Sample viewer

vx.netlux.org/Virus.DOS.Mirror.1056.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:37.71863246Z 53 PC: 13412 | Get interrupt vector (Interrupt = '100' AKA 'Set wait for external event flag')
2018-12-17T22:53:37.721089807Z 74 PC: 13437 | Reallocate memory
2018-12-17T22:53:37.724713187Z 72 PC: 13440 | Allocate memory
2018-12-17T22:53:37.726282162Z 37 PC: 13468 | Set interrupt vector (Interrupt = '100' AKA 'Set wait for external event flag')
2018-12-17T22:53:37.728192845Z 53 PC: 1346f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:37.729360957Z 37 PC: 1347f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:37.730484456Z 42 PC: 13483 | Get date 0x13483: cmp cx, 0x7c9
0x13487: jb 0x134a4
0x13489: mov ax, 0x3508
0x1348c: int 0x21
0x1348e: mov word ptr [0x128], es
0x13492: mov word ptr [0x126], bx
0x13496: mov word ptr [0x12a], 0
0x1349c: mov ax, 0x2508
0x1349f: mov dx, 0xd0
0x134a2: int 0x21
0x134a4: pop es
0x134a5: mov ax, es
0x134a7: add word ptr cs:[0xbe], ax
0x134ac: add word ptr cs:[0xbe], 0x10
0x134b2: pop bp
0x134b3: pop di
0x134b4: pop si
0x134b5: pop ds
0x134b6: pop es
0x134b7: pop dx
2018-12-17T22:53:37.732821733Z 53 PC: 1348e | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:53:37.734468733Z 37 PC: 134a4 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:53:37.735766485Z 9 PC: 133f2 | Display string (Could not find end pointer)
2018-12-17T22:53:37.739966438Z 76 PC: 133f8 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11288,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:30:17.752327634Z 53 PC: 13412 | Get interrupt vector (Interrupt = '100' AKA 'Set wait for external event flag')
2018-12-25T12:30:17.754734582Z 74 PC: 13437 | Reallocate memory
2018-12-25T12:30:17.75610204Z 72 PC: 13440 | Allocate memory
2018-12-25T12:30:17.757546937Z 37 PC: 13468 | Set interrupt vector (Interrupt = '100' AKA 'Set wait for external event flag')
2018-12-25T12:30:17.759125358Z 53 PC: 1346f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:30:17.760337301Z 37 PC: 1347f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:30:17.761615612Z 42 PC: 13483 | Get date 0x13483: cmp cx, 0x7c9
0x13487: jb 0x134a4
0x13489: mov ax, 0x3508
0x1348c: int 0x21
0x1348e: mov word ptr [0x128], es
0x13492: mov word ptr [0x126], bx
0x13496: mov word ptr [0x12a], 0
0x1349c: mov ax, 0x2508
0x1349f: mov dx, 0xd0
0x134a2: int 0x21
0x134a4: pop es
0x134a5: mov ax, es
0x134a7: add word ptr cs:[0xbe], ax
0x134ac: add word ptr cs:[0xbe], 0x10
0x134b2: pop bp
0x134b3: pop di
0x134b4: pop si
0x134b5: pop ds
0x134b6: pop es
0x134b7: pop dx
2018-12-25T12:30:17.765022857Z 9 PC: 133f2 | Display string (Could not find end pointer)
2018-12-25T12:30:17.770953468Z 76 PC: 133f8 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1993,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11288,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:30:17.810405375Z 53 PC: 13412 | Get interrupt vector (Interrupt = '100' AKA 'Set wait for external event flag')
2018-12-25T12:30:17.812857489Z 74 PC: 13437 | Reallocate memory
2018-12-25T12:30:17.814365842Z 72 PC: 13440 | Allocate memory
2018-12-25T12:30:17.81603503Z 37 PC: 13468 | Set interrupt vector (Interrupt = '100' AKA 'Set wait for external event flag')
2018-12-25T12:30:17.817635932Z 53 PC: 1346f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:30:17.819186063Z 37 PC: 1347f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:30:17.820617172Z 42 PC: 13483 | Get date 0x13483: cmp cx, 0x7c9
0x13487: jb 0x134a4
0x13489: mov ax, 0x3508
0x1348c: int 0x21
0x1348e: mov word ptr [0x128], es
0x13492: mov word ptr [0x126], bx
0x13496: mov word ptr [0x12a], 0
0x1349c: mov ax, 0x2508
0x1349f: mov dx, 0xd0
0x134a2: int 0x21
0x134a4: pop es
0x134a5: mov ax, es
0x134a7: add word ptr cs:[0xbe], ax
0x134ac: add word ptr cs:[0xbe], 0x10
0x134b2: pop bp
0x134b3: pop di
0x134b4: pop si
0x134b5: pop ds
0x134b6: pop es
0x134b7: pop dx
2018-12-25T12:30:17.823437259Z 53 PC: 1348e | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T12:30:17.825279633Z 37 PC: 134a4 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T12:30:17.826984022Z 9 PC: 133f2 | Display string (Could not find end pointer)
2018-12-25T12:30:17.833837319Z 76 PC: 133f8 | Terminate with return code (Return code = '0')