Sample viewer

vx.netlux.org/Virus.DOS.Opic.726

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:03:24.321026925Z 47 PC: 2132d | Get disk transfer address
2018-12-17T22:03:24.322697072Z 26 PC: 21339 | Set disk transfer address
2018-12-17T22:03:24.3237842Z 78 PC: 21351 | Find first file
2018-12-17T22:03:24.330174291Z 61 PC: 213cf | Open file (Filename = 'TEST.EXE')
2018-12-17T22:03:24.33641428Z 63 PC: 213dc | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:03:24.338773151Z 62 PC: 214d9 | Close file
2018-12-17T22:03:24.341190435Z 79 PC: 21351 | Find next file
2018-12-17T22:03:24.343432331Z 59 PC: 2135e | Change current directory
2018-12-17T22:03:24.34722773Z 42 PC: 21364 | Get date 0x21364: cmp dl, 1
0x21367: je 0x21379
0x21369: nop
0x2136a: nop
0x2136b: nop
0x2136c: cmp dl, 1
0x2136f: je 0x21379
0x21371: nop
0x21372: nop
0x21373: nop
0x21374: je 0x21379
0x21376: jmp 0x214de
0x21379: mov ah, 0x2c
0x2137b: int 0x21
0x2137d: cmp dh, 0x1e
0x21380: jb 0x21388
0x21382: nop
0x21383: nop
0x21384: nop
0x21385: jmp 0x214de
2018-12-17T22:03:24.349707067Z 26 PC: 214e4 | Set disk transfer address
2018-12-17T22:03:24.350701737Z 9 PC: 12a7c | Display string (Could not find end pointer)
2018-12-17T22:03:24.354381128Z 76 PC: 12a81 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":1499,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:43:53.262254754Z 2 PC: 1268d | Character output (Char = '45')
2018-12-25T11:43:53.264150617Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:43:53.265538082Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:43:53.26713847Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:43:53.269376889Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:43:53.270843079Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:43:53.272300571Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:43:53.274379589Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:43:53.27590781Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:43:53.277378318Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:43:53.279469763Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:43:53.280935931Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:43:53.282382762Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:43:53.284808893Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:43:53.286217699Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:43:53.287663852Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:43:53.30358738Z 2 PC: 1268d | Character output (See above)
2018-12-25T11:43:53.305786214Z 2 PC: 1268d | Character output (See above)

{"DateBased":true,"Day":2,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":1499,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:43:53.196891811Z 64 PC: 0 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T11:43:53.20568328Z 41 PC: 94fae | Parse filename
2018-12-25T11:43:53.212079317Z 41 PC: 9502f | Parse filename
2018-12-25T11:43:53.21384011Z 41 PC: 9504c | Parse filename
2018-12-25T11:43:53.216536618Z 26 PC: 984f7 | Set disk transfer address
2018-12-25T11:43:53.218713102Z 71 PC: 986f3 | Get current directory
2018-12-25T11:43:53.231208807Z 78 PC: 986fe | Find first file
2018-12-25T11:43:53.24343869Z 71 PC: 986f3 | Get current directory (See above)
2018-12-25T11:43:53.259094201Z 78 PC: 986fe | Find first file (See above)
2018-12-25T11:43:53.269011847Z 64 PC: 9a848 | Write file or device (Write 26 bytes on handle 2)
2018-12-25T11:43:53.281073297Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T11:43:53.282667572Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:43:53.283754567Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:43:53.29138043Z 62 PC: 122ab | Close file
2018-12-25T11:43:53.293340187Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:43:53.29508864Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:43:53.297064023Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:43:53.299565466Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:43:53.30130481Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:43:53.303042161Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:43:53.305721612Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:43:53.307453061Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:43:53.309223203Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:43:53.312080226Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:43:53.313643933Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:43:53.31516872Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:43:53.317398115Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:43:53.319063885Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:43:53.321060205Z 99 PC: 9a5d7 | Get DBCS lead byte table pointer
2018-12-25T11:43:53.32329833Z 56 PC: 94df9 | Get or set country info
2018-12-25T11:43:53.325315691Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T11:43:53.329799816Z 25 PC: 94e62 | Get default drive
2018-12-25T11:43:53.332493018Z 71 PC: 970dd | Get current directory
2018-12-25T11:43:53.337124644Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T11:43:53.340316229Z 2 PC: 970b2 | Character output (Char = '3e')
2018-12-25T11:43:53.34882444Z 93 PC: 94f20 | File sharing functions
2018-12-25T11:43:53.352283268Z 93 PC: 94f27 | File sharing functions
2018-12-25T11:43:53.354216147Z 10 PC: 94f39 | Buffered keyboard input
2018-12-25T11:44:08.243966195Z 0 PC: 0 | Program terminate (See above)
2018-12-25T11:44:09.59871516Z 0 PC: 0 | Program terminate (See above)
2018-12-25T11:44:09.702072413Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T11:44:09.708586197Z 41 PC: 94fae | Parse filename (See above)
2018-12-25T11:44:09.710597585Z 41 PC: 9502f | Parse filename (See above)
2018-12-25T11:44:09.713430344Z 41 PC: 9504c | Parse filename (See above)
2018-12-25T11:44:09.716833256Z 26 PC: 984f7 | Set disk transfer address (See above)
2018-12-25T11:44:09.718729702Z 71 PC: 986f3 | Get current directory (See above)
2018-12-25T11:44:09.74222137Z 78 PC: 986fe | Find first file (See above)
2018-12-25T11:44:09.758834726Z 71 PC: 9856c | Get current directory
2018-12-25T11:44:09.762164228Z 73 PC: 97c09 | Release memory
2018-12-25T11:44:09.764488545Z 75 PC: 11821 | Execute program
2018-12-25T11:44:09.778594816Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-25T11:44:09.78361422Z 76 PC: 12a4b | Terminate with return code (Return code = '36')