Sample viewer

vx.netlux.org/Virus.DOS.Breath.3457

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:41.530009779Z 48 PC: 13998 | Get DOS version
2018-12-17T22:52:41.532110335Z 82 PC: 13cc4 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:52:41.533824726Z 136 PC: 139a7 | UNKNOWN!
2018-12-17T22:52:41.534716641Z 73 PC: 139b3 | Release memory
2018-12-17T22:52:41.53635565Z 72 PC: 139ba | Allocate memory
2018-12-17T22:52:41.538894489Z 74 PC: 139cc | Reallocate memory
2018-12-17T22:52:41.540695823Z 74 PC: 139dc | Reallocate memory
2018-12-17T22:52:41.542648421Z 53 PC: 13a34 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:41.5446815Z 37 PC: 13a44 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:41.551006712Z 9 PC: 9ddfa | Display string (Could not find end pointer)
2018-12-17T22:52:41.561658381Z 26 PC: 9e0c0 | Set disk transfer address
2018-12-17T22:52:41.563674759Z 78 PC: 9e0ce | Find first file
2018-12-17T22:52:41.57067066Z 53 PC: 9e7f1 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:41.573255485Z 37 PC: 9e807 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:41.576634824Z 82 PC: 9ddfa | Get DOS internal pointers (SYSVARS)
2018-12-17T22:52:41.578648857Z 67 PC: 9e30a | Get or set file attributes
2018-12-17T22:52:41.585720091Z 67 PC: 9e325 | Get or set file attributes
2018-12-17T22:52:41.603458001Z 61 PC: 9de56 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:52:41.612073204Z 66 PC: 9e49b | Move file pointer
2018-12-17T22:52:41.614309435Z 66 PC: 9e49b | Move file pointer
2018-12-17T22:52:41.621378744Z 87 PC: 9de7c | Get or set file date and time
2018-12-17T22:52:41.623550544Z 63 PC: 9de95 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:52:41.630765107Z 66 PC: 9e49b | Move file pointer
2018-12-17T22:52:41.633051532Z 66 PC: 9e49b | Move file pointer
2018-12-17T22:52:41.636935036Z 64 PC: 9e4c4 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:52:41.64055697Z 66 PC: 9e49b | Move file pointer
2018-12-17T22:52:41.644951526Z 66 PC: 9e49b | Move file pointer
2018-12-17T22:52:41.647433909Z 64 PC: 9e78b | Write file or device (Write 1412 bytes on handle 5)
2018-12-17T22:52:41.660404083Z 66 PC: 9e49b | Move file pointer
2018-12-17T22:52:41.662071034Z 64 PC: 9e7d0 | Write file or device (Write 3457 bytes on handle 5)
2018-12-17T22:52:41.672131422Z 87 PC: 9ded7 | Get or set file date and time
2018-12-17T22:52:41.675426262Z 62 PC: 9dee5 | Close file
2018-12-17T22:52:41.697878969Z 67 PC: 9e342 | Get or set file attributes
2018-12-17T22:52:41.710113421Z 67 PC: 9e155 | Get or set file attributes
2018-12-17T22:52:41.716707838Z 67 PC: 9e155 | Get or set file attributes
2018-12-17T22:52:41.724356737Z 37 PC: 9e826 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:52:41.727911824Z 76 PC: 9ddfa | Terminate with return code (Return code = '36')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":10978,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:29:44.530635223Z 48 PC: 13998 | Get DOS version
2018-12-25T12:29:44.532157056Z 82 PC: 13cc4 | Get DOS internal pointers (SYSVARS)
2018-12-25T12:29:44.533785292Z 136 PC: 139a7 | UNKNOWN!
2018-12-25T12:29:44.534879101Z 73 PC: 139b3 | Release memory
2018-12-25T12:29:44.536778612Z 72 PC: 139ba | Allocate memory
2018-12-25T12:29:44.539481112Z 74 PC: 139cc | Reallocate memory
2018-12-25T12:29:44.541091914Z 74 PC: 139dc | Reallocate memory
2018-12-25T12:29:44.542702135Z 53 PC: 13a34 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:29:44.544526359Z 37 PC: 13a44 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:29:44.546024942Z 9 PC: 9ddfa | Display string (Could not find end pointer)
2018-12-25T12:29:44.558362882Z 26 PC: 9e0c0 | Set disk transfer address
2018-12-25T12:29:44.560668361Z 78 PC: 9e0ce | Find first file
2018-12-25T12:29:44.5679189Z 53 PC: 9e7f1 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:29:44.5697045Z 37 PC: 9e807 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:29:44.572532976Z 82 PC: 9ddfa | Get DOS internal pointers (SYSVARS) (See above)
2018-12-25T12:29:44.57396831Z 67 PC: 9e30a | Get or set file attributes
2018-12-25T12:29:44.580069512Z 67 PC: 9e325 | Get or set file attributes
2018-12-25T12:29:45.006991343Z 61 PC: 9de56 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:29:45.014323093Z 66 PC: 9e49b | Move file pointer
2018-12-25T12:29:45.015824978Z 66 PC: 9e49b | Move file pointer (See above)
2018-12-25T12:29:45.017546961Z 87 PC: 9de7c | Get or set file date and time
2018-12-25T12:29:45.019738128Z 63 PC: 9de95 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:29:45.028218648Z 66 PC: 9e49b | Move file pointer (See above)
2018-12-25T12:29:45.029652063Z 66 PC: 9e49b | Move file pointer (See above)
2018-12-25T12:29:45.032273884Z 64 PC: 9e4c4 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:29:45.035229588Z 66 PC: 9e49b | Move file pointer (See above)
2018-12-25T12:29:45.040894553Z 66 PC: 9e49b | Move file pointer (See above)
2018-12-25T12:29:45.042832705Z 64 PC: 9e78b | Write file or device (Write 1357 bytes on handle 5)
2018-12-25T12:29:45.049723449Z 66 PC: 9e49b | Move file pointer (See above)
2018-12-25T12:29:45.051455662Z 64 PC: 9e7d0 | Write file or device (Write 3457 bytes on handle 5)
2018-12-25T12:29:45.058367649Z 87 PC: 9ded7 | Get or set file date and time
2018-12-25T12:29:45.059591928Z 62 PC: 9dee5 | Close file
2018-12-25T12:29:45.065467795Z 67 PC: 9e342 | Get or set file attributes
2018-12-25T12:29:45.393793809Z 67 PC: 9e155 | Get or set file attributes
2018-12-25T12:29:45.400550538Z 67 PC: 9e155 | Get or set file attributes (See above)
2018-12-25T12:29:45.407527722Z 37 PC: 9e826 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:29:45.409704124Z 76 PC: 9ddfa | Terminate with return code (See above)

{"DateBased":true,"Day":1,"Month":8,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":10978,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:29:44.59871211Z 48 PC: 13998 | Get DOS version
2018-12-25T12:29:44.600633884Z 82 PC: 13cc4 | Get DOS internal pointers (SYSVARS)
2018-12-25T12:29:44.601942936Z 136 PC: 139a7 | UNKNOWN!
2018-12-25T12:29:44.602730441Z 73 PC: 139b3 | Release memory
2018-12-25T12:29:44.604586977Z 72 PC: 139ba | Allocate memory
2018-12-25T12:29:44.6065024Z 74 PC: 139cc | Reallocate memory
2018-12-25T12:29:44.608100367Z 74 PC: 139dc | Reallocate memory
2018-12-25T12:29:44.610769915Z 53 PC: 13a34 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:29:44.611953028Z 37 PC: 13a44 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:29:44.613283081Z 9 PC: 9ddfa | Display string (Could not find end pointer)
2018-12-25T12:29:44.632091644Z 26 PC: 9e0c0 | Set disk transfer address
2018-12-25T12:29:44.648095656Z 78 PC: 9e0ce | Find first file
2018-12-25T12:29:44.654057507Z 53 PC: 9e7f1 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:29:44.655614959Z 37 PC: 9e807 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:29:44.657618204Z 82 PC: 9ddfa | Get DOS internal pointers (SYSVARS) (See above)
2018-12-25T12:29:44.658806225Z 67 PC: 9e30a | Get or set file attributes
2018-12-25T12:29:44.662511342Z 67 PC: 9e325 | Get or set file attributes
2018-12-25T12:29:44.677492344Z 61 PC: 9de56 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:29:44.684013207Z 66 PC: 9e49b | Move file pointer
2018-12-25T12:29:44.685633893Z 66 PC: 9e49b | Move file pointer (See above)
2018-12-25T12:29:44.687947518Z 87 PC: 9de7c | Get or set file date and time
2018-12-25T12:29:44.689657492Z 63 PC: 9de95 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:29:44.696707423Z 66 PC: 9e49b | Move file pointer (See above)
2018-12-25T12:29:44.698672051Z 66 PC: 9e49b | Move file pointer (See above)
2018-12-25T12:29:44.700101615Z 64 PC: 9e4c4 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:29:44.702998213Z 66 PC: 9e49b | Move file pointer (See above)
2018-12-25T12:29:44.717459752Z 66 PC: 9e49b | Move file pointer (See above)
2018-12-25T12:29:44.719627475Z 64 PC: 9e78b | Write file or device (Write 1223 bytes on handle 5)
2018-12-25T12:29:44.729397445Z 66 PC: 9e49b | Move file pointer (See above)
2018-12-25T12:29:44.731809765Z 64 PC: 9e7d0 | Write file or device (Write 3457 bytes on handle 5)
2018-12-25T12:29:44.740447118Z 87 PC: 9ded7 | Get or set file date and time
2018-12-25T12:29:44.753232117Z 62 PC: 9dee5 | Close file
2018-12-25T12:29:44.763695028Z 67 PC: 9e342 | Get or set file attributes
2018-12-25T12:29:44.774249992Z 67 PC: 9e155 | Get or set file attributes
2018-12-25T12:29:44.780676038Z 67 PC: 9e155 | Get or set file attributes (See above)
2018-12-25T12:29:44.789004311Z 37 PC: 9e826 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:29:44.79040314Z 76 PC: 9ddfa | Terminate with return code (See above)

{"DateBased":true,"Day":7,"Month":8,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":10978,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:29:44.746991901Z 48 PC: 13998 | Get DOS version
2018-12-25T12:29:44.74986243Z 82 PC: 13cc4 | Get DOS internal pointers (SYSVARS)
2018-12-25T12:29:44.751331806Z 136 PC: 139a7 | UNKNOWN!
2018-12-25T12:29:44.752336283Z 73 PC: 139b3 | Release memory
2018-12-25T12:29:44.75401274Z 72 PC: 139ba | Allocate memory
2018-12-25T12:29:44.759028016Z 74 PC: 139cc | Reallocate memory
2018-12-25T12:29:44.762348581Z 74 PC: 139dc | Reallocate memory
2018-12-25T12:29:44.764083711Z 53 PC: 13a34 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:29:44.766747477Z 37 PC: 13a44 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:29:44.768420536Z 9 PC: 9ddfa | Display string (Could not find end pointer)
2018-12-25T12:29:44.779282407Z 26 PC: 9e0c0 | Set disk transfer address
2018-12-25T12:29:44.781194029Z 78 PC: 9e0ce | Find first file
2018-12-25T12:29:44.787479847Z 53 PC: 9e7f1 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:29:44.788944136Z 37 PC: 9e807 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:29:44.791864378Z 82 PC: 9ddfa | Get DOS internal pointers (SYSVARS) (See above)
2018-12-25T12:29:44.79331299Z 67 PC: 9e30a | Get or set file attributes
2018-12-25T12:29:44.798949834Z 67 PC: 9e325 | Get or set file attributes
2018-12-25T12:29:44.815660208Z 61 PC: 9de56 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:29:44.822519983Z 66 PC: 9e49b | Move file pointer
2018-12-25T12:29:44.824055284Z 66 PC: 9e49b | Move file pointer (See above)
2018-12-25T12:29:44.841460029Z 87 PC: 9de7c | Get or set file date and time
2018-12-25T12:29:44.843452397Z 63 PC: 9de95 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:29:44.849093017Z 66 PC: 9e49b | Move file pointer (See above)
2018-12-25T12:29:44.85121917Z 66 PC: 9e49b | Move file pointer (See above)
2018-12-25T12:29:44.855195187Z 64 PC: 9e4c4 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:29:44.858382342Z 66 PC: 9e49b | Move file pointer (See above)
2018-12-25T12:29:44.862396882Z 66 PC: 9e49b | Move file pointer (See above)
2018-12-25T12:29:44.864705658Z 64 PC: 9e78b | Write file or device (Write 1125 bytes on handle 5)
2018-12-25T12:29:44.874352421Z 66 PC: 9e49b | Move file pointer (See above)
2018-12-25T12:29:44.875589886Z 64 PC: 9e7d0 | Write file or device (Write 3457 bytes on handle 5)
2018-12-25T12:29:44.892698325Z 87 PC: 9ded7 | Get or set file date and time
2018-12-25T12:29:44.900828392Z 62 PC: 9dee5 | Close file
2018-12-25T12:29:44.909440178Z 67 PC: 9e342 | Get or set file attributes
2018-12-25T12:29:44.925467792Z 67 PC: 9e155 | Get or set file attributes
2018-12-25T12:29:44.95051669Z 67 PC: 9e155 | Get or set file attributes (See above)
2018-12-25T12:29:44.956344781Z 37 PC: 9e826 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:29:44.960518487Z 76 PC: 9ddfa | Terminate with return code (See above)