Sample viewer

vx.netlux.org/Virus.DOS.Lemming.2056

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:49:47.76199851Z 42 PC: 13c5c | Get date 0x13c5c: cmp dl, 0x1f
0x13c5f: jne 0x13c6b
0x13c61: mov ah, 0x2c
0x13c63: int 0x21
0x13c65: mov ah, dh
0x13c67: int 0x24
0x13c69: int 0x19
0x13c6b: push es
0x13c6c: push ds
0x13c6d: push cs
0x13c6e: pop ds
0x13c6f: mov ah, 0x72
0x13c71: int 0x21
0x13c73: cmp bx, 0x4850
0x13c77: jne 0x13c92
0x13c79: jmp 0x13d0a
0x13c7c: call 0x13e37
0x13c7f: mov di, 0x100
0x13c82: push cs
0x13c83: pop ds
2018-12-17T22:49:47.78001596Z 114 PC: 13c73 | UNKNOWN!
2018-12-17T22:49:47.78089237Z 82 PC: 13d65 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:49:47.782763583Z 88 PC: 13c9e | case 0xGet or set allocation strateg:
2018-12-17T22:49:47.785131022Z 88 PC: 13ca8 | case 0xGet or set allocation strateg:
2018-12-17T22:49:47.787157738Z 53 PC: 1429f | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:49:47.788772217Z 37 PC: 142ac | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:49:47.79164595Z 53 PC: 142d2 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:49:47.79331138Z 37 PC: 142e2 | Set interrupt vector (Interrupt = '1' AKA 'Character input')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":10012,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:26:59.779654534Z 42 PC: 13c5c | Get date 0x13c5c: cmp dl, 0x1f
0x13c5f: jne 0x13c6b
0x13c61: mov ah, 0x2c
0x13c63: int 0x21
0x13c65: mov ah, dh
0x13c67: int 0x24
0x13c69: int 0x19
0x13c6b: push es
0x13c6c: push ds
0x13c6d: push cs
0x13c6e: pop ds
0x13c6f: mov ah, 0x72
0x13c71: int 0x21
0x13c73: cmp bx, 0x4850
0x13c77: jne 0x13c92
0x13c79: jmp 0x13d0a
0x13c7c: call 0x13e37
0x13c7f: mov di, 0x100
0x13c82: push cs
0x13c83: pop ds
2018-12-25T12:26:59.782667121Z 114 PC: 13c73 | UNKNOWN!
2018-12-25T12:26:59.784127783Z 82 PC: 13d65 | Get DOS internal pointers (SYSVARS)
2018-12-25T12:26:59.785576356Z 88 PC: 13c9e | case 0xGet or set allocation strateg:
2018-12-25T12:26:59.788115358Z 88 PC: 13ca8 | case 0xGet or set allocation strateg:
2018-12-25T12:26:59.789906801Z 53 PC: 1429f | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T12:26:59.791303456Z 37 PC: 142ac | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T12:26:59.793083496Z 53 PC: 142d2 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:26:59.795282798Z 37 PC: 142e2 | Set interrupt vector (Interrupt = '1' AKA 'Character input')

{"DateBased":true,"Day":31,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":10012,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:26:59.83687455Z 42 PC: 13c5c | Get date 0x13c5c: cmp dl, 0x1f
0x13c5f: jne 0x13c6b
0x13c61: mov ah, 0x2c
0x13c63: int 0x21
0x13c65: mov ah, dh
0x13c67: int 0x24
0x13c69: int 0x19
0x13c6b: push es
0x13c6c: push ds
0x13c6d: push cs
0x13c6e: pop ds
0x13c6f: mov ah, 0x72
0x13c71: int 0x21
0x13c73: cmp bx, 0x4850
0x13c77: jne 0x13c92
0x13c79: jmp 0x13d0a
0x13c7c: call 0x13e37
0x13c7f: mov di, 0x100
0x13c82: push cs
0x13c83: pop ds
2018-12-25T12:26:59.839896779Z 44 PC: 13c65 | Get time 0x13c65: mov ah, dh
0x13c67: int 0x24
0x13c69: int 0x19
0x13c6b: push es
0x13c6c: push ds
0x13c6d: push cs
0x13c6e: pop ds
0x13c6f: mov ah, 0x72
0x13c71: int 0x21
0x13c73: cmp bx, 0x4850
0x13c77: jne 0x13c92
0x13c79: jmp 0x13d0a
0x13c7c: call 0x13e37
0x13c7f: mov di, 0x100
0x13c82: push cs
0x13c83: pop ds
0x13c84: lea si, word ptr [bp + 0x100]
0x13c88: mov cx, 0x808
0x13c8b: rep movsb byte ptr es:[di], byte ptr [si]
0x13c8d: call 0x13e5f
2018-12-25T12:26:59.842493138Z 81 PC: 122cc | Get current PSP
2018-12-25T12:26:59.843420837Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-25T12:26:59.845706711Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.849657998Z 89 PC: 12459 | Get extended error info
2018-12-25T12:26:59.850877746Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.853131452Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.869110932Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.871901237Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.874297029Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.877133231Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.879552694Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.881926028Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.885916246Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.888213401Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.891221567Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.896849469Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.898829958Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.900803744Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.906357276Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.908641914Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.910600366Z 2 PC: 126da | Character output (Char = '72')
2018-12-25T12:26:59.912631313Z 2 PC: 126da | Character output (See above)
2018-12-25T12:26:59.927724633Z 2 PC: 126da | Character output (See above)
2018-12-25T12:26:59.929639196Z 2 PC: 126da | Character output (See above)
2018-12-25T12:26:59.931663925Z 2 PC: 126da | Character output (See above)
2018-12-25T12:26:59.933822634Z 2 PC: 126da | Character output (See above)
2018-12-25T12:26:59.935826771Z 2 PC: 126da | Character output (See above)
2018-12-25T12:26:59.937837106Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.948487685Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.9507379Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.953597756Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.95665429Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.960395933Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.962509108Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.967335106Z 2 PC: 126ce | Character output (Char = '41')
2018-12-25T12:26:59.96936467Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.973944887Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.978630331Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.981850624Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.983820418Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.986740935Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.989370684Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.991692768Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.994841959Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.997096183Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:26:59.999324895Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:27:00.002223845Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:27:00.012568366Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:27:00.014596447Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:27:00.016732131Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:27:00.019509345Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:27:00.021728593Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:27:00.023967738Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:27:00.027108064Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:27:00.029323346Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:27:00.031548469Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:27:00.034894235Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:27:00.037180592Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:27:00.03942519Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:27:00.042554717Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:27:00.044790744Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:27:00.047009618Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:27:00.050018272Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:27:00.05259621Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:27:00.054820073Z 12 PC: 12581 | Flush input buffer and input