Sample viewer

vx.netlux.org/Virus.DOS.VCL.Marbas.1303

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:33.146369887Z 25 PC: 12b84 | Get default drive
2018-12-17T23:02:33.148267292Z 71 PC: 12b94 | Get current directory
2018-12-17T23:02:33.151569404Z 42 PC: 12e03 | Get date 0x12e03: cmp al, 5
0x12e05: jne 0x12e0e
0x12e07: cmp dl, 0xd
0x12e0a: jne 0x12e0e
0x12e0c: jmp 0x12e2a
0x12e0e: mov ah, 0x2c
0x12e10: int 0x21
0x12e12: cmp ch, 0
0x12e15: jne 0x12e21
0x12e17: mov ah, 0x2a
0x12e19: int 0x21
0x12e1b: cmp al, 5
0x12e1d: jne 0x12e21
0x12e1f: jmp 0x12e2b
0x12e21: in ax, 0x40
0x12e23: cmp ax, 0x29a
0x12e26: je 0x12e29
0x12e28: ret
0x12e29: ret
0x12e2a: ret
2018-12-17T23:02:33.154133279Z 44 PC: 12e12 | Get time 0x12e12: cmp ch, 0
0x12e15: jne 0x12e21
0x12e17: mov ah, 0x2a
0x12e19: int 0x21
0x12e1b: cmp al, 5
0x12e1d: jne 0x12e21
0x12e1f: jmp 0x12e2b
0x12e21: in ax, 0x40
0x12e23: cmp ax, 0x29a
0x12e26: je 0x12e29
0x12e28: ret
0x12e29: ret
0x12e2a: ret
0x12e2b: ret
0x12e2c: pop bx
0x12e2d: cli
0x12e2e: push ax
0x12e2f: outsw dx, word ptr [si]
0x12e30: insb byte ptr es:[di], dx
0x12e31: jns 0x12e80
2018-12-17T23:02:33.15851416Z 26 PC: 12c39 | Set disk transfer address
2018-12-17T23:02:33.160846314Z 78 PC: 12c44 | Find first file
2018-12-17T23:02:33.165814709Z 26 PC: 12baf | Set disk transfer address
2018-12-17T23:02:33.167328756Z 78 PC: 12bba | Find first file
2018-12-17T23:02:33.178351385Z 0 PC: 12c04 | Program terminate

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":14256,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:40:16.088003609Z 25 PC: 12b84 | Get default drive
2018-12-25T12:40:16.089540379Z 71 PC: 12b94 | Get current directory
2018-12-25T12:40:16.09345655Z 42 PC: 12e03 | Get date 0x12e03: cmp al, 5
0x12e05: jne 0x12e0e
0x12e07: cmp dl, 0xd
0x12e0a: jne 0x12e0e
0x12e0c: jmp 0x12e2a
0x12e0e: mov ah, 0x2c
0x12e10: int 0x21
0x12e12: cmp ch, 0
0x12e15: jne 0x12e21
0x12e17: mov ah, 0x2a
0x12e19: int 0x21
0x12e1b: cmp al, 5
0x12e1d: jne 0x12e21
0x12e1f: jmp 0x12e2b
0x12e21: in ax, 0x40
0x12e23: cmp ax, 0x29a
0x12e26: je 0x12e29
0x12e28: ret
0x12e29: ret
0x12e2a: ret
2018-12-25T12:40:16.096431454Z 44 PC: 12e12 | Get time 0x12e12: cmp ch, 0
0x12e15: jne 0x12e21
0x12e17: mov ah, 0x2a
0x12e19: int 0x21
0x12e1b: cmp al, 5
0x12e1d: jne 0x12e21
0x12e1f: jmp 0x12e2b
0x12e21: in ax, 0x40
0x12e23: cmp ax, 0x29a
0x12e26: je 0x12e29
0x12e28: ret
0x12e29: ret
0x12e2a: ret
0x12e2b: ret
0x12e2c: pop bx
0x12e2d: cli
0x12e2e: push ax
0x12e2f: outsw dx, word ptr [si]
0x12e30: insb byte ptr es:[di], dx
0x12e31: jns 0x12e80
2018-12-25T12:40:16.09906952Z 42 PC: 12e1b | Get date 0x12e1b: cmp al, 5
0x12e1d: jne 0x12e21
0x12e1f: jmp 0x12e2b
0x12e21: in ax, 0x40
0x12e23: cmp ax, 0x29a
0x12e26: je 0x12e29
0x12e28: ret
0x12e29: ret
0x12e2a: ret
0x12e2b: ret
0x12e2c: pop bx
0x12e2d: cli
0x12e2e: push ax
0x12e2f: outsw dx, word ptr [si]
0x12e30: insb byte ptr es:[di], dx
0x12e31: jns 0x12e80
0x12e33: outsw dx, word ptr [si]
0x12e34: jb 0x12ea6
0x12e36: push 0x7369
0x12e39: dec bp
2018-12-25T12:40:16.102280457Z 26 PC: 12c39 | Set disk transfer address
2018-12-25T12:40:16.103644193Z 78 PC: 12c44 | Find first file
2018-12-25T12:40:16.108155451Z 26 PC: 12baf | Set disk transfer address
2018-12-25T12:40:16.109779804Z 78 PC: 12bba | Find first file
2018-12-25T12:40:16.114857498Z 0 PC: 12c04 | Program terminate

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":14256,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:40:16.249597684Z 25 PC: 12b84 | Get default drive
2018-12-25T12:40:16.251745646Z 71 PC: 12b94 | Get current directory
2018-12-25T12:40:16.254537988Z 42 PC: 12e03 | Get date 0x12e03: cmp al, 5
0x12e05: jne 0x12e0e
0x12e07: cmp dl, 0xd
0x12e0a: jne 0x12e0e
0x12e0c: jmp 0x12e2a
0x12e0e: mov ah, 0x2c
0x12e10: int 0x21
0x12e12: cmp ch, 0
0x12e15: jne 0x12e21
0x12e17: mov ah, 0x2a
0x12e19: int 0x21
0x12e1b: cmp al, 5
0x12e1d: jne 0x12e21
0x12e1f: jmp 0x12e2b
0x12e21: in ax, 0x40
0x12e23: cmp ax, 0x29a
0x12e26: je 0x12e29
0x12e28: ret
0x12e29: ret
0x12e2a: ret
2018-12-25T12:40:16.257190369Z 44 PC: 12e12 | Get time 0x12e12: cmp ch, 0
0x12e15: jne 0x12e21
0x12e17: mov ah, 0x2a
0x12e19: int 0x21
0x12e1b: cmp al, 5
0x12e1d: jne 0x12e21
0x12e1f: jmp 0x12e2b
0x12e21: in ax, 0x40
0x12e23: cmp ax, 0x29a
0x12e26: je 0x12e29
0x12e28: ret
0x12e29: ret
0x12e2a: ret
0x12e2b: ret
0x12e2c: pop bx
0x12e2d: cli
0x12e2e: push ax
0x12e2f: outsw dx, word ptr [si]
0x12e30: insb byte ptr es:[di], dx
0x12e31: jns 0x12e80
2018-12-25T12:40:16.260095658Z 42 PC: 12e1b | Get date 0x12e1b: cmp al, 5
0x12e1d: jne 0x12e21
0x12e1f: jmp 0x12e2b
0x12e21: in ax, 0x40
0x12e23: cmp ax, 0x29a
0x12e26: je 0x12e29
0x12e28: ret
0x12e29: ret
0x12e2a: ret
0x12e2b: ret
0x12e2c: pop bx
0x12e2d: cli
0x12e2e: push ax
0x12e2f: outsw dx, word ptr [si]
0x12e30: insb byte ptr es:[di], dx
0x12e31: jns 0x12e80
0x12e33: outsw dx, word ptr [si]
0x12e34: jb 0x12ea6
0x12e36: push 0x7369
0x12e39: dec bp
2018-12-25T12:40:16.262545865Z 26 PC: 12c39 | Set disk transfer address
2018-12-25T12:40:16.263580044Z 78 PC: 12c44 | Find first file
2018-12-25T12:40:16.274394633Z 26 PC: 12baf | Set disk transfer address
2018-12-25T12:40:16.275637021Z 78 PC: 12bba | Find first file
2018-12-25T12:40:16.284293592Z 3 PC: 12c04 | Auxiliary input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":1,"Min":0,"Second":0,"TimeBased":true,"OriginalID":14256,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:40:16.490258429Z 25 PC: 12b84 | Get default drive
2018-12-25T12:40:16.492363972Z 71 PC: 12b94 | Get current directory
2018-12-25T12:40:16.496770781Z 42 PC: 12e03 | Get date 0x12e03: cmp al, 5
0x12e05: jne 0x12e0e
0x12e07: cmp dl, 0xd
0x12e0a: jne 0x12e0e
0x12e0c: jmp 0x12e2a
0x12e0e: mov ah, 0x2c
0x12e10: int 0x21
0x12e12: cmp ch, 0
0x12e15: jne 0x12e21
0x12e17: mov ah, 0x2a
0x12e19: int 0x21
0x12e1b: cmp al, 5
0x12e1d: jne 0x12e21
0x12e1f: jmp 0x12e2b
0x12e21: in ax, 0x40
0x12e23: cmp ax, 0x29a
0x12e26: je 0x12e29
0x12e28: ret
0x12e29: ret
0x12e2a: ret
2018-12-25T12:40:16.499644681Z 44 PC: 12e12 | Get time 0x12e12: cmp ch, 0
0x12e15: jne 0x12e21
0x12e17: mov ah, 0x2a
0x12e19: int 0x21
0x12e1b: cmp al, 5
0x12e1d: jne 0x12e21
0x12e1f: jmp 0x12e2b
0x12e21: in ax, 0x40
0x12e23: cmp ax, 0x29a
0x12e26: je 0x12e29
0x12e28: ret
0x12e29: ret
0x12e2a: ret
0x12e2b: ret
0x12e2c: pop bx
0x12e2d: cli
0x12e2e: push ax
0x12e2f: outsw dx, word ptr [si]
0x12e30: insb byte ptr es:[di], dx
0x12e31: jns 0x12e80
2018-12-25T12:40:16.503519518Z 26 PC: 12c39 | Set disk transfer address
2018-12-25T12:40:16.504978Z 78 PC: 12c44 | Find first file
2018-12-25T12:40:16.510254982Z 26 PC: 12baf | Set disk transfer address
2018-12-25T12:40:16.512694253Z 78 PC: 12bba | Find first file
2018-12-25T12:40:16.517809393Z 0 PC: 12c04 | Program terminate

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":1,"Min":0,"Second":0,"TimeBased":true,"OriginalID":14256,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:40:16.54665923Z 25 PC: 12b84 | Get default drive
2018-12-25T12:40:16.548011786Z 71 PC: 12b94 | Get current directory
2018-12-25T12:40:16.5502228Z 42 PC: 12e03 | Get date 0x12e03: cmp al, 5
0x12e05: jne 0x12e0e
0x12e07: cmp dl, 0xd
0x12e0a: jne 0x12e0e
0x12e0c: jmp 0x12e2a
0x12e0e: mov ah, 0x2c
0x12e10: int 0x21
0x12e12: cmp ch, 0
0x12e15: jne 0x12e21
0x12e17: mov ah, 0x2a
0x12e19: int 0x21
0x12e1b: cmp al, 5
0x12e1d: jne 0x12e21
0x12e1f: jmp 0x12e2b
0x12e21: in ax, 0x40
0x12e23: cmp ax, 0x29a
0x12e26: je 0x12e29
0x12e28: ret
0x12e29: ret
0x12e2a: ret
2018-12-25T12:40:16.551799733Z 44 PC: 12e12 | Get time 0x12e12: cmp ch, 0
0x12e15: jne 0x12e21
0x12e17: mov ah, 0x2a
0x12e19: int 0x21
0x12e1b: cmp al, 5
0x12e1d: jne 0x12e21
0x12e1f: jmp 0x12e2b
0x12e21: in ax, 0x40
0x12e23: cmp ax, 0x29a
0x12e26: je 0x12e29
0x12e28: ret
0x12e29: ret
0x12e2a: ret
0x12e2b: ret
0x12e2c: pop bx
0x12e2d: cli
0x12e2e: push ax
0x12e2f: outsw dx, word ptr [si]
0x12e30: insb byte ptr es:[di], dx
0x12e31: jns 0x12e80
2018-12-25T12:40:16.553546257Z 26 PC: 12c39 | Set disk transfer address
2018-12-25T12:40:16.554981858Z 78 PC: 12c44 | Find first file
2018-12-25T12:40:16.558150594Z 26 PC: 12baf | Set disk transfer address
2018-12-25T12:40:16.559511967Z 78 PC: 12bba | Find first file
2018-12-25T12:40:16.56294735Z 3 PC: 12c04 | Auxiliary input