Sample viewer

vx.netlux.org/Virus.DOS.ARCV.916.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:37.442291115Z 42 PC: 12a7d | Get date 0x12a7d: cmp dh, 0xc
0x12a80: jne 0x12a8f
0x12a82: cmp dl, 0xa
0x12a85: jne 0x12a8f
0x12a87: mov ah, 9
0x12a89: lea dx, word ptr [si + 0x3cd]
0x12a8d: int 0x21
0x12a8f: mov di, 0x100
0x12a92: push si
0x12a93: mov ax, 0x486
0x12a96: add si, ax
0x12a98: mov cx, 5
0x12a9b: cld
0x12a9c: rep movsb byte ptr es:[di], byte ptr [si]
0x12a9e: mov ax, 0xff04
0x12aa1: int 0x21
0x12aa3: pop si
0x12aa4: cmp ax, 0x4221
0x12aa7: je 0x12b02
0x12aa9: xor ax, ax
2018-12-17T22:56:37.445610446Z 255 PC: 12aa3 | UNKNOWN!

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12276,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:22.531246054Z 42 PC: 12a7d | Get date 0x12a7d: cmp dh, 0xc
0x12a80: jne 0x12a8f
0x12a82: cmp dl, 0xa
0x12a85: jne 0x12a8f
0x12a87: mov ah, 9
0x12a89: lea dx, word ptr [si + 0x3cd]
0x12a8d: int 0x21
0x12a8f: mov di, 0x100
0x12a92: push si
0x12a93: mov ax, 0x486
0x12a96: add si, ax
0x12a98: mov cx, 5
0x12a9b: cld
0x12a9c: rep movsb byte ptr es:[di], byte ptr [si]
0x12a9e: mov ax, 0xff04
0x12aa1: int 0x21
0x12aa3: pop si
0x12aa4: cmp ax, 0x4221
0x12aa7: je 0x12b02
0x12aa9: xor ax, ax
2018-12-25T12:32:22.533831545Z 255 PC: 12aa3 | UNKNOWN!

{"DateBased":true,"Day":1,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12276,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:22.683034624Z 42 PC: 12a7d | Get date 0x12a7d: cmp dh, 0xc
0x12a80: jne 0x12a8f
0x12a82: cmp dl, 0xa
0x12a85: jne 0x12a8f
0x12a87: mov ah, 9
0x12a89: lea dx, word ptr [si + 0x3cd]
0x12a8d: int 0x21
0x12a8f: mov di, 0x100
0x12a92: push si
0x12a93: mov ax, 0x486
0x12a96: add si, ax
0x12a98: mov cx, 5
0x12a9b: cld
0x12a9c: rep movsb byte ptr es:[di], byte ptr [si]
0x12a9e: mov ax, 0xff04
0x12aa1: int 0x21
0x12aa3: pop si
0x12aa4: cmp ax, 0x4221
0x12aa7: je 0x12b02
0x12aa9: xor ax, ax
2018-12-25T12:32:22.686446417Z 255 PC: 12aa3 | UNKNOWN!

{"DateBased":true,"Day":10,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12276,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:23.010387922Z 42 PC: 12a7d | Get date 0x12a7d: cmp dh, 0xc
0x12a80: jne 0x12a8f
0x12a82: cmp dl, 0xa
0x12a85: jne 0x12a8f
0x12a87: mov ah, 9
0x12a89: lea dx, word ptr [si + 0x3cd]
0x12a8d: int 0x21
0x12a8f: mov di, 0x100
0x12a92: push si
0x12a93: mov ax, 0x486
0x12a96: add si, ax
0x12a98: mov cx, 5
0x12a9b: cld
0x12a9c: rep movsb byte ptr es:[di], byte ptr [si]
0x12a9e: mov ax, 0xff04
0x12aa1: int 0x21
0x12aa3: pop si
0x12aa4: cmp ax, 0x4221
0x12aa7: je 0x12b02
0x12aa9: xor ax, ax
2018-12-25T12:32:23.012772911Z 9 PC: 12a8f | Display string (String= 'Looking Good Slimline Joanna. Made in England by Apache Warrior, ARCV Pres. Jo Ver. 1.11 (c) Apache Warrior 92. ')
2018-12-25T12:32:23.018361841Z 255 PC: 12aa3 | UNKNOWN!

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12276,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:23.319050344Z 42 PC: 12a7d | Get date 0x12a7d: cmp dh, 0xc
0x12a80: jne 0x12a8f
0x12a82: cmp dl, 0xa
0x12a85: jne 0x12a8f
0x12a87: mov ah, 9
0x12a89: lea dx, word ptr [si + 0x3cd]
0x12a8d: int 0x21
0x12a8f: mov di, 0x100
0x12a92: push si
0x12a93: mov ax, 0x486
0x12a96: add si, ax
0x12a98: mov cx, 5
0x12a9b: cld
0x12a9c: rep movsb byte ptr es:[di], byte ptr [si]
0x12a9e: mov ax, 0xff04
0x12aa1: int 0x21
0x12aa3: pop si
0x12aa4: cmp ax, 0x4221
0x12aa7: je 0x12b02
0x12aa9: xor ax, ax
2018-12-25T12:32:23.321641024Z 255 PC: 12aa3 | UNKNOWN!

{"DateBased":true,"Day":1,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12276,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:23.414370622Z 42 PC: 12a7d | Get date 0x12a7d: cmp dh, 0xc
0x12a80: jne 0x12a8f
0x12a82: cmp dl, 0xa
0x12a85: jne 0x12a8f
0x12a87: mov ah, 9
0x12a89: lea dx, word ptr [si + 0x3cd]
0x12a8d: int 0x21
0x12a8f: mov di, 0x100
0x12a92: push si
0x12a93: mov ax, 0x486
0x12a96: add si, ax
0x12a98: mov cx, 5
0x12a9b: cld
0x12a9c: rep movsb byte ptr es:[di], byte ptr [si]
0x12a9e: mov ax, 0xff04
0x12aa1: int 0x21
0x12aa3: pop si
0x12aa4: cmp ax, 0x4221
0x12aa7: je 0x12b02
0x12aa9: xor ax, ax
2018-12-25T12:32:23.417450825Z 255 PC: 12aa3 | UNKNOWN!

{"DateBased":true,"Day":10,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12276,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:23.905985532Z 42 PC: 12a7d | Get date 0x12a7d: cmp dh, 0xc
0x12a80: jne 0x12a8f
0x12a82: cmp dl, 0xa
0x12a85: jne 0x12a8f
0x12a87: mov ah, 9
0x12a89: lea dx, word ptr [si + 0x3cd]
0x12a8d: int 0x21
0x12a8f: mov di, 0x100
0x12a92: push si
0x12a93: mov ax, 0x486
0x12a96: add si, ax
0x12a98: mov cx, 5
0x12a9b: cld
0x12a9c: rep movsb byte ptr es:[di], byte ptr [si]
0x12a9e: mov ax, 0xff04
0x12aa1: int 0x21
0x12aa3: pop si
0x12aa4: cmp ax, 0x4221
0x12aa7: je 0x12b02
0x12aa9: xor ax, ax
2018-12-25T12:32:23.908577848Z 9 PC: 12a8f | Display string (String= 'Looking Good Slimline Joanna. Made in England by Apache Warrior, ARCV Pres. Jo Ver. 1.11 (c) Apache Warrior 92. ')
2018-12-25T12:32:23.919533235Z 255 PC: 12aa3 | UNKNOWN!