Sample viewer

vx.netlux.org/Virus.DOS.Holiday.2900

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:03:22.712576125Z 9 PC: 12c22 | Display string (Could not find end pointer)
2018-12-17T23:03:22.719438224Z 76 PC: 12c28 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14518,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:40:49.925002431Z 9 PC: 12c22 | Display string (Could not find end pointer)
2018-12-25T12:40:49.929002474Z 76 PC: 12c28 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":3,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14518,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:40:50.045426347Z 64 PC: 0 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T12:40:50.057643674Z 41 PC: 94fae | Parse filename
2018-12-25T12:40:50.078584571Z 41 PC: 9502f | Parse filename
2018-12-25T12:40:50.08054641Z 41 PC: 9504c | Parse filename
2018-12-25T12:40:50.082385731Z 26 PC: 984f7 | Set disk transfer address
2018-12-25T12:40:50.084932733Z 71 PC: 986f3 | Get current directory
2018-12-25T12:40:50.08997902Z 78 PC: 986fe | Find first file
2018-12-25T12:40:50.100434878Z 71 PC: 986f3 | Get current directory (See above)
2018-12-25T12:40:50.103672371Z 78 PC: 986fe | Find first file (See above)
2018-12-25T12:40:50.113536766Z 64 PC: 9a848 | Write file or device (Write 26 bytes on handle 2)
2018-12-25T12:40:50.118322347Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T12:40:50.120280868Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T12:40:50.121352876Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:40:50.122507514Z 62 PC: 122ab | Close file
2018-12-25T12:40:50.124839488Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:40:50.12591589Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:40:50.126935132Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:40:50.135135923Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:40:50.137003474Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:40:50.138324609Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:40:50.139803043Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:40:50.141409425Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:40:50.142728696Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:40:50.144136971Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:40:50.145575537Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:40:50.146808366Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:40:50.148014832Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:40:50.149547756Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:40:50.151290564Z 99 PC: 9a5d7 | Get DBCS lead byte table pointer
2018-12-25T12:40:50.152719781Z 56 PC: 94df9 | Get or set country info
2018-12-25T12:40:50.15513193Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T12:40:50.159261062Z 25 PC: 94e62 | Get default drive
2018-12-25T12:40:50.160594918Z 71 PC: 970dd | Get current directory
2018-12-25T12:40:50.167436214Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T12:40:50.170346953Z 2 PC: 970b2 | Character output (Char = '3e')
2018-12-25T12:40:50.172257817Z 93 PC: 94f20 | File sharing functions
2018-12-25T12:40:50.174886962Z 93 PC: 94f27 | File sharing functions
2018-12-25T12:40:50.176492432Z 10 PC: 94f39 | Buffered keyboard input
2018-12-25T12:41:05.092581279Z 0 PC: 0 | Program terminate (See above)
2018-12-25T12:41:06.447101261Z 0 PC: 0 | Program terminate (See above)
2018-12-25T12:41:06.549329011Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T12:41:06.557244932Z 41 PC: 94fae | Parse filename (See above)
2018-12-25T12:41:06.559259686Z 41 PC: 9502f | Parse filename (See above)
2018-12-25T12:41:06.562353408Z 41 PC: 9504c | Parse filename (See above)
2018-12-25T12:41:06.565763257Z 26 PC: 984f7 | Set disk transfer address (See above)
2018-12-25T12:41:06.567533912Z 71 PC: 986f3 | Get current directory (See above)
2018-12-25T12:41:06.575592512Z 78 PC: 986fe | Find first file (See above)
2018-12-25T12:41:06.585767282Z 71 PC: 9856c | Get current directory
2018-12-25T12:41:06.589018806Z 73 PC: 97c09 | Release memory
2018-12-25T12:41:06.590490558Z 75 PC: 11821 | Execute program
2018-12-25T12:41:06.606568165Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-25T12:41:06.611358203Z 76 PC: 12a4b | Terminate with return code (Return code = '36')

{"DateBased":true,"Day":3,"Month":3,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14518,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:40:50.008127173Z 2 PC: 1268d | Character output (Char = '45')
2018-12-25T12:40:50.011319363Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:40:50.013847967Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:40:50.0165468Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:40:50.018922427Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:40:50.022151297Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:40:50.026657154Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:40:50.029212339Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:40:50.032654975Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:40:50.03480771Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:40:50.037275807Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:40:50.040245548Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:40:50.042290789Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:40:50.044214696Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:40:50.047748305Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:40:50.049703892Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:40:50.051734172Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:40:50.059447091Z 2 PC: 1268d | Character output (See above)