Sample viewer

vx.netlux.org/Virus.DOS.Quark.1600

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:59.453288848Z 48 PC: 20559 | Get DOS version
2018-12-17T22:56:59.455888671Z 42 PC: 12e87 | Get date 0x12e87: mov al, 0xf
0x12e89: add al, dl
0x12e8b: mov cx, 0xe
0x12e8e: mov di, 0x39
0x12e91: repne stosb byte ptr es:[di], al
0x12e93: mov word ptr [0xa], 0x49a
0x12e99: mov word ptr [0xc], es
0x12e9d: mov ds, bx
0x12e9f: mov ax, 0x3515
0x12ea2: int 0x21
0x12ea4: mov word ptr [0x3bc], es
0x12ea8: mov word ptr [0x3ba], bx
0x12eac: sub ah, 0x10
0x12eaf: mov dx, 0x328
0x12eb2: int 0x21
0x12eb4: mov ax, 0x3521
0x12eb7: int 0x21
0x12eb9: mov word ptr [0x5f], es
0x12ebd: mov word ptr [0x5d], bx
0x12ec1: sub ah, 0x10
2018-12-17T22:56:59.458373387Z 53 PC: 12ea4 | Get interrupt vector (Interrupt = '21' AKA 'Sequential write')
2018-12-17T22:56:59.459737117Z 37 PC: 12eb4 | Set interrupt vector (Interrupt = '21' AKA 'Sequential write')
2018-12-17T22:56:59.461997565Z 53 PC: 12eb9 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:56:59.463663413Z 37 PC: 12ec9 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:56:59.465340034Z 73 PC: 12d3c | Release memory
2018-12-17T22:56:59.468706236Z 49 PC: 12d3c | Terminate and stay resident (Return code = '147' | Memory size = '123')
2018-12-17T22:56:59.472125071Z 75 PC: 12d3c | Execute program
2018-12-17T22:56:59.491659335Z 80 PC: 147c9 | Set current PSP
2018-12-17T22:56:59.493485774Z 48 PC: 147ce | Get DOS version
2018-12-17T22:56:59.49553334Z 2 PC: 1467c | Character output (Char = '49')
2018-12-17T22:56:59.498263035Z 2 PC: 1467c | Character output (Char = '6e')
2018-12-17T22:56:59.500927996Z 2 PC: 1467c | Character output (Char = '63')
2018-12-17T22:56:59.504964079Z 2 PC: 1467c | Character output (Char = '6f')
2018-12-17T22:56:59.507561Z 2 PC: 1467c | Character output (Char = '72')
2018-12-17T22:56:59.510716857Z 2 PC: 1467c | Character output (Char = '72')
2018-12-17T22:56:59.519600743Z 2 PC: 1467c | Character output (Char = '65')
2018-12-17T22:56:59.533718223Z 2 PC: 1467c | Character output (Char = '63')
2018-12-17T22:56:59.536461879Z 2 PC: 1467c | Character output (Char = '74')
2018-12-17T22:56:59.541415896Z 2 PC: 1467c | Character output (Char = '20')
2018-12-17T22:56:59.543998218Z 2 PC: 1467c | Character output (Char = '44')
2018-12-17T22:56:59.546789109Z 2 PC: 1467c | Character output (Char = '4f')
2018-12-17T22:56:59.550201767Z 2 PC: 1467c | Character output (Char = '53')
2018-12-17T22:56:59.563994691Z 2 PC: 1467c | Character output (Char = '20')
2018-12-17T22:56:59.56692922Z 2 PC: 1467c | Character output (Char = '76')
2018-12-17T22:56:59.571451565Z 2 PC: 1467c | Character output (Char = '65')
2018-12-17T22:56:59.574086975Z 2 PC: 1467c | Character output (Char = '72')
2018-12-17T22:56:59.589377692Z 2 PC: 1467c | Character output (Char = '73')
2018-12-17T22:56:59.592592416Z 2 PC: 1467c | Character output (Char = '69')
2018-12-17T22:56:59.594975062Z 2 PC: 1467c | Character output (Char = '6f')
2018-12-17T22:56:59.597257408Z 2 PC: 1467c | Character output (Char = '6e')
2018-12-17T22:56:59.600371911Z 2 PC: 1467c | Character output (Char = '0d')
2018-12-17T22:56:59.602999078Z 2 PC: 1467c | Character output (Char = '0a')
2018-12-17T22:56:59.613539373Z 77 PC: 12d3c | Get program return code