Sample viewer

vx.netlux.org/Virus.DOS.Klepavka.881

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:00.750568443Z 74 PC: 12e5b | Reallocate memory
2018-12-17T23:04:00.753126996Z 88 PC: 12e60 | case 0xGet or set allocation strateg:
2018-12-17T23:04:00.755723661Z 88 PC: 12e68 | case 0xGet or set allocation strateg:
2018-12-17T23:04:00.757155755Z 72 PC: 12e77 | Allocate memory
2018-12-17T23:04:00.75897162Z 88 PC: 12e8c | case 0xGet or set allocation strateg:
2018-12-17T23:04:00.768786683Z 53 PC: 12eac | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:00.770214258Z 37 PC: 12ebf | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:00.771696917Z 42 PC: 12ec6 | Get date 0x12ec6: cmp dh, 2
0x12ec9: jne 0x12f17
0x12ecb: cmp dl, 0x12
0x12ece: jne 0x12f17
0x12ed0: xor si, si
0x12ed2: mov bx, word ptr cs:[0x101]
0x12ed7: add bx, 3
0x12eda: mov dl, byte ptr [bx + si + 0x3f2]
0x12ede: sub dl, 0x64
0x12ee1: mov ah, 2
0x12ee3: int 0x21
0x12ee5: cmp si, 0x45
0x12ee8: nop
0x12ee9: je 0x12eee
0x12eeb: inc si
0x12eec: jmp 0x12eda
0x12eee: mov ah, 8
0x12ef0: int 0x21
0x12ef2: mov ax, 0x3508
0x12ef5: int 0x21
2018-12-17T23:04:00.778083802Z 9 PC: 12e26 | Display string (String= 'BCDEF- This is a 1000 byte COM test, 1994 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14736,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:32.844523331Z 74 PC: 12e5b | Reallocate memory
2018-12-25T12:41:32.847155927Z 88 PC: 12e60 | case 0xGet or set allocation strateg:
2018-12-25T12:41:32.848311798Z 88 PC: 12e68 | case 0xGet or set allocation strateg:
2018-12-25T12:41:32.849519676Z 72 PC: 12e77 | Allocate memory
2018-12-25T12:41:32.851547088Z 88 PC: 12e8c | case 0xGet or set allocation strateg:
2018-12-25T12:41:32.853148426Z 53 PC: 12eac | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:32.854488474Z 37 PC: 12ebf | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:32.856027989Z 42 PC: 12ec6 | Get date 0x12ec6: cmp dh, 2
0x12ec9: jne 0x12f17
0x12ecb: cmp dl, 0x12
0x12ece: jne 0x12f17
0x12ed0: xor si, si
0x12ed2: mov bx, word ptr cs:[0x101]
0x12ed7: add bx, 3
0x12eda: mov dl, byte ptr [bx + si + 0x3f2]
0x12ede: sub dl, 0x64
0x12ee1: mov ah, 2
0x12ee3: int 0x21
0x12ee5: cmp si, 0x45
0x12ee8: nop
0x12ee9: je 0x12eee
0x12eeb: inc si
0x12eec: jmp 0x12eda
0x12eee: mov ah, 8
0x12ef0: int 0x21
0x12ef2: mov ax, 0x3508
0x12ef5: int 0x21
2018-12-25T12:41:32.85775345Z 9 PC: 12e26 | Display string (String= 'BCDEF- This is a 1000 byte COM test, 1994 ')

{"DateBased":true,"Day":1,"Month":2,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14736,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:32.875661591Z 74 PC: 12e5b | Reallocate memory
2018-12-25T12:41:32.878238886Z 88 PC: 12e60 | case 0xGet or set allocation strateg:
2018-12-25T12:41:32.881645384Z 88 PC: 12e68 | case 0xGet or set allocation strateg:
2018-12-25T12:41:32.884686439Z 72 PC: 12e77 | Allocate memory
2018-12-25T12:41:32.887920516Z 88 PC: 12e8c | case 0xGet or set allocation strateg:
2018-12-25T12:41:32.890741855Z 53 PC: 12eac | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:32.892869873Z 37 PC: 12ebf | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:32.901012219Z 42 PC: 12ec6 | Get date 0x12ec6: cmp dh, 2
0x12ec9: jne 0x12f17
0x12ecb: cmp dl, 0x12
0x12ece: jne 0x12f17
0x12ed0: xor si, si
0x12ed2: mov bx, word ptr cs:[0x101]
0x12ed7: add bx, 3
0x12eda: mov dl, byte ptr [bx + si + 0x3f2]
0x12ede: sub dl, 0x64
0x12ee1: mov ah, 2
0x12ee3: int 0x21
0x12ee5: cmp si, 0x45
0x12ee8: nop
0x12ee9: je 0x12eee
0x12eeb: inc si
0x12eec: jmp 0x12eda
0x12eee: mov ah, 8
0x12ef0: int 0x21
0x12ef2: mov ax, 0x3508
0x12ef5: int 0x21
2018-12-25T12:41:32.908754121Z 9 PC: 12e26 | Display string (String= 'BCDEF- This is a 1000 byte COM test, 1994 ')

{"DateBased":true,"Day":18,"Month":2,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14736,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:32.932175784Z 74 PC: 12e5b | Reallocate memory
2018-12-25T12:41:32.934527428Z 88 PC: 12e60 | case 0xGet or set allocation strateg:
2018-12-25T12:41:32.936479918Z 88 PC: 12e68 | case 0xGet or set allocation strateg:
2018-12-25T12:41:32.938336598Z 72 PC: 12e77 | Allocate memory
2018-12-25T12:41:32.941296297Z 88 PC: 12e8c | case 0xGet or set allocation strateg:
2018-12-25T12:41:32.943536086Z 53 PC: 12eac | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:32.945372784Z 37 PC: 12ebf | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:32.94718421Z 42 PC: 12ec6 | Get date 0x12ec6: cmp dh, 2
0x12ec9: jne 0x12f17
0x12ecb: cmp dl, 0x12
0x12ece: jne 0x12f17
0x12ed0: xor si, si
0x12ed2: mov bx, word ptr cs:[0x101]
0x12ed7: add bx, 3
0x12eda: mov dl, byte ptr [bx + si + 0x3f2]
0x12ede: sub dl, 0x64
0x12ee1: mov ah, 2
0x12ee3: int 0x21
0x12ee5: cmp si, 0x45
0x12ee8: nop
0x12ee9: je 0x12eee
0x12eeb: inc si
0x12eec: jmp 0x12eda
0x12eee: mov ah, 8
0x12ef0: int 0x21
0x12ef2: mov ax, 0x3508
0x12ef5: int 0x21
2018-12-25T12:41:32.950977998Z 2 PC: 12ee5 | Character output (Char = '0d')
2018-12-25T12:41:32.954026686Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:32.959634393Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:32.963253144Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:32.965883129Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:32.973897692Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:32.97785881Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:32.980100409Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:32.98174531Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:32.983793521Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:32.985481676Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:32.987071564Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:32.988841833Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:32.990633875Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:32.992149354Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:32.994497235Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:32.999999086Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.002702283Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.005487512Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.012366476Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.016484237Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.020509557Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.02373986Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.026173184Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.028490518Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.031394055Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.034126604Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.036922419Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.041769576Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.052786929Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.055204771Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.058795671Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.061713248Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.064102504Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.066471592Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.069716168Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.072158044Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.074491254Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.07977183Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.082630116Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.08543371Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.089151294Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.091809543Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.09410515Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.101195224Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.104237437Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.106966252Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.110154441Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.122471042Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.125657218Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.127934956Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.133931141Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.136438944Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.138820353Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.142290843Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.145110135Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.14738537Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.150534738Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.153224262Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.155749939Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.16014589Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.162908771Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.166131438Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.169741611Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.172497989Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.176642133Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.180180851Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.183111236Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.185727326Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.190388766Z 2 PC: 12ee5 | Character output (See above)
2018-12-25T12:41:33.200371085Z 8 PC: 12ef2 | Console input without echo