Sample viewer

vx.netlux.org/Virus.DOS.Itv.454

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:00:12.993956614Z 47 PC: 12abf | Get disk transfer address
2018-12-17T22:00:12.995364224Z 26 PC: 12acf | Set disk transfer address
2018-12-17T22:00:12.996329685Z 37 PC: 12ad8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:00:12.997508013Z 78 PC: 12b47 | Find first file
2018-12-17T22:00:13.003690497Z 67 PC: 12b7c | Get or set file attributes
2018-12-17T22:00:13.018952903Z 61 PC: 12b85 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:00:13.025330729Z 63 PC: 12b94 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:00:13.03197981Z 66 PC: 12ba4 | Move file pointer
2018-12-17T22:00:13.03351375Z 64 PC: 12bb8 | Write file or device (Write 454 bytes on handle 5)
2018-12-17T22:00:13.041736664Z 66 PC: 12bc8 | Move file pointer
2018-12-17T22:00:13.043845632Z 64 PC: 12bd5 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:00:13.060537128Z 87 PC: 12be8 | Get or set file date and time
2018-12-17T22:00:13.061960598Z 62 PC: 12bec | Close file
2018-12-17T22:00:13.070243972Z 67 PC: 12bfb | Get or set file attributes
2018-12-17T22:00:13.080687304Z 26 PC: 12c04 | Set disk transfer address
2018-12-17T22:00:13.081820587Z 37 PC: 12c0e | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:00:13.08289605Z 42 PC: 12c13 | Get date 0x12c13: cmp dx, 0x50d
0x12c17: jne 0x12c29
0x12c19: push es
0x12c1a: mov ah, 0x52
0x12c1c: int 0x21
0x12c1e: mov es, word ptr es:[bx - 2]
0x12c22: mov byte ptr es:[0], 0
0x12c28: pop es
0x12c29: pop ax
0x12c2a: xor bx, bx
0x12c2c: xor cx, cx
0x12c2e: xor dx, dx
0x12c30: xor si, si
0x12c32: xor di, di
0x12c34: mov bp, 0x100
0x12c37: push bp
0x12c38: xor bp, bp
0x12c3a: ret
0x12c3b: add sp, 6
0x12c3e: pop ax
2018-12-17T22:00:13.085447839Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":1134,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:42:54.810867252Z 47 PC: 12abf | Get disk transfer address
2018-12-25T11:42:54.812580545Z 26 PC: 12acf | Set disk transfer address
2018-12-25T11:42:54.813649947Z 37 PC: 12ad8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:42:54.814802273Z 78 PC: 12b47 | Find first file
2018-12-25T11:42:54.821133166Z 67 PC: 12b7c | Get or set file attributes
2018-12-25T11:42:54.835987716Z 61 PC: 12b85 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:42:54.842156673Z 63 PC: 12b94 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:42:54.848427585Z 66 PC: 12ba4 | Move file pointer
2018-12-25T11:42:54.857076522Z 64 PC: 12bb8 | Write file or device (Write 454 bytes on handle 5)
2018-12-25T11:42:54.864613224Z 66 PC: 12bc8 | Move file pointer
2018-12-25T11:42:54.866026193Z 64 PC: 12bd5 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:42:54.872662205Z 87 PC: 12be8 | Get or set file date and time
2018-12-25T11:42:54.873968724Z 62 PC: 12bec | Close file
2018-12-25T11:42:54.881764474Z 67 PC: 12bfb | Get or set file attributes
2018-12-25T11:42:54.891700814Z 26 PC: 12c04 | Set disk transfer address
2018-12-25T11:42:54.892807874Z 37 PC: 12c0e | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:42:54.89385103Z 42 PC: 12c13 | Get date 0x12c13: cmp dx, 0x50d
0x12c17: jne 0x12c29
0x12c19: push es
0x12c1a: mov ah, 0x52
0x12c1c: int 0x21
0x12c1e: mov es, word ptr es:[bx - 2]
0x12c22: mov byte ptr es:[0], 0
0x12c28: pop es
0x12c29: pop ax
0x12c2a: xor bx, bx
0x12c2c: xor cx, cx
0x12c2e: xor dx, dx
0x12c30: xor si, si
0x12c32: xor di, di
0x12c34: mov bp, 0x100
0x12c37: push bp
0x12c38: xor bp, bp
0x12c3a: ret
0x12c3b: add sp, 6
0x12c3e: pop ax
2018-12-25T11:42:54.896899004Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":13,"Month":5,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":1134,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:42:55.057020947Z 47 PC: 12abf | Get disk transfer address
2018-12-25T11:42:55.058822008Z 26 PC: 12acf | Set disk transfer address
2018-12-25T11:42:55.060030463Z 37 PC: 12ad8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:42:55.061198815Z 78 PC: 12b47 | Find first file
2018-12-25T11:42:55.068491878Z 67 PC: 12b7c | Get or set file attributes
2018-12-25T11:42:55.083680295Z 61 PC: 12b85 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:42:55.090241315Z 63 PC: 12b94 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:42:55.096795351Z 66 PC: 12ba4 | Move file pointer
2018-12-25T11:42:55.099018547Z 64 PC: 12bb8 | Write file or device (Write 454 bytes on handle 5)
2018-12-25T11:42:55.10714076Z 66 PC: 12bc8 | Move file pointer
2018-12-25T11:42:55.108824437Z 64 PC: 12bd5 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:42:55.116573548Z 87 PC: 12be8 | Get or set file date and time
2018-12-25T11:42:55.118302334Z 62 PC: 12bec | Close file
2018-12-25T11:42:55.126154507Z 67 PC: 12bfb | Get or set file attributes
2018-12-25T11:42:55.13643611Z 26 PC: 12c04 | Set disk transfer address
2018-12-25T11:42:55.137674011Z 37 PC: 12c0e | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:42:55.138873809Z 42 PC: 12c13 | Get date 0x12c13: cmp dx, 0x50d
0x12c17: jne 0x12c29
0x12c19: push es
0x12c1a: mov ah, 0x52
0x12c1c: int 0x21
0x12c1e: mov es, word ptr es:[bx - 2]
0x12c22: mov byte ptr es:[0], 0
0x12c28: pop es
0x12c29: pop ax
0x12c2a: xor bx, bx
0x12c2c: xor cx, cx
0x12c2e: xor dx, dx
0x12c30: xor si, si
0x12c32: xor di, di
0x12c34: mov bp, 0x100
0x12c37: push bp
0x12c38: xor bp, bp
0x12c3a: ret
0x12c3b: add sp, 6
0x12c3e: pop ax
2018-12-25T11:42:55.14265116Z 82 PC: 12c1e | Get DOS internal pointers (SYSVARS)
2018-12-25T11:42:55.14407749Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')
2018-12-25T11:42:55.151894903Z 77 PC: 11fe0 | Get program return code
2018-12-25T11:42:55.154073024Z 72 PC: 12174 | Allocate memory
2018-12-25T11:42:55.156004014Z 72 PC: 1218d | Allocate memory
2018-12-25T11:42:55.15778364Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-25T11:42:55.160287846Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.163951193Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.166127104Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.168453089Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.170976069Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.173518822Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.176028846Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.179318008Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.181462792Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.184038372Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.190050896Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.192417942Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.194862169Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.197967615Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.214788891Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.216821645Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.222914164Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.224928257Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.226897742Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.229599262Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.231657589Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.233655805Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.236358947Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.238444045Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.240559807Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.242856205Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.246333085Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.248845837Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.252090108Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.254868475Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.257606661Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.260153341Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.262386236Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.264521174Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.267559145Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.269242948Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.270834919Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.272577834Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.274427211Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.27588897Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.277651433Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.279368655Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.280866863Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.282531964Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.284635805Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.286170877Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.297506507Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.299133123Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.300598129Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.302605598Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.304118449Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.305469604Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.307194952Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.308700342Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.310866604Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.313422792Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.315373459Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.317258362Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.319797789Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.321816576Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.323722085Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:42:55.326436694Z 2 PC: 1268d | Character output (See above)