Z 67 PC: 12c3c | Get or set file attributes
2018-12-17T22:49:15.56024523Z 61 PC: 12c3c | Open file (Filename = 'TEST.COM')
2018-12-17T22:49:15.56775419Z 63 PC: 12c3c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:49:15.570599585Z 62 PC: 12b27 | Close file
2018-12-17T22:49:15.572697767Z 79 PC: 12c3c | Find next file
2018-12-17T22:49:15.576261332Z 78 PC: 12b4c | Find first file
2018-12-17T22:49:15.583086292Z 53 PC: 12b57 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:49:15.584603374Z 37 PC: 12b67 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:49:15.586853827Z 53 PC: 12c3c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:49:15.588716771Z 37 PC: 12c3c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:49:15.590205722Z 9 PC: 12c3c | Display string (Could not find end pointer)
2018-12-17T22:49:15.594805436Z 37 PC: 12b97 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:49:15.597187092Z 49 PC: 12c3c | Terminate and stay resident (Return code = '36' | Memory size = '62')