Sample viewer

vx.netlux.org/Virus.DOS.ARCV.Ice.642

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:00:31.394189386Z 42 PC: 15161 | Get date 0x15161: cmp dh, 1
0x15164: jne 0x1518d
0x15166: cmp dl, 7
0x15169: jae 0x1518d
0x1516b: mov di, 0x313
0x1516e: add di, si
0x15170: mov al, 0x99
0x15172: mov cx, 0x71
0x15175: mov ah, byte ptr [di]
0x15177: mov dl, ah
0x15179: xor ah, al
0x1517b: mov byte ptr [di], ah
0x1517d: mov al, dl
0x1517f: inc di
0x15180: loop 0x15175
0x15182: mov ah, 9
0x15184: mov dx, 0x313
0x15187: add dx, si
0x15189: int 0x21
0x1518b: jmp 0x1518b
2018-12-17T23:00:31.39847022Z 255 PC: 151a1 | UNKNOWN!
2018-12-17T23:00:31.400229406Z 49 PC: 151e7 | Terminate and stay resident (Return code = '0' | Memory size = '69')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13568,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:38:27.773466105Z 42 PC: 15161 | Get date 0x15161: cmp dh, 1
0x15164: jne 0x1518d
0x15166: cmp dl, 7
0x15169: jae 0x1518d
0x1516b: mov di, 0x313
0x1516e: add di, si
0x15170: mov al, 0x99
0x15172: mov cx, 0x71
0x15175: mov ah, byte ptr [di]
0x15177: mov dl, ah
0x15179: xor ah, al
0x1517b: mov byte ptr [di], ah
0x1517d: mov al, dl
0x1517f: inc di
0x15180: loop 0x15175
0x15182: mov ah, 9
0x15184: mov dx, 0x313
0x15187: add dx, si
0x15189: int 0x21
0x1518b: jmp 0x1518b
2018-12-25T12:38:27.776806728Z 9 PC: 1518b | Display string (String= ' Happy New Year from the ARCV Released 1 June 1992. Made in England by ICE-9 ')

{"DateBased":true,"Day":8,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13568,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:38:27.888508371Z 42 PC: 15161 | Get date 0x15161: cmp dh, 1
0x15164: jne 0x1518d
0x15166: cmp dl, 7
0x15169: jae 0x1518d
0x1516b: mov di, 0x313
0x1516e: add di, si
0x15170: mov al, 0x99
0x15172: mov cx, 0x71
0x15175: mov ah, byte ptr [di]
0x15177: mov dl, ah
0x15179: xor ah, al
0x1517b: mov byte ptr [di], ah
0x1517d: mov al, dl
0x1517f: inc di
0x15180: loop 0x15175
0x15182: mov ah, 9
0x15184: mov dx, 0x313
0x15187: add dx, si
0x15189: int 0x21
0x1518b: jmp 0x1518b
2018-12-25T12:38:27.891686821Z 255 PC: 151a1 | UNKNOWN!
2018-12-25T12:38:27.89272571Z 49 PC: 151e7 | Terminate and stay resident (Return code = '0' | Memory size = '69')

{"DateBased":true,"Day":1,"Month":2,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13568,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:38:28.211296193Z 42 PC: 15161 | Get date 0x15161: cmp dh, 1
0x15164: jne 0x1518d
0x15166: cmp dl, 7
0x15169: jae 0x1518d
0x1516b: mov di, 0x313
0x1516e: add di, si
0x15170: mov al, 0x99
0x15172: mov cx, 0x71
0x15175: mov ah, byte ptr [di]
0x15177: mov dl, ah
0x15179: xor ah, al
0x1517b: mov byte ptr [di], ah
0x1517d: mov al, dl
0x1517f: inc di
0x15180: loop 0x15175
0x15182: mov ah, 9
0x15184: mov dx, 0x313
0x15187: add dx, si
0x15189: int 0x21
0x1518b: jmp 0x1518b
2018-12-25T12:38:28.215253692Z 255 PC: 151a1 | UNKNOWN!
2018-12-25T12:38:28.216092214Z 49 PC: 151e7 | Terminate and stay resident (Return code = '0' | Memory size = '69')

{"DateBased":true,"Day":1,"Month":2,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13568,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:38:28.382585228Z 42 PC: 15161 | Get date 0x15161: cmp dh, 1
0x15164: jne 0x1518d
0x15166: cmp dl, 7
0x15169: jae 0x1518d
0x1516b: mov di, 0x313
0x1516e: add di, si
0x15170: mov al, 0x99
0x15172: mov cx, 0x71
0x15175: mov ah, byte ptr [di]
0x15177: mov dl, ah
0x15179: xor ah, al
0x1517b: mov byte ptr [di], ah
0x1517d: mov al, dl
0x1517f: inc di
0x15180: loop 0x15175
0x15182: mov ah, 9
0x15184: mov dx, 0x313
0x15187: add dx, si
0x15189: int 0x21
0x1518b: jmp 0x1518b
2018-12-25T12:38:28.385020987Z 255 PC: 151a1 | UNKNOWN!
2018-12-25T12:38:28.385718979Z 49 PC: 151e7 | Terminate and stay resident (Return code = '0' | Memory size = '69')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13568,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:38:28.610022536Z 42 PC: 15161 | Get date 0x15161: cmp dh, 1
0x15164: jne 0x1518d
0x15166: cmp dl, 7
0x15169: jae 0x1518d
0x1516b: mov di, 0x313
0x1516e: add di, si
0x15170: mov al, 0x99
0x15172: mov cx, 0x71
0x15175: mov ah, byte ptr [di]
0x15177: mov dl, ah
0x15179: xor ah, al
0x1517b: mov byte ptr [di], ah
0x1517d: mov al, dl
0x1517f: inc di
0x15180: loop 0x15175
0x15182: mov ah, 9
0x15184: mov dx, 0x313
0x15187: add dx, si
0x15189: int 0x21
0x1518b: jmp 0x1518b
2018-12-25T12:38:28.61250448Z 9 PC: 1518b | Display string (String= ' Happy New Year from the ARCV Released 1 June 1992. Made in England by ICE-9 ')

{"DateBased":true,"Day":8,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13568,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:38:29.75739898Z 42 PC: 15161 | Get date 0x15161: cmp dh, 1
0x15164: jne 0x1518d
0x15166: cmp dl, 7
0x15169: jae 0x1518d
0x1516b: mov di, 0x313
0x1516e: add di, si
0x15170: mov al, 0x99
0x15172: mov cx, 0x71
0x15175: mov ah, byte ptr [di]
0x15177: mov dl, ah
0x15179: xor ah, al
0x1517b: mov byte ptr [di], ah
0x1517d: mov al, dl
0x1517f: inc di
0x15180: loop 0x15175
0x15182: mov ah, 9
0x15184: mov dx, 0x313
0x15187: add dx, si
0x15189: int 0x21
0x1518b: jmp 0x1518b
2018-12-25T12:38:29.76053975Z 255 PC: 151a1 | UNKNOWN!
2018-12-25T12:38:29.761993788Z 49 PC: 151e7 | Terminate and stay resident (Return code = '0' | Memory size = '69')