Sample viewer

vx.netlux.org/Virus.DOS.Tim.1700

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:02:54.949456848Z 189 PC: 13719 | UNKNOWN!
2018-12-17T22:02:54.951163086Z 42 PC: 13726 | Get date 0x13726: cli
0x13727: cmp cx, 0x7c4
0x1372b: jne 0x1373f
0x1372d: cmp dx, 0xa0d
0x13731: jne 0x1373f
0x13733: lea di, word ptr [0x6c]
0x13737: call 0x13c06
0x1373a: xor ax, ax
0x1373c: push es
0x1373d: push ax
0x1373e: retf
0x1373f: mov byte ptr cs:[0xf2], 0x19
0x13745: mov di, 0x100
0x13748: mov cx, 0x6a4
0x1374b: nop
0x1374c: push cs
0x1374d: pop ds
0x1374e: cld
0x1374f: xor si, si
0x13751: rep movsb byte ptr es:[di], byte ptr [si]
2018-12-17T22:02:54.953403985Z 74 PC: 12bad | Reallocate memory
2018-12-17T22:02:54.954801648Z 53 PC: 12bb3 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:02:54.957140926Z 37 PC: 12bc9 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:02:54.958704035Z 75 PC: 12c14 | Execute program
2018-12-17T22:02:54.973309051Z 76 PC: 135a4 | Terminate with return code (Return code = '0')
2018-12-17T22:02:54.976837207Z 73 PC: 12c1a | Release memory
2018-12-17T22:02:54.978446479Z 64 PC: 12c1f | Write file or device (Write 32718 bytes on handle 35958)
2018-12-17T22:02:54.979986184Z 49 PC: 12c27 | Terminate and stay resident (Return code = '6' | Memory size = '176')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":1441,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:43:36.257541339Z 189 PC: 13719 | UNKNOWN!
2018-12-25T11:43:36.258953458Z 42 PC: 13726 | Get date 0x13726: cli
0x13727: cmp cx, 0x7c4
0x1372b: jne 0x1373f
0x1372d: cmp dx, 0xa0d
0x13731: jne 0x1373f
0x13733: lea di, word ptr [0x6c]
0x13737: call 0x13c06
0x1373a: xor ax, ax
0x1373c: push es
0x1373d: push ax
0x1373e: retf
0x1373f: mov byte ptr cs:[0xf2], 0x19
0x13745: mov di, 0x100
0x13748: mov cx, 0x6a4
0x1374b: nop
0x1374c: push cs
0x1374d: pop ds
0x1374e: cld
0x1374f: xor si, si
0x13751: rep movsb byte ptr es:[di], byte ptr [si]
2018-12-25T11:43:36.261527999Z 74 PC: 12bad | Reallocate memory
2018-12-25T11:43:36.26313042Z 53 PC: 12bb3 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:43:36.265360075Z 37 PC: 12bc9 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:43:36.267005828Z 75 PC: 12c14 | Execute program
2018-12-25T11:43:36.281419114Z 76 PC: 135a4 | Terminate with return code (Return code = '0')
2018-12-25T11:43:36.28469083Z 73 PC: 12c1a | Release memory
2018-12-25T11:43:36.28681843Z 64 PC: 12c1f | Write file or device (Write 32718 bytes on handle 35958)
2018-12-25T11:43:36.288334678Z 49 PC: 12c27 | Terminate and stay resident (Return code = '6' | Memory size = '176')

{"DateBased":true,"Day":1,"Month":1,"Year":1988,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":1441,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:43:36.389786482Z 189 PC: 13719 | UNKNOWN!
2018-12-25T11:43:36.3910745Z 42 PC: 13726 | Get date 0x13726: cli
0x13727: cmp cx, 0x7c4
0x1372b: jne 0x1373f
0x1372d: cmp dx, 0xa0d
0x13731: jne 0x1373f
0x13733: lea di, word ptr [0x6c]
0x13737: call 0x13c06
0x1373a: xor ax, ax
0x1373c: push es
0x1373d: push ax
0x1373e: retf
0x1373f: mov byte ptr cs:[0xf2], 0x19
0x13745: mov di, 0x100
0x13748: mov cx, 0x6a4
0x1374b: nop
0x1374c: push cs
0x1374d: pop ds
0x1374e: cld
0x1374f: xor si, si
0x13751: rep movsb byte ptr es:[di], byte ptr [si]
2018-12-25T11:43:36.393602035Z 74 PC: 12bad | Reallocate memory
2018-12-25T11:43:36.395247161Z 53 PC: 12bb3 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:43:36.397008936Z 37 PC: 12bc9 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:43:36.399389779Z 75 PC: 12c14 | Execute program
2018-12-25T11:43:36.415641586Z 76 PC: 135a4 | Terminate with return code (Return code = '0')
2018-12-25T11:43:36.419089404Z 73 PC: 12c1a | Release memory
2018-12-25T11:43:36.421984267Z 64 PC: 12c1f | Write file or device (Write 32718 bytes on handle 35958)
2018-12-25T11:43:36.423924493Z 49 PC: 12c27 | Terminate and stay resident (Return code = '6' | Memory size = '176')

{"DateBased":true,"Day":13,"Month":10,"Year":1988,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":1441,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:43:36.427114151Z 189 PC: 13719 | UNKNOWN!
2018-12-25T11:43:36.428893978Z 42 PC: 13726 | Get date 0x13726: cli
0x13727: cmp cx, 0x7c4
0x1372b: jne 0x1373f
0x1372d: cmp dx, 0xa0d
0x13731: jne 0x1373f
0x13733: lea di, word ptr [0x6c]
0x13737: call 0x13c06
0x1373a: xor ax, ax
0x1373c: push es
0x1373d: push ax
0x1373e: retf
0x1373f: mov byte ptr cs:[0xf2], 0x19
0x13745: mov di, 0x100
0x13748: mov cx, 0x6a4
0x1374b: nop
0x1374c: push cs
0x1374d: pop ds
0x1374e: cld
0x1374f: xor si, si
0x13751: rep movsb byte ptr es:[di], byte ptr [si]
2018-12-25T11:43:36.431405136Z 2 PC: 13bcc | Character output (Char = '07')