Sample viewer

vx.netlux.org/Virus.DOS.CFFL.2560

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:10.490572132Z 26 PC: 207fc | Set disk transfer address
2018-12-17T23:04:10.491528976Z 98 PC: 20800 | Get current PSP
2018-12-17T23:04:10.492563847Z 53 PC: 20af5 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:04:10.494064304Z 44 PC: 20b04 | Get time 0x20b04: cmp cl, 0x1e
0x20b07: jge 0x20b0c
0x20b09: jmp 0x20b93
0x20b0c: mov ah, 0x35
0x20b0e: mov al, 8
0x20b10: int 0x21
0x20b12: mov word ptr ds:[bp + 0x89a], bx
0x20b17: mov word ptr ds:[bp + 0x89c], es
0x20b1c: lea bx, word ptr [bp + 0x6d3]
0x20b20: mov cx, 0x28
0x20b23: mov al, byte ptr [bx]
0x20b25: xor al, 0x4f
0x20b27: xor al, 0x5a
0x20b29: xor al, 0x53
0x20b2b: mov byte ptr [bx], al
0x20b2d: inc bx
0x20b2e: loop 0x20b23
0x20b30: lea bx, word ptr [bp + 0x614]
0x20b34: mov cx, 0x20
0x20b37: mov al, byte ptr [bx]
2018-12-17T23:04:10.496520972Z 64 PC: 1a1ab | Write file or device (Write 1 bytes on handle 2)
2018-12-17T23:04:10.507722043Z 64 PC: 1a1ab | Write file or device (Write 1 bytes on handle 2)
2018-12-17T23:04:10.622084472Z 76 PC: 0 | Terminate with return code (Return code = '0')

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":14786,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:41.900091677Z 26 PC: 207fc | Set disk transfer address
2018-12-25T12:41:41.901257806Z 98 PC: 20800 | Get current PSP
2018-12-25T12:41:41.902063655Z 53 PC: 20af5 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T12:41:41.903637953Z 44 PC: 20b04 | Get time 0x20b04: cmp cl, 0x1e
0x20b07: jge 0x20b0c
0x20b09: jmp 0x20b93
0x20b0c: mov ah, 0x35
0x20b0e: mov al, 8
0x20b10: int 0x21
0x20b12: mov word ptr ds:[bp + 0x89a], bx
0x20b17: mov word ptr ds:[bp + 0x89c], es
0x20b1c: lea bx, word ptr [bp + 0x6d3]
0x20b20: mov cx, 0x28
0x20b23: mov al, byte ptr [bx]
0x20b25: xor al, 0x4f
0x20b27: xor al, 0x5a
0x20b29: xor al, 0x53
0x20b2b: mov byte ptr [bx], al
0x20b2d: inc bx
0x20b2e: loop 0x20b23
0x20b30: lea bx, word ptr [bp + 0x614]
0x20b34: mov cx, 0x20
0x20b37: mov al, byte ptr [bx]
2018-12-25T12:41:41.906231627Z 64 PC: 1a1ab | Write file or device (Write 1 bytes on handle 2)
2018-12-25T12:41:41.943362961Z 64 PC: 1a1ab | Write file or device (See above)
2018-12-25T12:41:41.999202117Z 66 PC: 1ade2 | Move file pointer
2018-12-25T12:41:42.001253154Z 64 PC: 1a1ab | Write file or device (See above)
2018-12-25T12:41:42.004277385Z 66 PC: 1add3 | Move file pointer
2018-12-25T12:41:42.007042369Z 64 PC: 1a1ab | Write file or device (See above)
2018-12-25T12:41:42.058023737Z 64 PC: 1a1ab | Write file or device (See above)
2018-12-25T12:41:42.062085867Z 66 PC: 1add3 | Move file pointer (See above)
2018-12-25T12:41:42.064734303Z 64 PC: 1a1ab | Write file or device (See above)
2018-12-25T12:41:42.115803332Z 64 PC: 1a1ab | Write file or device (See above)
2018-12-25T12:41:42.120160216Z 66 PC: 1add3 | Move file pointer (See above)
2018-12-25T12:41:42.122065952Z 64 PC: 1a1ab | Write file or device (See above)
2018-12-25T12:41:42.173972204Z 64 PC: 1a1ab | Write file or device (See above)

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":30,"Second":0,"TimeBased":true,"OriginalID":14786,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:41.94575408Z 26 PC: 207fc | Set disk transfer address
2018-12-25T12:41:41.946679232Z 98 PC: 20800 | Get current PSP
2018-12-25T12:41:41.947368742Z 53 PC: 20af5 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T12:41:41.950541116Z 44 PC: 20b04 | Get time 0x20b04: cmp cl, 0x1e
0x20b07: jge 0x20b0c
0x20b09: jmp 0x20b93
0x20b0c: mov ah, 0x35
0x20b0e: mov al, 8
0x20b10: int 0x21
0x20b12: mov word ptr ds:[bp + 0x89a], bx
0x20b17: mov word ptr ds:[bp + 0x89c], es
0x20b1c: lea bx, word ptr [bp + 0x6d3]
0x20b20: mov cx, 0x28
0x20b23: mov al, byte ptr [bx]
0x20b25: xor al, 0x4f
0x20b27: xor al, 0x5a
0x20b29: xor al, 0x53
0x20b2b: mov byte ptr [bx], al
0x20b2d: inc bx
0x20b2e: loop 0x20b23
0x20b30: lea bx, word ptr [bp + 0x614]
0x20b34: mov cx, 0x20
0x20b37: mov al, byte ptr [bx]
2018-12-25T12:41:41.952055215Z 53 PC: 20b12 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T12:41:41.952935139Z 37 PC: 20b75 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T12:41:41.955503222Z 49 PC: 20b93 | Terminate and stay resident (Return code = '0' | Memory size = '93')