Sample viewer

vx.netlux.org/Virus.DOS.MadSatan.19033

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:54.022641818Z 53 PC: 14854 | Get interrupt vector (Interrupt = '99' AKA 'Get DBCS lead byte table pointer')
2018-12-17T22:51:54.025226534Z 53 PC: 14863 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:54.027370331Z 74 PC: 12b01 | Reallocate memory
2018-12-17T22:51:54.029228442Z 37 PC: 12b09 | Set interrupt vector (Interrupt = '99' AKA 'Get DBCS lead byte table pointer')
2018-12-17T22:51:54.031075181Z 37 PC: 12b11 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:54.033705813Z 42 PC: 12b18 | Get date 0x12b18: cmp dh, 0xc
0x12b1b: jne 0x12b4e
0x12b1d: cmp dl, 0x17
0x12b20: jbe 0x12b4e
0x12b22: cmp dl, 0x1b
0x12b25: jae 0x12b4e
0x12b27: mov ax, 0x3508
0x12b2a: pushf
0x12b2b: lcall ptr [0x5e2]
0x12b2f: mov word ptr [0x5ec], es
0x12b33: mov word ptr [0x5ea], bx
0x12b37: mov dx, 0x190
0x12b3a: mov ax, 0x2508
0x12b3d: pushf
0x12b3e: lcall ptr [0x5e2]
0x12b42: mov word ptr [0x272], 0
0x12b48: mov word ptr [0x273], 0
0x12b4e: mov ax, ds
0x12b50: mov es, ax
0x12b52: sub ax, 0x10
2018-12-17T22:51:54.036810435Z 75 PC: 12b6c | Execute program
2018-12-17T22:51:54.054649276Z 53 PC: 15054 | Get interrupt vector (Interrupt = '99' AKA 'Get DBCS lead byte table pointer')
2018-12-17T22:51:54.057170923Z 76 PC: 1372b | Terminate with return code (Return code = '0')
2018-12-17T22:51:54.060712115Z 49 PC: 12b91 | Terminate and stay resident (Return code = '92' | Memory size = '122')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":10703,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:28:54.558066922Z 53 PC: 14854 | Get interrupt vector (Interrupt = '99' AKA 'Get DBCS lead byte table pointer')
2018-12-25T12:28:54.560624181Z 53 PC: 14863 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:28:54.562014527Z 74 PC: 12b01 | Reallocate memory
2018-12-25T12:28:54.563562415Z 37 PC: 12b09 | Set interrupt vector (Interrupt = '99' AKA 'Get DBCS lead byte table pointer')
2018-12-25T12:28:54.565227434Z 37 PC: 12b11 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:28:54.566257817Z 42 PC: 12b18 | Get date 0x12b18: cmp dh, 0xc
0x12b1b: jne 0x12b4e
0x12b1d: cmp dl, 0x17
0x12b20: jbe 0x12b4e
0x12b22: cmp dl, 0x1b
0x12b25: jae 0x12b4e
0x12b27: mov ax, 0x3508
0x12b2a: pushf
0x12b2b: lcall ptr [0x5e2]
0x12b2f: mov word ptr [0x5ec], es
0x12b33: mov word ptr [0x5ea], bx
0x12b37: mov dx, 0x190
0x12b3a: mov ax, 0x2508
0x12b3d: pushf
0x12b3e: lcall ptr [0x5e2]
0x12b42: mov word ptr [0x272], 0
0x12b48: mov word ptr [0x273], 0
0x12b4e: mov ax, ds
0x12b50: mov es, ax
0x12b52: sub ax, 0x10
2018-12-25T12:28:54.568232523Z 75 PC: 12b6c | Execute program
2018-12-25T12:28:54.583327049Z 53 PC: 15054 | Get interrupt vector (Interrupt = '99' AKA 'Get DBCS lead byte table pointer')
2018-12-25T12:28:54.584518418Z 76 PC: 1372b | Terminate with return code (Return code = '0')
2018-12-25T12:28:54.587405464Z 49 PC: 12b91 | Terminate and stay resident (Return code = '92' | Memory size = '122')

{"DateBased":true,"Day":1,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":10703,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:28:54.746992012Z 53 PC: 14854 | Get interrupt vector (Interrupt = '99' AKA 'Get DBCS lead byte table pointer')
2018-12-25T12:28:54.749483782Z 53 PC: 14863 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:28:54.751095472Z 74 PC: 12b01 | Reallocate memory
2018-12-25T12:28:54.752688585Z 37 PC: 12b09 | Set interrupt vector (Interrupt = '99' AKA 'Get DBCS lead byte table pointer')
2018-12-25T12:28:54.754709381Z 37 PC: 12b11 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:28:54.756106782Z 42 PC: 12b18 | Get date 0x12b18: cmp dh, 0xc
0x12b1b: jne 0x12b4e
0x12b1d: cmp dl, 0x17
0x12b20: jbe 0x12b4e
0x12b22: cmp dl, 0x1b
0x12b25: jae 0x12b4e
0x12b27: mov ax, 0x3508
0x12b2a: pushf
0x12b2b: lcall ptr [0x5e2]
0x12b2f: mov word ptr [0x5ec], es
0x12b33: mov word ptr [0x5ea], bx
0x12b37: mov dx, 0x190
0x12b3a: mov ax, 0x2508
0x12b3d: pushf
0x12b3e: lcall ptr [0x5e2]
0x12b42: mov word ptr [0x272], 0
0x12b48: mov word ptr [0x273], 0
0x12b4e: mov ax, ds
0x12b50: mov es, ax
0x12b52: sub ax, 0x10
2018-12-25T12:28:54.758527346Z 75 PC: 12b6c | Execute program
2018-12-25T12:28:54.775093118Z 53 PC: 15054 | Get interrupt vector (Interrupt = '99' AKA 'Get DBCS lead byte table pointer')
2018-12-25T12:28:54.776651277Z 76 PC: 1372b | Terminate with return code (Return code = '0')
2018-12-25T12:28:54.780089507Z 49 PC: 12b91 | Terminate and stay resident (Return code = '92' | Memory size = '122')

{"DateBased":true,"Day":23,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":10703,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:28:54.829865962Z 53 PC: 14854 | Get interrupt vector (Interrupt = '99' AKA 'Get DBCS lead byte table pointer')
2018-12-25T12:28:54.831359915Z 53 PC: 14863 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:28:54.833110609Z 74 PC: 12b01 | Reallocate memory
2018-12-25T12:28:54.834434008Z 37 PC: 12b09 | Set interrupt vector (Interrupt = '99' AKA 'Get DBCS lead byte table pointer')
2018-12-25T12:28:54.835765373Z 37 PC: 12b11 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:28:54.837167656Z 42 PC: 12b18 | Get date 0x12b18: cmp dh, 0xc
0x12b1b: jne 0x12b4e
0x12b1d: cmp dl, 0x17
0x12b20: jbe 0x12b4e
0x12b22: cmp dl, 0x1b
0x12b25: jae 0x12b4e
0x12b27: mov ax, 0x3508
0x12b2a: pushf
0x12b2b: lcall ptr [0x5e2]
0x12b2f: mov word ptr [0x5ec], es
0x12b33: mov word ptr [0x5ea], bx
0x12b37: mov dx, 0x190
0x12b3a: mov ax, 0x2508
0x12b3d: pushf
0x12b3e: lcall ptr [0x5e2]
0x12b42: mov word ptr [0x272], 0
0x12b48: mov word ptr [0x273], 0
0x12b4e: mov ax, ds
0x12b50: mov es, ax
0x12b52: sub ax, 0x10
2018-12-25T12:28:54.839216252Z 75 PC: 12b6c | Execute program
2018-12-25T12:28:54.854250717Z 53 PC: 15054 | Get interrupt vector (Interrupt = '99' AKA 'Get DBCS lead byte table pointer')
2018-12-25T12:28:54.855543024Z 76 PC: 1372b | Terminate with return code (Return code = '0')
2018-12-25T12:28:54.858448575Z 49 PC: 12b91 | Terminate and stay resident (Return code = '92' | Memory size = '122')