Sample viewer

vx.netlux.org/Virus.DOS.XS.851

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:59:06.837324343Z 255 PC: 13e62 | UNKNOWN!
2018-12-17T22:59:06.839287423Z 42 PC: 13ee5 | Get date 0x13ee5: cmp cx, 0x7c8
0x13ee9: jb 0x13ef8
0x13eeb: cmp dh, 7
0x13eee: jb 0x13ef8
0x13ef0: cmp dl, 0x1c
0x13ef3: jb 0x13ef8
0x13ef5: jmp 0x1415f
0x13ef8: pop es
0x13ef9: push es
0x13efa: pop ds
0x13efb: pop si
0x13efc: cmp byte ptr cs:[si - 0x12], 1
0x13f01: jne 0x13f06
0x13f03: jmp 0x13e6e
0x13f06: jmp 0x13e7b
0x13f09: mov al, 3
0x13f0b: iret
0x13f0c: push bp
0x13f0d: add ax, bp
0x13f0f: add al, 0x55
2018-12-17T22:59:06.842183949Z 9 PC: 12a85 | Display string (String= ' COM goat 1400H bytes long ')
2018-12-17T22:59:06.848611999Z 0 PC: 12a89 | Program terminate

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13094,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:37:28.242888977Z 255 PC: 13e62 | UNKNOWN!
2018-12-25T12:37:28.244889855Z 42 PC: 13ee5 | Get date 0x13ee5: cmp cx, 0x7c8
0x13ee9: jb 0x13ef8
0x13eeb: cmp dh, 7
0x13eee: jb 0x13ef8
0x13ef0: cmp dl, 0x1c
0x13ef3: jb 0x13ef8
0x13ef5: jmp 0x1415f
0x13ef8: pop es
0x13ef9: push es
0x13efa: pop ds
0x13efb: pop si
0x13efc: cmp byte ptr cs:[si - 0x12], 1
0x13f01: jne 0x13f06
0x13f03: jmp 0x13e6e
0x13f06: jmp 0x13e7b
0x13f09: mov al, 3
0x13f0b: iret
0x13f0c: push bp
0x13f0d: add ax, bp
0x13f0f: add al, 0x55
2018-12-25T12:37:28.246725135Z 9 PC: 12a85 | Display string (String= ' COM goat 1400H bytes long ')
2018-12-25T12:37:28.250513785Z 0 PC: 12a89 | Program terminate

{"DateBased":true,"Day":1,"Month":1,"Year":1992,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13094,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:37:28.316997744Z 255 PC: 13e62 | UNKNOWN!
2018-12-25T12:37:28.31865219Z 42 PC: 13ee5 | Get date 0x13ee5: cmp cx, 0x7c8
0x13ee9: jb 0x13ef8
0x13eeb: cmp dh, 7
0x13eee: jb 0x13ef8
0x13ef0: cmp dl, 0x1c
0x13ef3: jb 0x13ef8
0x13ef5: jmp 0x1415f
0x13ef8: pop es
0x13ef9: push es
0x13efa: pop ds
0x13efb: pop si
0x13efc: cmp byte ptr cs:[si - 0x12], 1
0x13f01: jne 0x13f06
0x13f03: jmp 0x13e6e
0x13f06: jmp 0x13e7b
0x13f09: mov al, 3
0x13f0b: iret
0x13f0c: push bp
0x13f0d: add ax, bp
0x13f0f: add al, 0x55
2018-12-25T12:37:28.320853545Z 9 PC: 12a85 | Display string (String= ' COM goat 1400H bytes long ')
2018-12-25T12:37:28.326583377Z 0 PC: 12a89 | Program terminate

{"DateBased":true,"Day":1,"Month":7,"Year":1992,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13094,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:37:28.408543289Z 255 PC: 13e62 | UNKNOWN!
2018-12-25T12:37:28.410180072Z 42 PC: 13ee5 | Get date 0x13ee5: cmp cx, 0x7c8
0x13ee9: jb 0x13ef8
0x13eeb: cmp dh, 7
0x13eee: jb 0x13ef8
0x13ef0: cmp dl, 0x1c
0x13ef3: jb 0x13ef8
0x13ef5: jmp 0x1415f
0x13ef8: pop es
0x13ef9: push es
0x13efa: pop ds
0x13efb: pop si
0x13efc: cmp byte ptr cs:[si - 0x12], 1
0x13f01: jne 0x13f06
0x13f03: jmp 0x13e6e
0x13f06: jmp 0x13e7b
0x13f09: mov al, 3
0x13f0b: iret
0x13f0c: push bp
0x13f0d: add ax, bp
0x13f0f: add al, 0x55
2018-12-25T12:37:28.411959021Z 9 PC: 12a85 | Display string (String= ' COM goat 1400H bytes long ')
2018-12-25T12:37:28.416025895Z 0 PC: 12a89 | Program terminate

{"DateBased":true,"Day":28,"Month":7,"Year":1992,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13094,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:37:29.213416939Z 255 PC: 13e62 | UNKNOWN!
2018-12-25T12:37:29.214848133Z 42 PC: 13ee5 | Get date 0x13ee5: cmp cx, 0x7c8
0x13ee9: jb 0x13ef8
0x13eeb: cmp dh, 7
0x13eee: jb 0x13ef8
0x13ef0: cmp dl, 0x1c
0x13ef3: jb 0x13ef8
0x13ef5: jmp 0x1415f
0x13ef8: pop es
0x13ef9: push es
0x13efa: pop ds
0x13efb: pop si
0x13efc: cmp byte ptr cs:[si - 0x12], 1
0x13f01: jne 0x13f06
0x13f03: jmp 0x13e6e
0x13f06: jmp 0x13e7b
0x13f09: mov al, 3
0x13f0b: iret
0x13f0c: push bp
0x13f0d: add ax, bp
0x13f0f: add al, 0x55
2018-12-25T12:37:29.566653657Z 9 PC: 12a85 | Display string (String= ' COM goat 1400H bytes long ')
2018-12-25T12:37:29.574391278Z 0 PC: 12a89 | Program terminate