Sample viewer

vx.netlux.org/Virus.DOS.Andromeda.1024.c

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:00:06.916706556Z 42 PC: 1c636 | Get date 0x1c636: cmp dl, 5
0x1c639: jne 0x1c645
0x1c63b: cmp dh, 3
0x1c63e: jne 0x1c645
0x1c640: call 0x1c9db
0x1c643: hlt
0x1c644: hlt
0x1c645: mov si, 0xa3b4
0x1c648: mov ah, 0x30
0x1c64a: int 0x21
0x1c64c: cmp di, 0xa3a3
0x1c650: jne 0x1c666
0x1c652: mov bx, cs
0x1c654: mov ax, word ptr cs:[0x395]
0x1c658: sub bx, ax
0x1c65a: mov word ptr cs:[0x395], bx
0x1c65f: pop ds
0x1c660: pop es
0x1c661: ljmp ptr cs:[0x393]
0x1c666: mov ax, es
2018-12-17T22:00:06.920094036Z 48 PC: 1c64c | Get DOS version
2018-12-17T22:00:06.921257419Z 38 PC: 1c685 | Create PSP
2018-12-17T22:00:06.922585802Z 53 PC: 1c6be | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:00:06.924758542Z 37 PC: 1c6d1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:00:06.941055407Z 130 PC: 0 | UNKNOWN!

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":1122,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:42:53.319597354Z 42 PC: 1c636 | Get date 0x1c636: cmp dl, 5
0x1c639: jne 0x1c645
0x1c63b: cmp dh, 3
0x1c63e: jne 0x1c645
0x1c640: call 0x1c9db
0x1c643: hlt
0x1c644: hlt
0x1c645: mov si, 0xa3b4
0x1c648: mov ah, 0x30
0x1c64a: int 0x21
0x1c64c: cmp di, 0xa3a3
0x1c650: jne 0x1c666
0x1c652: mov bx, cs
0x1c654: mov ax, word ptr cs:[0x395]
0x1c658: sub bx, ax
0x1c65a: mov word ptr cs:[0x395], bx
0x1c65f: pop ds
0x1c660: pop es
0x1c661: ljmp ptr cs:[0x393]
0x1c666: mov ax, es
2018-12-25T11:42:53.322701342Z 48 PC: 1c64c | Get DOS version
2018-12-25T11:42:53.323780144Z 38 PC: 1c685 | Create PSP
2018-12-25T11:42:53.325017689Z 53 PC: 1c6be | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:42:53.32710214Z 37 PC: 1c6d1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:42:53.343292793Z 130 PC: 0 | UNKNOWN!

{"DateBased":true,"Day":5,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":1122,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:42:53.220936782Z 42 PC: 1c636 | Get date 0x1c636: cmp dl, 5
0x1c639: jne 0x1c645
0x1c63b: cmp dh, 3
0x1c63e: jne 0x1c645
0x1c640: call 0x1c9db
0x1c643: hlt
0x1c644: hlt
0x1c645: mov si, 0xa3b4
0x1c648: mov ah, 0x30
0x1c64a: int 0x21
0x1c64c: cmp di, 0xa3a3
0x1c650: jne 0x1c666
0x1c652: mov bx, cs
0x1c654: mov ax, word ptr cs:[0x395]
0x1c658: sub bx, ax
0x1c65a: mov word ptr cs:[0x395], bx
0x1c65f: pop ds
0x1c660: pop es
0x1c661: ljmp ptr cs:[0x393]
0x1c666: mov ax, es
2018-12-25T11:42:53.22361356Z 48 PC: 1c64c | Get DOS version
2018-12-25T11:42:53.224782075Z 38 PC: 1c685 | Create PSP
2018-12-25T11:42:53.22612698Z 53 PC: 1c6be | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:42:53.22824927Z 37 PC: 1c6d1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:42:53.246633379Z 130 PC: 0 | UNKNOWN!

{"DateBased":true,"Day":5,"Month":3,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":1122,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:42:53.709488377Z 42 PC: 1c636 | Get date 0x1c636: cmp dl, 5
0x1c639: jne 0x1c645
0x1c63b: cmp dh, 3
0x1c63e: jne 0x1c645
0x1c640: call 0x1c9db
0x1c643: hlt
0x1c644: hlt
0x1c645: mov si, 0xa3b4
0x1c648: mov ah, 0x30
0x1c64a: int 0x21
0x1c64c: cmp di, 0xa3a3
0x1c650: jne 0x1c666
0x1c652: mov bx, cs
0x1c654: mov ax, word ptr cs:[0x395]
0x1c658: sub bx, ax
0x1c65a: mov word ptr cs:[0x395], bx
0x1c65f: pop ds
0x1c660: pop es
0x1c661: ljmp ptr cs:[0x393]
0x1c666: mov ax, es
2018-12-25T11:42:53.712812589Z 64 PC: 1c883 | Write file or device (Write 1024 bytes on handle 0)
2018-12-25T11:42:53.721726949Z 66 PC: 1c88c | Move file pointer
2018-12-25T11:42:53.723252055Z 72 PC: 119f5 | Allocate memory