Sample viewer

vx.netlux.org/Virus.DOS.Mans.1486

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:49:21.123737809Z 44 PC: 13cd6 | Get time 0x13cd6: ret
0x13cd7: clc
0x13cd8: inc ax
0x13cd9: sbb word ptr [bx + si], ax
0x13cdb: mov word ptr cs:[bp + 0x130], ds
0x13ce0: xor ax, ax
0x13ce2: mov es, ax
0x13ce4: mov di, 4
0x13ce7: cli
0x13ce8: cld
0x13ce9: stosw word ptr es:[di], ax
0x13cea: stosw word ptr es:[di], ax
0x13ceb: add di, 4
0x13cee: stosw word ptr es:[di], ax
0x13cef: stosw word ptr es:[di], ax
0x13cf0: sti
0x13cf1: sub word ptr cs:[bp + 0x1c3], 0x7182
0x13cf8: call 0x13d03
0x13cfb: add word ptr cs:[bp + 0x1c3], 0x7182
0x13d02: ret
2018-12-17T22:49:21.1267771Z 25 PC: 13cd6 | Get default drive
2018-12-17T22:49:21.128764945Z 71 PC: 13cd6 | Get current directory
2018-12-17T22:49:21.131622814Z 53 PC: 13cd6 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:49:21.133602503Z 37 PC: 13cd6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:49:21.13503242Z 26 PC: 13cd6 | Set disk transfer address
2018-12-17T22:49:21.136372748Z 78 PC: 13cd6 | Find first file
2018-12-17T22:49:21.142565193Z 47 PC: 13cd6 | Get disk transfer address
2018-12-17T22:49:21.150657407Z 67 PC: 13cd6 | Get or set file attributes
2018-12-17T22:49:21.156497429Z 67 PC: 13cd6 | Get or set file attributes
2018-12-17T22:49:21.174411276Z 61 PC: 13cd6 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:49:21.183606733Z 63 PC: 13cd6 | Read file or device (Read 24 bytes on handle 5)
2018-12-17T22:49:21.186409509Z 66 PC: 13cd6 | Move file pointer
2018-12-17T22:49:21.188298989Z 66 PC: 13cd6 | Move file pointer
2018-12-17T22:49:21.190587528Z 64 PC: 13cd6 | Write file or device (Write 24 bytes on handle 5)
2018-12-17T22:49:21.193426542Z 66 PC: 13cd6 | Move file pointer
2018-12-17T22:49:21.195221825Z 64 PC: 13cd6 | Write file or device (Write 1486 bytes on handle 5)
2018-12-17T22:49:21.205850134Z 87 PC: 13cd6 | Get or set file date and time
2018-12-17T22:49:21.207580475Z 67 PC: 13cd6 | Get or set file attributes
2018-12-17T22:49:21.220068999Z 62 PC: 13cd6 | Close file
2018-12-17T22:49:21.228247796Z 26 PC: 13cd6 | Set disk transfer address
2018-12-17T22:49:21.229924546Z 26 PC: 13cd6 | Set disk transfer address
2018-12-17T22:49:21.231577592Z 79 PC: 13cd6 | Find next file
2018-12-17T22:49:21.234776391Z 26 PC: 13cd6 | Set disk transfer address
2018-12-17T22:49:21.236605117Z 59 PC: 13cd6 | Change current directory
2018-12-17T22:49:21.240878426Z 78 PC: 13cd6 | Find first file
2018-12-17T22:49:21.251825804Z 59 PC: 13cd6 | Change current directory
2018-12-17T22:49:21.255920307Z 42 PC: 13cd6 | Get date 0x13cd6: ret
0x13cd7: clc
0x13cd8: inc ax
0x13cd9: sbb word ptr [bx + si], ax
0x13cdb: mov word ptr cs:[bp + 0x130], ds
0x13ce0: xor ax, ax
0x13ce2: mov es, ax
0x13ce4: mov di, 4
0x13ce7: cli
0x13ce8: cld
0x13ce9: stosw word ptr es:[di], ax
0x13cea: stosw word ptr es:[di], ax
0x13ceb: add di, 4
0x13cee: stosw word ptr es:[di], ax
0x13cef: stosw word ptr es:[di], ax
0x13cf0: sti
0x13cf1: sub word ptr cs:[bp + 0x1c3], 0x7182
0x13cf8: call 0x13d03
0x13cfb: add word ptr cs:[bp + 0x1c3], 0x7182
0x13d02: ret
2018-12-17T22:49:21.25879091Z 37 PC: 13cd6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:49:21.260543713Z 9 PC: 12a5c | Display string (Could not find end pointer)
2018-12-17T22:49:21.268325244Z 76 PC: 12a61 | Terminate with return code (Return code = '0')