Sample viewer

vx.netlux.org/Virus.DOS.Inquisitor.1344

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:42.716450168Z 71 PC: 12a9b | Get current directory
2018-12-17T22:56:42.719823237Z 78 PC: 12aa6 | Find first file
2018-12-17T22:56:42.72571669Z 67 PC: 12ac2 | Get or set file attributes
2018-12-17T22:56:42.73170633Z 61 PC: 12ad6 | Open file (Filename = 'W’')
2018-12-17T22:56:42.738162116Z 67 PC: 12bf0 | Get or set file attributes
2018-12-17T22:56:42.750531792Z 79 PC: 12aa6 | Find next file
2018-12-17T22:56:42.75314675Z 67 PC: 12ac2 | Get or set file attributes
2018-12-17T22:56:42.764034849Z 61 PC: 12ad6 | Open file (Filename = 'W’')
2018-12-17T22:56:42.771212216Z 67 PC: 12bf0 | Get or set file attributes
2018-12-17T22:56:42.776577506Z 79 PC: 12aa6 | Find next file
2018-12-17T22:56:42.779133618Z 67 PC: 12ac2 | Get or set file attributes
2018-12-17T22:56:42.78633176Z 61 PC: 12ad6 | Open file (Filename = 'W’')
2018-12-17T22:56:42.792352831Z 67 PC: 12bf0 | Get or set file attributes
2018-12-17T22:56:42.798189632Z 79 PC: 12aa6 | Find next file
2018-12-17T22:56:42.801342601Z 67 PC: 12ac2 | Get or set file attributes
2018-12-17T22:56:42.806723882Z 61 PC: 12ad6 | Open file (Filename = 'W’')
2018-12-17T22:56:42.812574074Z 67 PC: 12bf0 | Get or set file attributes
2018-12-17T22:56:42.818556755Z 79 PC: 12aa6 | Find next file
2018-12-17T22:56:42.821329317Z 67 PC: 12ac2 | Get or set file attributes
2018-12-17T22:56:42.827053033Z 61 PC: 12ad6 | Open file (Filename = 'W’')
2018-12-17T22:56:42.834211436Z 67 PC: 12bf0 | Get or set file attributes
2018-12-17T22:56:42.839542384Z 79 PC: 12aa6 | Find next file
2018-12-17T22:56:42.841819026Z 67 PC: 12ac2 | Get or set file attributes
2018-12-17T22:56:42.847691726Z 61 PC: 12ad6 | Open file (Filename = 'W’')
2018-12-17T22:56:42.853549867Z 67 PC: 12bf0 | Get or set file attributes
2018-12-17T22:56:42.858867827Z 79 PC: 12aa6 | Find next file
2018-12-17T22:56:42.861767334Z 67 PC: 12ac2 | Get or set file attributes
2018-12-17T22:56:42.867163034Z 61 PC: 12ad6 | Open file (Filename = 'W’')
2018-12-17T22:56:42.873094081Z 67 PC: 12bf0 | Get or set file attributes
2018-12-17T22:56:42.87907936Z 79 PC: 12aa6 | Find next file
2018-12-17T22:56:42.881522297Z 67 PC: 12ac2 | Get or set file attributes
2018-12-17T22:56:42.886861548Z 61 PC: 12ad6 | Open file (Filename = 'W’')
2018-12-17T22:56:42.894381687Z 67 PC: 12bf0 | Get or set file attributes
2018-12-17T22:56:42.89983569Z 79 PC: 12aa6 | Find next file
2018-12-17T22:56:42.902055357Z 78 PC: 12c1b | Find first file
2018-12-17T22:56:42.908165805Z 78 PC: 12c1b | Find first file
2018-12-17T22:56:42.913846751Z 78 PC: 12c1b | Find first file
2018-12-17T22:56:42.919497285Z 78 PC: 12c1b | Find first file
2018-12-17T22:56:42.925518807Z 78 PC: 12c1b | Find first file
2018-12-17T22:56:42.931075701Z 78 PC: 12c1b | Find first file
2018-12-17T22:56:42.936589847Z 78 PC: 12c1b | Find first file
2018-12-17T22:56:42.942676007Z 78 PC: 12c1b | Find first file
2018-12-17T22:56:42.948221197Z 78 PC: 12c1b | Find first file
2018-12-17T22:56:42.953778386Z 59 PC: 12c56 | Change current directory
2018-12-17T22:56:42.958684017Z 42 PC: 12cb1 | Get date 0x12cb1: cmp dh, 4
0x12cb4: jne 0x12cf0
0x12cb6: cmp dl, 0x19
0x12cb9: jne 0x12cf0
0x12cbb: mov al, 2
0x12cbd: out 0x21, al
0x12cbf: mov ah, 9
0x12cc1: mov dx, 0x52c
0x12cc4: int 0x21
0x12cc6: mov dx, 0x3b1
0x12cc9: mov cx, 7
0x12ccc: mov ah, 0x4e
0x12cce: nop
0x12ccf: nop
0x12cd0: int 0x21
0x12cd2: jb 0x12cee
0x12cd4: call 0x12cf5
0x12cd7: jb 0x12ce8
0x12cd9: xchg ax, bx
0x12cda: xor cx, cx
2018-12-17T22:56:42.960910629Z 26 PC: 12c76 | Set disk transfer address
2018-12-17T22:56:42.962015517Z 59 PC: 12c81 | Change current directory

{"DateBased":true,"Day":25,"Month":4,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12312,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:27.018902387Z 71 PC: 12a9b | Get current directory
2018-12-25T12:32:27.021957959Z 78 PC: 12aa6 | Find first file
2018-12-25T12:32:27.027700515Z 67 PC: 12ac2 | Get or set file attributes
2018-12-25T12:32:27.037852235Z 61 PC: 12ad6 | Open file (Filename = 'W’')
2018-12-25T12:32:27.048900561Z 67 PC: 12bf0 | Get or set file attributes
2018-12-25T12:32:27.059705381Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.062373295Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.068213786Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.074738842Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.080319731Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.082959995Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.08995484Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.100604058Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.110870847Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.114560488Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.12522479Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.131366307Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.137881313Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.140521304Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.14804029Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.160428723Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.171091837Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.173522429Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.184510861Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.190370292Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.196167625Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.199340561Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.204830598Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.214949175Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.225499649Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.228798612Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.239366196Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.250478406Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.256643938Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.259327797Z 78 PC: 12c1b | Find first file
2018-12-25T12:32:27.265163017Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.271134071Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.276541987Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.286595376Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.29695899Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.307799403Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.313558023Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.319767726Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.325544512Z 59 PC: 12c56 | Change current directory
2018-12-25T12:32:27.329649681Z 42 PC: 12cb1 | Get date 0x12cb1: cmp dh, 4
0x12cb4: jne 0x12cf0
0x12cb6: cmp dl, 0x19
0x12cb9: jne 0x12cf0
0x12cbb: mov al, 2
0x12cbd: out 0x21, al
0x12cbf: mov ah, 9
0x12cc1: mov dx, 0x52c
0x12cc4: int 0x21
0x12cc6: mov dx, 0x3b1
0x12cc9: mov cx, 7
0x12ccc: mov ah, 0x4e
0x12cce: nop
0x12ccf: nop
0x12cd0: int 0x21
0x12cd2: jb 0x12cee
0x12cd4: call 0x12cf5
0x12cd7: jb 0x12ce8
0x12cd9: xchg ax, bx
0x12cda: xor cx, cx
2018-12-25T12:32:27.332483851Z 9 PC: 12cc6 | Display string (Could not find end pointer)
2018-12-25T12:32:27.353249379Z 78 PC: 12cd2 | Find first file
2018-12-25T12:32:27.363772462Z 67 PC: 12d03 | Get or set file attributes
2018-12-25T12:32:27.370365066Z 61 PC: 12d0b | Open file (Filename = 'W’')
2018-12-25T12:32:27.37638474Z 79 PC: 12cd2 | Find next file (See above)
2018-12-25T12:32:27.378986508Z 67 PC: 12d03 | Get or set file attributes (See above)
2018-12-25T12:32:27.384977145Z 61 PC: 12d0b | Open file (See above)
2018-12-25T12:32:27.390959607Z 79 PC: 12cd2 | Find next file (See above)
2018-12-25T12:32:27.393567227Z 67 PC: 12d03 | Get or set file attributes (See above)
2018-12-25T12:32:27.399539579Z 61 PC: 12d0b | Open file (See above)
2018-12-25T12:32:27.405418981Z 79 PC: 12cd2 | Find next file (See above)
2018-12-25T12:32:27.407936632Z 67 PC: 12d03 | Get or set file attributes (See above)
2018-12-25T12:32:27.415837983Z 61 PC: 12d0b | Open file (See above)
2018-12-25T12:32:27.421594422Z 79 PC: 12cd2 | Find next file (See above)
2018-12-25T12:32:27.423957493Z 67 PC: 12d03 | Get or set file attributes (See above)
2018-12-25T12:32:27.430216624Z 61 PC: 12d0b | Open file (See above)
2018-12-25T12:32:27.436522319Z 79 PC: 12cd2 | Find next file (See above)
2018-12-25T12:32:27.439143033Z 67 PC: 12d03 | Get or set file attributes (See above)
2018-12-25T12:32:27.445118009Z 61 PC: 12d0b | Open file (See above)
2018-12-25T12:32:27.450830778Z 79 PC: 12cd2 | Find next file (See above)
2018-12-25T12:32:27.453090426Z 67 PC: 12d03 | Get or set file attributes (See above)
2018-12-25T12:32:27.465277596Z 61 PC: 12d0b | Open file (See above)
2018-12-25T12:32:27.471704251Z 79 PC: 12cd2 | Find next file (See above)
2018-12-25T12:32:27.474345489Z 67 PC: 12d03 | Get or set file attributes (See above)
2018-12-25T12:32:27.480681279Z 61 PC: 12d0b | Open file (See above)
2018-12-25T12:32:27.486623195Z 79 PC: 12cd2 | Find next file (See above)
2018-12-25T12:32:27.489001999Z 67 PC: 12d03 | Get or set file attributes (See above)
2018-12-25T12:32:27.495535854Z 61 PC: 12d0b | Open file (See above)
2018-12-25T12:32:27.501959805Z 79 PC: 12cd2 | Find next file (See above)

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12312,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:27.194469739Z 71 PC: 12a9b | Get current directory
2018-12-25T12:32:27.211758922Z 78 PC: 12aa6 | Find first file
2018-12-25T12:32:27.217625725Z 67 PC: 12ac2 | Get or set file attributes
2018-12-25T12:32:27.228236642Z 61 PC: 12ad6 | Open file (Filename = 'W’')
2018-12-25T12:32:27.235141947Z 67 PC: 12bf0 | Get or set file attributes
2018-12-25T12:32:27.24118427Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.244000761Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.253000853Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.260306776Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.271224564Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.274072544Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.285766681Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.292506295Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.298253625Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.301535045Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.307438041Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.313721171Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.320894753Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.323649991Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.329220681Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.336200658Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.342096226Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.344864917Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.351479662Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.358296761Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.364046862Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.367869333Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.37379249Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.380194442Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.386774437Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.389363831Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.395048086Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.404315999Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.40983046Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.412116272Z 78 PC: 12c1b | Find first file
2018-12-25T12:32:27.418659017Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.424689904Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.430482039Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.436403826Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.442251424Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.447787693Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.453895349Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.460160434Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.465721323Z 59 PC: 12c56 | Change current directory
2018-12-25T12:32:27.469563501Z 42 PC: 12cb1 | Get date 0x12cb1: cmp dh, 4
0x12cb4: jne 0x12cf0
0x12cb6: cmp dl, 0x19
0x12cb9: jne 0x12cf0
0x12cbb: mov al, 2
0x12cbd: out 0x21, al
0x12cbf: mov ah, 9
0x12cc1: mov dx, 0x52c
0x12cc4: int 0x21
0x12cc6: mov dx, 0x3b1
0x12cc9: mov cx, 7
0x12ccc: mov ah, 0x4e
0x12cce: nop
0x12ccf: nop
0x12cd0: int 0x21
0x12cd2: jb 0x12cee
0x12cd4: call 0x12cf5
0x12cd7: jb 0x12ce8
0x12cd9: xchg ax, bx
0x12cda: xor cx, cx
2018-12-25T12:32:27.472274184Z 26 PC: 12c76 | Set disk transfer address
2018-12-25T12:32:27.473283906Z 59 PC: 12c81 | Change current directory

{"DateBased":true,"Day":1,"Month":4,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12312,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:27.205167359Z 71 PC: 12a9b | Get current directory
2018-12-25T12:32:27.209265633Z 78 PC: 12aa6 | Find first file
2018-12-25T12:32:27.216245721Z 67 PC: 12ac2 | Get or set file attributes
2018-12-25T12:32:27.228740019Z 61 PC: 12ad6 | Open file (Filename = 'W’')
2018-12-25T12:32:27.236646667Z 67 PC: 12bf0 | Get or set file attributes
2018-12-25T12:32:27.243747206Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.246618294Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.252911109Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.260319653Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.26681802Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.269886948Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.277443275Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.28412178Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.290201787Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.293422688Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.300432951Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.306834558Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.314213366Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.317051553Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.323170475Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.329953103Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.336354099Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.339063115Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.345131124Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.35197239Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.358852628Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.361525863Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.368208211Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.375300252Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.38197778Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.385542705Z 67 PC: 12ac2 | Get or set file attributes (See above)
2018-12-25T12:32:27.389255894Z 61 PC: 12ad6 | Open file (See above)
2018-12-25T12:32:27.39320287Z 67 PC: 12bf0 | Get or set file attributes (See above)
2018-12-25T12:32:27.39750305Z 79 PC: 12aa6 | Find next file (See above)
2018-12-25T12:32:27.400043352Z 78 PC: 12c1b | Find first file
2018-12-25T12:32:27.406382925Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.413307277Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.419882404Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.427228104Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.434218131Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.440503804Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.446796248Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.453112144Z 78 PC: 12c1b | Find first file (See above)
2018-12-25T12:32:27.459579756Z 59 PC: 12c56 | Change current directory
2018-12-25T12:32:27.46418593Z 42 PC: 12cb1 | Get date 0x12cb1: cmp dh, 4
0x12cb4: jne 0x12cf0
0x12cb6: cmp dl, 0x19
0x12cb9: jne 0x12cf0
0x12cbb: mov al, 2
0x12cbd: out 0x21, al
0x12cbf: mov ah, 9
0x12cc1: mov dx, 0x52c
0x12cc4: int 0x21
0x12cc6: mov dx, 0x3b1
0x12cc9: mov cx, 7
0x12ccc: mov ah, 0x4e
0x12cce: nop
0x12ccf: nop
0x12cd0: int 0x21
0x12cd2: jb 0x12cee
0x12cd4: call 0x12cf5
0x12cd7: jb 0x12ce8
0x12cd9: xchg ax, bx
0x12cda: xor cx, cx
2018-12-25T12:32:27.466492126Z 26 PC: 12c76 | Set disk transfer address
2018-12-25T12:32:27.468327968Z 59 PC: 12c81 | Change current directory