Sample viewer

vx.netlux.org/Virus.DOS.Lyceum.1800

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:17.218706721Z 187 PC: 12a50 | UNKNOWN!
2018-12-17T22:54:17.219689481Z 42 PC: 12a90 | Get date 0x12a90: xor al, al
0x12a92: cmp dl, 0xd
0x12a95: jne 0x12a99
0x12a97: dec al
0x12a99: mov byte ptr [0x716], al
0x12a9c: mov ax, 0x3508
0x12a9f: int 0x21
0x12aa1: mov word ptr [0x708], bx
0x12aa5: mov word ptr [0x70a], es
0x12aa9: mov al, 9
0x12aab: int 0x21
0x12aad: mov word ptr [0x70c], bx
0x12ab1: mov word ptr [0x70e], es
0x12ab5: mov al, 0x21
0x12ab7: int 0x21
0x12ab9: mov word ptr [0x710], bx
0x12abd: mov word ptr [0x712], es
0x12ac1: mov dx, 0xd9
0x12ac4: mov ax, 0x2508
0x12ac7: int 0x21
2018-12-17T22:54:17.230823568Z 53 PC: 12aa1 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:54:17.232243282Z 53 PC: 12aad | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:54:17.233612219Z 53 PC: 12ab9 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:54:17.235949515Z 37 PC: 12ac9 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:54:17.237787003Z 37 PC: 12ad0 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:54:17.239648031Z 37 PC: 12ad7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11507,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:30:49.245404902Z 187 PC: 12a50 | UNKNOWN!
2018-12-25T12:30:49.254728715Z 42 PC: 12a90 | Get date 0x12a90: xor al, al
0x12a92: cmp dl, 0xd
0x12a95: jne 0x12a99
0x12a97: dec al
0x12a99: mov byte ptr [0x716], al
0x12a9c: mov ax, 0x3508
0x12a9f: int 0x21
0x12aa1: mov word ptr [0x708], bx
0x12aa5: mov word ptr [0x70a], es
0x12aa9: mov al, 9
0x12aab: int 0x21
0x12aad: mov word ptr [0x70c], bx
0x12ab1: mov word ptr [0x70e], es
0x12ab5: mov al, 0x21
0x12ab7: int 0x21
0x12ab9: mov word ptr [0x710], bx
0x12abd: mov word ptr [0x712], es
0x12ac1: mov dx, 0xd9
0x12ac4: mov ax, 0x2508
0x12ac7: int 0x21
2018-12-25T12:30:49.256810725Z 53 PC: 12aa1 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T12:30:49.257909313Z 53 PC: 12aad | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:30:49.259859995Z 53 PC: 12ab9 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:30:49.261101144Z 37 PC: 12ac9 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T12:30:49.262110456Z 37 PC: 12ad0 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:30:49.263123043Z 37 PC: 12ad7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')

{"DateBased":true,"Day":13,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11507,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:30:49.575038262Z 187 PC: 12a50 | UNKNOWN!
2018-12-25T12:30:49.576426902Z 42 PC: 12a90 | Get date 0x12a90: xor al, al
0x12a92: cmp dl, 0xd
0x12a95: jne 0x12a99
0x12a97: dec al
0x12a99: mov byte ptr [0x716], al
0x12a9c: mov ax, 0x3508
0x12a9f: int 0x21
0x12aa1: mov word ptr [0x708], bx
0x12aa5: mov word ptr [0x70a], es
0x12aa9: mov al, 9
0x12aab: int 0x21
0x12aad: mov word ptr [0x70c], bx
0x12ab1: mov word ptr [0x70e], es
0x12ab5: mov al, 0x21
0x12ab7: int 0x21
0x12ab9: mov word ptr [0x710], bx
0x12abd: mov word ptr [0x712], es
0x12ac1: mov dx, 0xd9
0x12ac4: mov ax, 0x2508
0x12ac7: int 0x21
2018-12-25T12:30:49.578837445Z 53 PC: 12aa1 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T12:30:49.579863407Z 53 PC: 12aad | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:30:49.581273454Z 53 PC: 12ab9 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:30:49.583432313Z 37 PC: 12ac9 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T12:30:49.584541979Z 37 PC: 12ad0 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:30:49.586319165Z 37 PC: 12ad7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')