Sample viewer

vx.netlux.org/Virus.DOS.Xtar.1605

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:40.658301676Z 11 PC: 143f9 | Get input status
2018-12-17T22:55:40.662018621Z 74 PC: 12eb5 | Reallocate memory
2018-12-17T22:55:40.663649525Z 53 PC: 12ebf | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:40.665092588Z 37 PC: 12ed3 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:40.666725887Z 75 PC: 12f13 | Execute program
2018-12-17T22:55:40.673218426Z 42 PC: 12f27 | Get date 0x12f27: cmp dh, 6
0x12f2a: jne 0x12f34
0x12f2c: cmp dl, 3
0x12f2f: jne 0x12f34
0x12f31: call 0x12f40
0x12f34: mov ax, 0x3100
0x12f37: mov dx, 0x94e
0x12f3a: mov cl, 4
0x12f3c: shr dx, cl
0x12f3e: int 0x21
0x12f40: call 0x12fc2
0x12f43: mov ah, 2
0x12f45: mov bh, 0
0x12f47: mov dx, 0x171a
0x12f4a: int 0x10
0x12f4c: mov si, 0x179
0x12f4f: mov di, si
0x12f51: mov cx, 0x1d
0x12f54: lodsb al, byte ptr [si]
0x12f55: not al
2018-12-17T22:55:40.675344445Z 49 PC: 12f40 | Terminate and stay resident (Return code = '0' | Memory size = '148')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11964,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:31:39.283716484Z 11 PC: 143f9 | Get input status
2018-12-25T12:31:39.286989851Z 74 PC: 12eb5 | Reallocate memory
2018-12-25T12:31:39.288020638Z 53 PC: 12ebf | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:31:39.288947941Z 37 PC: 12ed3 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:31:39.290560323Z 75 PC: 12f13 | Execute program
2018-12-25T12:31:39.294635638Z 42 PC: 12f27 | Get date 0x12f27: cmp dh, 6
0x12f2a: jne 0x12f34
0x12f2c: cmp dl, 3
0x12f2f: jne 0x12f34
0x12f31: call 0x12f40
0x12f34: mov ax, 0x3100
0x12f37: mov dx, 0x94e
0x12f3a: mov cl, 4
0x12f3c: shr dx, cl
0x12f3e: int 0x21
0x12f40: call 0x12fc2
0x12f43: mov ah, 2
0x12f45: mov bh, 0
0x12f47: mov dx, 0x171a
0x12f4a: int 0x10
0x12f4c: mov si, 0x179
0x12f4f: mov di, si
0x12f51: mov cx, 0x1d
0x12f54: lodsb al, byte ptr [si]
0x12f55: not al
2018-12-25T12:31:39.296218178Z 49 PC: 12f40 | Terminate and stay resident (Return code = '0' | Memory size = '148')

{"DateBased":true,"Day":1,"Month":6,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11964,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:31:39.363861275Z 11 PC: 143f9 | Get input status
2018-12-25T12:31:39.372417939Z 74 PC: 12eb5 | Reallocate memory
2018-12-25T12:31:39.373899689Z 53 PC: 12ebf | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:31:39.375590509Z 37 PC: 12ed3 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:31:39.377787237Z 75 PC: 12f13 | Execute program
2018-12-25T12:31:39.385005925Z 42 PC: 12f27 | Get date 0x12f27: cmp dh, 6
0x12f2a: jne 0x12f34
0x12f2c: cmp dl, 3
0x12f2f: jne 0x12f34
0x12f31: call 0x12f40
0x12f34: mov ax, 0x3100
0x12f37: mov dx, 0x94e
0x12f3a: mov cl, 4
0x12f3c: shr dx, cl
0x12f3e: int 0x21
0x12f40: call 0x12fc2
0x12f43: mov ah, 2
0x12f45: mov bh, 0
0x12f47: mov dx, 0x171a
0x12f4a: int 0x10
0x12f4c: mov si, 0x179
0x12f4f: mov di, si
0x12f51: mov cx, 0x1d
0x12f54: lodsb al, byte ptr [si]
0x12f55: not al
2018-12-25T12:31:39.387697416Z 49 PC: 12f40 | Terminate and stay resident (Return code = '0' | Memory size = '148')

{"DateBased":true,"Day":3,"Month":6,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11964,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:31:39.773956143Z 11 PC: 143f9 | Get input status
2018-12-25T12:31:39.777851876Z 74 PC: 12eb5 | Reallocate memory
2018-12-25T12:31:39.779558274Z 53 PC: 12ebf | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:31:39.781663738Z 37 PC: 12ed3 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:31:39.783469845Z 75 PC: 12f13 | Execute program
2018-12-25T12:31:39.792182233Z 42 PC: 12f27 | Get date 0x12f27: cmp dh, 6
0x12f2a: jne 0x12f34
0x12f2c: cmp dl, 3
0x12f2f: jne 0x12f34
0x12f31: call 0x12f40
0x12f34: mov ax, 0x3100
0x12f37: mov dx, 0x94e
0x12f3a: mov cl, 4
0x12f3c: shr dx, cl
0x12f3e: int 0x21
0x12f40: call 0x12fc2
0x12f43: mov ah, 2
0x12f45: mov bh, 0
0x12f47: mov dx, 0x171a
0x12f4a: int 0x10
0x12f4c: mov si, 0x179
0x12f4f: mov di, si
0x12f51: mov cx, 0x1d
0x12f54: lodsb al, byte ptr [si]
0x12f55: not al
2018-12-25T12:31:39.796443382Z 9 PC: 12f61 | Display string (String= 'June 3, Its Sparcle's Birthday')
2018-12-25T12:31:52.323295829Z 49 PC: 12f40 | Terminate and stay resident (Return code = '0' | Memory size = '148')