Sample viewer

vx.netlux.org/Virus.DOS.Hitch.1247.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:58:11.840136953Z 48 PC: 12a47 | Get DOS version
2018-12-17T22:58:11.841367987Z 75 PC: 12a50 | Execute program
2018-12-17T22:58:11.843306782Z 53 PC: 12a5d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:58:11.84439081Z 37 PC: 12a6f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:58:11.845562111Z 42 PC: 12a85 | Get date 0x12a85: cmp dh, 8
0x12a88: je 0x12a92
0x12a8a: mov dx, 0x210
0x12a8d: mov ax, 0x251c
0x12a90: int 0x21
0x12a92: mov bp, cs
0x12a94: dec bp
0x12a95: mov es, bp
0x12a97: mov ax, 0x100
0x12a9a: mov si, word ptr [0x16]
0x12a9e: mov word ptr es:[1], si
0x12aa3: mov dx, word ptr es:[3]
0x12aa8: mov word ptr es:[3], ax
0x12aac: mov byte ptr es:[0], 0x4d
0x12ab2: sub dx, ax
0x12ab4: dec dx
0x12ab5: inc bp
0x12ab6: add bp, ax
0x12ab8: mov es, bp
0x12aba: inc bp
2018-12-17T22:58:11.848215248Z 37 PC: 12a92 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:58:11.849372714Z 80 PC: 12ad3 | Set current PSP
2018-12-17T22:58:11.850480747Z 9 PC: 13cf2 | Display string (String= 'BACopy (C) 1985, Dickinson Associates Inc. ')
2018-12-17T22:58:11.854715898Z 9 PC: 13f78 | Display string (String= ' BACopy Error - ')
2018-12-17T22:58:11.859413487Z 9 PC: 13f7d | Display string (String= 'Correct Syntax is: BACopy [d:][source_path]source_filename[.ext] [d:][target_path]')
2018-12-17T22:58:11.866512882Z 9 PC: 13f88 | Display string (String= ' . . . Aborting ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12787,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:36:15.843106076Z 48 PC: 12a47 | Get DOS version
2018-12-25T12:36:15.84578789Z 75 PC: 12a50 | Execute program
2018-12-25T12:36:15.847477983Z 53 PC: 12a5d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:36:15.848584686Z 37 PC: 12a6f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:36:15.850023006Z 42 PC: 12a85 | Get date 0x12a85: cmp dh, 8
0x12a88: je 0x12a92
0x12a8a: mov dx, 0x210
0x12a8d: mov ax, 0x251c
0x12a90: int 0x21
0x12a92: mov bp, cs
0x12a94: dec bp
0x12a95: mov es, bp
0x12a97: mov ax, 0x100
0x12a9a: mov si, word ptr [0x16]
0x12a9e: mov word ptr es:[1], si
0x12aa3: mov dx, word ptr es:[3]
0x12aa8: mov word ptr es:[3], ax
0x12aac: mov byte ptr es:[0], 0x4d
0x12ab2: sub dx, ax
0x12ab4: dec dx
0x12ab5: inc bp
0x12ab6: add bp, ax
0x12ab8: mov es, bp
0x12aba: inc bp
2018-12-25T12:36:15.852739723Z 37 PC: 12a92 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:36:15.853839749Z 80 PC: 12ad3 | Set current PSP
2018-12-25T12:36:15.854792273Z 9 PC: 13cf2 | Display string (String= 'BACopy (C) 1985, Dickinson Associates Inc. ')
2018-12-25T12:36:15.860806174Z 9 PC: 13f78 | Display string (String= ' BACopy Error - ')
2018-12-25T12:36:15.864829234Z 9 PC: 13f7d | Display string (String= 'Correct Syntax is: BACopy [d:][source_path]source_filename[.ext] [d:][target_path]')
2018-12-25T12:36:15.8717109Z 9 PC: 13f88 | Display string (String= ' . . . Aborting ')

{"DateBased":true,"Day":1,"Month":8,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12787,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:36:16.450991723Z 48 PC: 12a47 | Get DOS version
2018-12-25T12:36:16.46723322Z 75 PC: 12a50 | Execute program
2018-12-25T12:36:16.468718926Z 53 PC: 12a5d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:36:16.469926215Z 37 PC: 12a6f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:36:16.471228167Z 42 PC: 12a85 | Get date 0x12a85: cmp dh, 8
0x12a88: je 0x12a92
0x12a8a: mov dx, 0x210
0x12a8d: mov ax, 0x251c
0x12a90: int 0x21
0x12a92: mov bp, cs
0x12a94: dec bp
0x12a95: mov es, bp
0x12a97: mov ax, 0x100
0x12a9a: mov si, word ptr [0x16]
0x12a9e: mov word ptr es:[1], si
0x12aa3: mov dx, word ptr es:[3]
0x12aa8: mov word ptr es:[3], ax
0x12aac: mov byte ptr es:[0], 0x4d
0x12ab2: sub dx, ax
0x12ab4: dec dx
0x12ab5: inc bp
0x12ab6: add bp, ax
0x12ab8: mov es, bp
0x12aba: inc bp
2018-12-25T12:36:16.47297075Z 80 PC: 12ad3 | Set current PSP
2018-12-25T12:36:16.473683711Z 9 PC: 13cf2 | Display string (String= 'BACopy (C) 1985, Dickinson Associates Inc. ')
2018-12-25T12:36:16.477295745Z 9 PC: 13f78 | Display string (String= ' BACopy Error - ')
2018-12-25T12:36:16.479679536Z 9 PC: 13f7d | Display string (String= 'Correct Syntax is: BACopy [d:][source_path]source_filename[.ext] [d:][target_path]')
2018-12-25T12:36:16.483328013Z 9 PC: 13f88 | Display string (String= ' . . . Aborting ')