Sample viewer

vx.netlux.org/Virus.DOS.ARCV.1208

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:01:36.357297397Z 42 PC: 12a73 | Get date 0x12a73: cmp dh, 0xc
0x12a76: jne 0x12a86
0x12a78: cmp dl, 0xc
0x12a7b: jne 0x12a86
0x12a7d: mov ah, 9
0x12a7f: mov dx, 0x4c3
0x12a82: add dx, si
0x12a84: int 0x21
0x12a86: mov di, 0x100
0x12a89: push si
0x12a8a: mov ax, 0x5aa
0x12a8d: add si, ax
0x12a8f: mov cx, 5
0x12a92: cld
0x12a93: rep movsb byte ptr es:[di], byte ptr [si]
0x12a95: mov ax, 0xff05
0x12a98: int 0x21
0x12a9a: pop si
0x12a9b: cmp ax, 0x4521
0x12a9e: je 0x12aaf
2018-12-17T22:01:36.359823232Z 255 PC: 12a9a | UNKNOWN!

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":1295,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:43:19.888213872Z 42 PC: 12a73 | Get date 0x12a73: cmp dh, 0xc
0x12a76: jne 0x12a86
0x12a78: cmp dl, 0xc
0x12a7b: jne 0x12a86
0x12a7d: mov ah, 9
0x12a7f: mov dx, 0x4c3
0x12a82: add dx, si
0x12a84: int 0x21
0x12a86: mov di, 0x100
0x12a89: push si
0x12a8a: mov ax, 0x5aa
0x12a8d: add si, ax
0x12a8f: mov cx, 5
0x12a92: cld
0x12a93: rep movsb byte ptr es:[di], byte ptr [si]
0x12a95: mov ax, 0xff05
0x12a98: int 0x21
0x12a9a: pop si
0x12a9b: cmp ax, 0x4521
0x12a9e: je 0x12aaf
2018-12-25T11:43:19.890987889Z 255 PC: 12a9a | UNKNOWN!

{"DateBased":true,"Day":1,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":1295,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:43:20.074758169Z 42 PC: 12a73 | Get date 0x12a73: cmp dh, 0xc
0x12a76: jne 0x12a86
0x12a78: cmp dl, 0xc
0x12a7b: jne 0x12a86
0x12a7d: mov ah, 9
0x12a7f: mov dx, 0x4c3
0x12a82: add dx, si
0x12a84: int 0x21
0x12a86: mov di, 0x100
0x12a89: push si
0x12a8a: mov ax, 0x5aa
0x12a8d: add si, ax
0x12a8f: mov cx, 5
0x12a92: cld
0x12a93: rep movsb byte ptr es:[di], byte ptr [si]
0x12a95: mov ax, 0xff05
0x12a98: int 0x21
0x12a9a: pop si
0x12a9b: cmp ax, 0x4521
0x12a9e: je 0x12aaf
2018-12-25T11:43:20.077377282Z 255 PC: 12a9a | UNKNOWN!

{"DateBased":true,"Day":12,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":1295,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:43:20.744433526Z 42 PC: 12a73 | Get date 0x12a73: cmp dh, 0xc
0x12a76: jne 0x12a86
0x12a78: cmp dl, 0xc
0x12a7b: jne 0x12a86
0x12a7d: mov ah, 9
0x12a7f: mov dx, 0x4c3
0x12a82: add dx, si
0x12a84: int 0x21
0x12a86: mov di, 0x100
0x12a89: push si
0x12a8a: mov ax, 0x5aa
0x12a8d: add si, ax
0x12a8f: mov cx, 5
0x12a92: cld
0x12a93: rep movsb byte ptr es:[di], byte ptr [si]
0x12a95: mov ax, 0xff05
0x12a98: int 0x21
0x12a9a: pop si
0x12a9b: cmp ax, 0x4521
0x12a9e: je 0x12aaf
2018-12-25T11:43:20.755141252Z 9 PC: 12a86 | Display string (String= 'This is the Scythe for Reaper Man. Beware I`m Sharp! Made in England by Apache Warrior, ARCV Pres. Scythe Ver. 1.01 (c) Apache Warrior 92. ')
2018-12-25T11:43:20.762022885Z 255 PC: 12a9a | UNKNOWN!

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":1295,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:43:21.180070691Z 42 PC: 12a73 | Get date 0x12a73: cmp dh, 0xc
0x12a76: jne 0x12a86
0x12a78: cmp dl, 0xc
0x12a7b: jne 0x12a86
0x12a7d: mov ah, 9
0x12a7f: mov dx, 0x4c3
0x12a82: add dx, si
0x12a84: int 0x21
0x12a86: mov di, 0x100
0x12a89: push si
0x12a8a: mov ax, 0x5aa
0x12a8d: add si, ax
0x12a8f: mov cx, 5
0x12a92: cld
0x12a93: rep movsb byte ptr es:[di], byte ptr [si]
0x12a95: mov ax, 0xff05
0x12a98: int 0x21
0x12a9a: pop si
0x12a9b: cmp ax, 0x4521
0x12a9e: je 0x12aaf
2018-12-25T11:43:21.183687309Z 255 PC: 12a9a | UNKNOWN!

{"DateBased":true,"Day":1,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":1295,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:43:21.708860176Z 42 PC: 12a73 | Get date 0x12a73: cmp dh, 0xc
0x12a76: jne 0x12a86
0x12a78: cmp dl, 0xc
0x12a7b: jne 0x12a86
0x12a7d: mov ah, 9
0x12a7f: mov dx, 0x4c3
0x12a82: add dx, si
0x12a84: int 0x21
0x12a86: mov di, 0x100
0x12a89: push si
0x12a8a: mov ax, 0x5aa
0x12a8d: add si, ax
0x12a8f: mov cx, 5
0x12a92: cld
0x12a93: rep movsb byte ptr es:[di], byte ptr [si]
0x12a95: mov ax, 0xff05
0x12a98: int 0x21
0x12a9a: pop si
0x12a9b: cmp ax, 0x4521
0x12a9e: je 0x12aaf
2018-12-25T11:43:21.711109094Z 255 PC: 12a9a | UNKNOWN!

{"DateBased":true,"Day":12,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":1295,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:43:21.979300688Z 42 PC: 12a73 | Get date 0x12a73: cmp dh, 0xc
0x12a76: jne 0x12a86
0x12a78: cmp dl, 0xc
0x12a7b: jne 0x12a86
0x12a7d: mov ah, 9
0x12a7f: mov dx, 0x4c3
0x12a82: add dx, si
0x12a84: int 0x21
0x12a86: mov di, 0x100
0x12a89: push si
0x12a8a: mov ax, 0x5aa
0x12a8d: add si, ax
0x12a8f: mov cx, 5
0x12a92: cld
0x12a93: rep movsb byte ptr es:[di], byte ptr [si]
0x12a95: mov ax, 0xff05
0x12a98: int 0x21
0x12a9a: pop si
0x12a9b: cmp ax, 0x4521
0x12a9e: je 0x12aaf
2018-12-25T11:43:21.982743182Z 9 PC: 12a86 | Display string (String= 'This is the Scythe for Reaper Man. Beware I`m Sharp! Made in England by Apache Warrior, ARCV Pres. Scythe Ver. 1.01 (c) Apache Warrior 92. ')
2018-12-25T11:43:21.993691604Z 255 PC: 12a9a | UNKNOWN!