Sample viewer

vx.netlux.org/Virus.DOS.April_1st.Com.1000.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:01:54.202842836Z 221 PC: 12a63 | UNKNOWN!
2018-12-17T23:01:54.205098412Z 53 PC: 12aa7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:54.206972278Z 37 PC: 12ab7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:54.208468703Z 53 PC: 12abc | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:01:54.211457637Z 37 PC: 12acc | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:01:54.21299235Z 74 PC: 12ae7 | Reallocate memory
2018-12-17T23:01:54.214938461Z 75 PC: 12b1e | Execute program
2018-12-17T23:01:54.235168198Z 9 PC: 19355 | Display string (Could not find end pointer)
2018-12-17T23:01:54.247577718Z 48 PC: 19721 | Get DOS version
2018-12-17T23:01:54.248673337Z 73 PC: 19762 | Release memory
2018-12-17T23:01:54.250049084Z 53 PC: 19767 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T23:01:54.251744518Z 53 PC: 19774 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:54.252824882Z 37 PC: 19798 | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T23:01:54.253871837Z 37 PC: 197a8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:54.255893302Z 49 PC: 197b0 | Terminate and stay resident (Return code = '0' | Memory size = '63')
2018-12-17T23:01:54.257701484Z 77 PC: 12b22 | Get program return code
2018-12-17T23:01:54.259936636Z 49 PC: 12b2b | Terminate and stay resident (Return code = '0' | Memory size = '79')

{"DateBased":true,"Day":1,"Month":1,"Year":1988,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14020,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:39:43.442202043Z 221 PC: 12a63 | UNKNOWN!
2018-12-25T12:39:43.443678856Z 53 PC: 12aa7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:39:43.444702319Z 37 PC: 12ab7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:39:43.445821456Z 53 PC: 12abc | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:39:43.44753461Z 37 PC: 12acc | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:39:43.44870486Z 74 PC: 12ae7 | Reallocate memory
2018-12-25T12:39:43.450046564Z 75 PC: 12b1e | Execute program
2018-12-25T12:39:43.466595463Z 9 PC: 19355 | Display string (Could not find end pointer)
2018-12-25T12:39:43.484362285Z 48 PC: 19721 | Get DOS version
2018-12-25T12:39:43.485691545Z 73 PC: 19762 | Release memory
2018-12-25T12:39:43.487460805Z 53 PC: 19767 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-25T12:39:43.488659495Z 53 PC: 19774 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:39:43.489883894Z 37 PC: 19798 | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-25T12:39:43.491837403Z 37 PC: 197a8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:39:43.493145181Z 49 PC: 197b0 | Terminate and stay resident (Return code = '0' | Memory size = '63')
2018-12-25T12:39:43.495335016Z 77 PC: 12b22 | Get program return code
2018-12-25T12:39:43.497359682Z 49 PC: 12b2b | Terminate and stay resident (Return code = '0' | Memory size = '79')

{"DateBased":true,"Day":18,"Month":8,"Year":1988,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14020,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:39:43.534288154Z 221 PC: 12a63 | UNKNOWN!
2018-12-25T12:39:43.535980358Z 53 PC: 12aa7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:39:43.537479383Z 37 PC: 12ab7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:39:43.538953504Z 53 PC: 12abc | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:39:43.541141894Z 37 PC: 12acc | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:39:43.542470673Z 74 PC: 12ae7 | Reallocate memory
2018-12-25T12:39:43.54433961Z 75 PC: 12b1e | Execute program
2018-12-25T12:39:43.567767658Z 9 PC: 19355 | Display string (Could not find end pointer)
2018-12-25T12:39:43.585509742Z 48 PC: 19721 | Get DOS version
2018-12-25T12:39:43.587045436Z 73 PC: 19762 | Release memory
2018-12-25T12:39:43.589664399Z 53 PC: 19767 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-25T12:39:43.591209347Z 53 PC: 19774 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:39:43.592863327Z 37 PC: 19798 | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-25T12:39:43.594537335Z 37 PC: 197a8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:39:43.596391896Z 49 PC: 197b0 | Terminate and stay resident (Return code = '0' | Memory size = '63')
2018-12-25T12:39:43.598305321Z 77 PC: 12b22 | Get program return code
2018-12-25T12:39:43.599463572Z 49 PC: 12b2b | Terminate and stay resident (Return code = '0' | Memory size = '79')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14020,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:39:43.556760986Z 221 PC: 12a63 | UNKNOWN!
2018-12-25T12:39:43.558964082Z 53 PC: 12aa7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:39:43.560603918Z 37 PC: 12ab7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:39:43.562138286Z 53 PC: 12abc | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:39:43.564803181Z 37 PC: 12acc | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:39:43.566777706Z 74 PC: 12ae7 | Reallocate memory
2018-12-25T12:39:43.568707118Z 75 PC: 12b1e | Execute program
2018-12-25T12:39:43.585906481Z 9 PC: 19355 | Display string (Could not find end pointer)
2018-12-25T12:39:43.603859121Z 48 PC: 19721 | Get DOS version
2018-12-25T12:39:43.605009461Z 73 PC: 19762 | Release memory
2018-12-25T12:39:43.607860183Z 53 PC: 19767 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-25T12:39:43.609015229Z 53 PC: 19774 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:39:43.610202827Z 37 PC: 19798 | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-25T12:39:43.611333475Z 37 PC: 197a8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:39:43.612479427Z 49 PC: 197b0 | Terminate and stay resident (Return code = '0' | Memory size = '63')
2018-12-25T12:39:43.614508913Z 77 PC: 12b22 | Get program return code
2018-12-25T12:39:43.61563888Z 49 PC: 12b2b | Terminate and stay resident (Return code = '0' | Memory size = '79')