Sample viewer

vx.netlux.org/Virus.DOS.Gobot.2104

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:29.841599047Z 53 PC: 12a56 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:29.843607257Z 37 PC: 12a66 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:29.845667655Z 78 PC: 12a75 | Find first file
2018-12-17T22:57:29.852041341Z 61 PC: 12a7f | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:57:29.858228309Z 63 PC: 12a8a | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:57:29.865199239Z 44 PC: 12ade | Get time 0x12ade: xor dh, dh
0x12ae0: and dl, 7
0x12ae3: cmp dx, 6
0x12ae6: nop
0x12ae7: jg 0x12ada
0x12ae9: push dx
0x12aea: add dx, 0x733
0x12aee: mov si, dx
0x12af0: mov dl, byte ptr cs:[si]
0x12af3: mov byte ptr [0x103], dl
0x12af7: pop dx
0x12af8: push dx
0x12af9: add dx, 0x748
0x12afd: mov si, dx
0x12aff: mov dl, byte ptr cs:[si]
0x12b02: mov byte ptr [0x100], dl
0x12b06: mov ah, 0x2c
0x12b08: int 0x21
0x12b0a: xor dh, dh
0x12b0c: and dl, 7
2018-12-17T22:57:29.867847945Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.870222709Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.873206392Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.875744027Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.878207667Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.881022148Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.88340229Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.885636375Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.888198247Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.891075058Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.893416796Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.895795483Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.898618033Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.900926819Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.903120588Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.905767995Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.9081309Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.91057186Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.913841812Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.916213684Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.918429505Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.921288031Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.924401132Z 44 PC: 12b0a | Get time 0x12b0a: xor dh, dh
0x12b0c: and dl, 7
0x12b0f: cmp dx, 6
0x12b12: nop
0x12b13: jg 0x12b06
0x12b15: pop ax
0x12b16: push ax
0x12b17: cmp ax, dx
0x12b19: je 0x12b06
0x12b1b: pop ax
0x12b1c: push dx
0x12b1d: add dx, 0x73a
0x12b21: mov si, dx
0x12b23: mov dl, byte ptr cs:[si]
0x12b26: mov byte ptr [0x104], dl
0x12b2a: pop dx
0x12b2b: add dx, 0x741
0x12b2f: mov si, dx
0x12b31: mov dl, byte ptr cs:[si]
0x12b34: mov byte ptr [0x106], dl
2018-12-17T22:57:29.92685289Z 66 PC: 12b41 | Move file pointer
2018-12-17T22:57:29.928779106Z 44 PC: 12b46 | Get time 0x12b46: mov word ptr [0x934], dx
0x12b4a: mov si, 0x2dc
0x12b4d: mov di, 0x93c
0x12b50: mov cx, 0x1a
0x12b53: nop
0x12b54: rep movsb byte ptr es:[di], byte ptr [si]
0x12b56: call 0x1327c
0x12b59: mov ah, 0x3e
0x12b5b: int 0x21
0x12b5d: mov ah, 9
0x12b5f: mov dx, 0x74f
0x12b62: int 0x21
0x12b64: int 0x20
0x12b66: mov ah, 0xf
0x12b68: int 0x10
0x12b6a: xor ah, ah
0x12b6c: int 0x10
0x12b6e: mov ah, 1
0x12b70: mov cx, 0x2607
0x12b73: int 0x10
2018-12-17T22:57:29.931795158Z 64 PC: 1328e | Write file or device (Write 2104 bytes on handle 5)
2018-12-17T22:57:29.946941605Z 62 PC: 12b5d | Close file
2018-12-17T22:57:29.969571271Z 9 PC: 12b64 | Display string (String= 'Parameter value not in allowed range ')