Sample viewer

vx.netlux.org/Virus.DOS.Leathal.722.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:53.176345243Z 42 PC: 132ca | Get date 0x132ca: cmp dh, 9
0x132cd: jne 0x132db
0x132cf: push di
0x132d0: add di, 0xa5
0x132d4: mov dx, di
0x132d6: mov ah, 9
0x132d8: int 0x21
0x132da: pop di
0x132db: mov ax, 0x1a00
0x132de: push di
0x132df: add di, 0x1c
0x132e2: mov dx, di
0x132e4: int 0x21
0x132e6: pop di
0x132e7: xor bx, bx
0x132e9: xor cx, cx
0x132eb: mov ax, 0x4e00
0x132ee: push di
0x132ef: add di, 0x13
0x132f2: mov dx, di
2018-12-17T22:52:53.179006071Z 26 PC: 132e6 | Set disk transfer address
2018-12-17T22:52:53.180449813Z 78 PC: 132f7 | Find first file
2018-12-17T22:52:53.185705936Z 61 PC: 13318 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:52:53.19387441Z 63 PC: 13334 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:52:53.204610978Z 48 PC: 12f10 | Get DOS version
2018-12-17T22:52:53.20595318Z 101 PC: 12f31 | Get extended country info
2018-12-17T22:52:53.207611074Z 2 PC: 130de | Character output (Char = '5b')
2018-12-17T22:52:53.220128718Z 2 PC: 130e4 | Character output (Char = '53')
2018-12-17T22:52:53.222391368Z 2 PC: 130f0 | Character output (Char = '2c')
2018-12-17T22:52:53.224662375Z 2 PC: 130e4 | Character output (Char = '4e')
2018-12-17T22:52:53.227637594Z 2 PC: 130f8 | Character output (Char = '5d')
2018-12-17T22:52:53.230218552Z 2 PC: 130fe | Character output (Char = '3f')
2018-12-17T22:52:53.232825569Z 8 PC: 13136 | Console input without echo

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11033,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:29:46.274788298Z 42 PC: 132ca | Get date 0x132ca: cmp dh, 9
0x132cd: jne 0x132db
0x132cf: push di
0x132d0: add di, 0xa5
0x132d4: mov dx, di
0x132d6: mov ah, 9
0x132d8: int 0x21
0x132da: pop di
0x132db: mov ax, 0x1a00
0x132de: push di
0x132df: add di, 0x1c
0x132e2: mov dx, di
0x132e4: int 0x21
0x132e6: pop di
0x132e7: xor bx, bx
0x132e9: xor cx, cx
0x132eb: mov ax, 0x4e00
0x132ee: push di
0x132ef: add di, 0x13
0x132f2: mov dx, di
2018-12-25T12:29:46.277645123Z 26 PC: 132e6 | Set disk transfer address
2018-12-25T12:29:46.278658634Z 78 PC: 132f7 | Find first file
2018-12-25T12:29:46.284462903Z 61 PC: 13318 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:29:46.29151474Z 63 PC: 13334 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:29:46.297881944Z 48 PC: 12f10 | Get DOS version
2018-12-25T12:29:46.29935474Z 101 PC: 12f31 | Get extended country info
2018-12-25T12:29:46.301100328Z 2 PC: 130de | Character output (Char = '5b')
2018-12-25T12:29:46.303569571Z 2 PC: 130e4 | Character output (Char = '53')
2018-12-25T12:29:46.305575388Z 2 PC: 130f0 | Character output (Char = '2c')
2018-12-25T12:29:46.307606299Z 2 PC: 130e4 | Character output (See above)
2018-12-25T12:29:46.310562595Z 2 PC: 130f8 | Character output (Char = '5d')
2018-12-25T12:29:46.312637446Z 2 PC: 130fe | Character output (Char = '3f')
2018-12-25T12:29:46.315403572Z 8 PC: 13136 | Console input without echo

{"DateBased":true,"Day":1,"Month":9,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11033,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:29:46.42989574Z 42 PC: 132ca | Get date 0x132ca: cmp dh, 9
0x132cd: jne 0x132db
0x132cf: push di
0x132d0: add di, 0xa5
0x132d4: mov dx, di
0x132d6: mov ah, 9
0x132d8: int 0x21
0x132da: pop di
0x132db: mov ax, 0x1a00
0x132de: push di
0x132df: add di, 0x1c
0x132e2: mov dx, di
0x132e4: int 0x21
0x132e6: pop di
0x132e7: xor bx, bx
0x132e9: xor cx, cx
0x132eb: mov ax, 0x4e00
0x132ee: push di
0x132ef: add di, 0x13
0x132f2: mov dx, di
2018-12-25T12:29:46.432205768Z 9 PC: 132da | Display string (String= 'Leathal Virus Striked your fuking computer... Do not worry, I am not destructive...')
2018-12-25T12:29:46.436127107Z 26 PC: 132e6 | Set disk transfer address
2018-12-25T12:29:46.437666167Z 78 PC: 132f7 | Find first file
2018-12-25T12:29:46.443277703Z 61 PC: 13318 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:29:46.451294945Z 63 PC: 13334 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:29:46.458471365Z 48 PC: 12f10 | Get DOS version
2018-12-25T12:29:46.459811106Z 101 PC: 12f31 | Get extended country info
2018-12-25T12:29:46.462718981Z 2 PC: 130de | Character output (Char = '5b')
2018-12-25T12:29:46.465174796Z 2 PC: 130e4 | Character output (Char = '53')
2018-12-25T12:29:46.467991424Z 2 PC: 130f0 | Character output (Char = '2c')
2018-12-25T12:29:46.476865866Z 2 PC: 130e4 | Character output (See above)
2018-12-25T12:29:46.480164893Z 2 PC: 130f8 | Character output (Char = '5d')
2018-12-25T12:29:46.486844164Z 2 PC: 130fe | Character output (Char = '3f')
2018-12-25T12:29:46.490542102Z 8 PC: 13136 | Console input without echo