Sample viewer

vx.netlux.org/Virus.DOS.Paradigma.1231

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:05.465764524Z 48 PC: 12a63 | Get DOS version
2018-12-17T22:56:05.467510171Z 42 PC: 12a71 | Get date 0x12a71: cmp dh, 7
0x12a74: jne 0x12a7e
0x12a76: cmp dl, 4
0x12a79: jne 0x12a7e
0x12a7b: jmp 0x12df5
0x12a7e: cmp al, 2
0x12a80: jne 0x12a96
0x12a82: cmp dl, 5
0x12a85: jne 0x12a96
0x12a87: jmp 0x12df5
0x12a8a: sub ax, 0x233e
0x12a8d: dec cx
0x12a8e: outsb dx, byte ptr [si]
0x12a8f: push sp
0x12a90: push dx
0x12a92: inc cx
0x12a94: outsb dx, byte ptr [si]
0x12a95: inc di
0x12a96: mov ax, 0x3621
0x12a99: dec ah
2018-12-17T22:56:05.480185079Z 53 PC: 12a9d | Get interrupt vector (Interrupt = '33' AKA 'Random read')

{"DateBased":true,"Day":2,"Month":7,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12103,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:00.357614744Z 48 PC: 12a63 | Get DOS version
2018-12-25T12:32:00.358885766Z 42 PC: 12a71 | Get date 0x12a71: cmp dh, 7
0x12a74: jne 0x12a7e
0x12a76: cmp dl, 4
0x12a79: jne 0x12a7e
0x12a7b: jmp 0x12df5
0x12a7e: cmp al, 2
0x12a80: jne 0x12a96
0x12a82: cmp dl, 5
0x12a85: jne 0x12a96
0x12a87: jmp 0x12df5
0x12a8a: sub ax, 0x233e
0x12a8d: dec cx
0x12a8e: outsb dx, byte ptr [si]
0x12a8f: push sp
0x12a90: push dx
0x12a92: inc cx
0x12a94: outsb dx, byte ptr [si]
0x12a95: inc di
0x12a96: mov ax, 0x3621
0x12a99: dec ah
2018-12-25T12:32:00.3625145Z 53 PC: 12a9d | Get interrupt vector (Interrupt = '33' AKA 'Random read')

{"DateBased":true,"Day":4,"Month":7,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12103,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:00.363981803Z 48 PC: 12a63 | Get DOS version
2018-12-25T12:32:00.36594381Z 42 PC: 12a71 | Get date 0x12a71: cmp dh, 7
0x12a74: jne 0x12a7e
0x12a76: cmp dl, 4
0x12a79: jne 0x12a7e
0x12a7b: jmp 0x12df5
0x12a7e: cmp al, 2
0x12a80: jne 0x12a96
0x12a82: cmp dl, 5
0x12a85: jne 0x12a96
0x12a87: jmp 0x12df5
0x12a8a: sub ax, 0x233e
0x12a8d: dec cx
0x12a8e: outsb dx, byte ptr [si]
0x12a8f: push sp
0x12a90: push dx
0x12a92: inc cx
0x12a94: outsb dx, byte ptr [si]
0x12a95: inc di
0x12a96: mov ax, 0x3621
0x12a99: dec ah

{"DateBased":true,"Day":5,"Month":7,"Year":1983,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12103,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:00.652167472Z 48 PC: 12a63 | Get DOS version
2018-12-25T12:32:00.653854319Z 42 PC: 12a71 | Get date 0x12a71: cmp dh, 7
0x12a74: jne 0x12a7e
0x12a76: cmp dl, 4
0x12a79: jne 0x12a7e
0x12a7b: jmp 0x12df5
0x12a7e: cmp al, 2
0x12a80: jne 0x12a96
0x12a82: cmp dl, 5
0x12a85: jne 0x12a96
0x12a87: jmp 0x12df5
0x12a8a: sub ax, 0x233e
0x12a8d: dec cx
0x12a8e: outsb dx, byte ptr [si]
0x12a8f: push sp
0x12a90: push dx
0x12a92: inc cx
0x12a94: outsb dx, byte ptr [si]
0x12a95: inc di
0x12a96: mov ax, 0x3621
0x12a99: dec ah

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12103,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:00.877208854Z 48 PC: 12a63 | Get DOS version
2018-12-25T12:32:00.879236658Z 42 PC: 12a71 | Get date 0x12a71: cmp dh, 7
0x12a74: jne 0x12a7e
0x12a76: cmp dl, 4
0x12a79: jne 0x12a7e
0x12a7b: jmp 0x12df5
0x12a7e: cmp al, 2
0x12a80: jne 0x12a96
0x12a82: cmp dl, 5
0x12a85: jne 0x12a96
0x12a87: jmp 0x12df5
0x12a8a: sub ax, 0x233e
0x12a8d: dec cx
0x12a8e: outsb dx, byte ptr [si]
0x12a8f: push sp
0x12a90: push dx
0x12a92: inc cx
0x12a94: outsb dx, byte ptr [si]
0x12a95: inc di
0x12a96: mov ax, 0x3621
0x12a99: dec ah
2018-12-25T12:32:00.881297627Z 53 PC: 12a9d | Get interrupt vector (Interrupt = '33' AKA 'Random read')

{"DateBased":true,"Day":2,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12103,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:00.942589348Z 48 PC: 12a63 | Get DOS version
2018-12-25T12:32:00.944267106Z 42 PC: 12a71 | Get date 0x12a71: cmp dh, 7
0x12a74: jne 0x12a7e
0x12a76: cmp dl, 4
0x12a79: jne 0x12a7e
0x12a7b: jmp 0x12df5
0x12a7e: cmp al, 2
0x12a80: jne 0x12a96
0x12a82: cmp dl, 5
0x12a85: jne 0x12a96
0x12a87: jmp 0x12df5
0x12a8a: sub ax, 0x233e
0x12a8d: dec cx
0x12a8e: outsb dx, byte ptr [si]
0x12a8f: push sp
0x12a90: push dx
0x12a92: inc cx
0x12a94: outsb dx, byte ptr [si]
0x12a95: inc di
0x12a96: mov ax, 0x3621
0x12a99: dec ah
2018-12-25T12:32:00.948311065Z 53 PC: 12a9d | Get interrupt vector (Interrupt = '33' AKA 'Random read')

{"DateBased":true,"Day":5,"Month":2,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12103,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:00.960714266Z 48 PC: 12a63 | Get DOS version
2018-12-25T12:32:00.965506755Z 42 PC: 12a71 | Get date 0x12a71: cmp dh, 7
0x12a74: jne 0x12a7e
0x12a76: cmp dl, 4
0x12a79: jne 0x12a7e
0x12a7b: jmp 0x12df5
0x12a7e: cmp al, 2
0x12a80: jne 0x12a96
0x12a82: cmp dl, 5
0x12a85: jne 0x12a96
0x12a87: jmp 0x12df5
0x12a8a: sub ax, 0x233e
0x12a8d: dec cx
0x12a8e: outsb dx, byte ptr [si]
0x12a8f: push sp
0x12a90: push dx
0x12a92: inc cx
0x12a94: outsb dx, byte ptr [si]
0x12a95: inc di
0x12a96: mov ax, 0x3621
0x12a99: dec ah

{"DateBased":true,"Day":1,"Month":7,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12103,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:01.014271657Z 48 PC: 12a63 | Get DOS version
2018-12-25T12:32:01.016778976Z 42 PC: 12a71 | Get date 0x12a71: cmp dh, 7
0x12a74: jne 0x12a7e
0x12a76: cmp dl, 4
0x12a79: jne 0x12a7e
0x12a7b: jmp 0x12df5
0x12a7e: cmp al, 2
0x12a80: jne 0x12a96
0x12a82: cmp dl, 5
0x12a85: jne 0x12a96
0x12a87: jmp 0x12df5
0x12a8a: sub ax, 0x233e
0x12a8d: dec cx
0x12a8e: outsb dx, byte ptr [si]
0x12a8f: push sp
0x12a90: push dx
0x12a92: inc cx
0x12a94: outsb dx, byte ptr [si]
0x12a95: inc di
0x12a96: mov ax, 0x3621
0x12a99: dec ah
2018-12-25T12:32:01.019243588Z 53 PC: 12a9d | Get interrupt vector (Interrupt = '33' AKA 'Random read')