Sample viewer

vx.netlux.org/Virus.DOS.Xuxa.1405

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:51.204718506Z 221 PC: 12a5f | UNKNOWN!
2018-12-17T23:04:51.205908238Z 53 PC: 12a8d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:51.206915814Z 37 PC: 12a9d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:51.207880916Z 53 PC: 12aa2 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:04:51.20973257Z 37 PC: 12ab2 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:04:51.21088841Z 74 PC: 12acd | Reallocate memory
2018-12-17T23:04:51.21226067Z 75 PC: 12b04 | Execute program
2018-12-17T23:04:51.235533559Z 9 PC: 13137 | Display string (String= '(C) 1993 American Eagle Poblications Inc., All Rights Reserved. Unauthorized use will be prosecuted under applicable copyright and software piracy laws. HOST #1 - You have just released a virus!')
2018-12-17T23:04:51.242821806Z 76 PC: 1313c | Terminate with return code (Return code = '0')
2018-12-17T23:04:51.245995198Z 77 PC: 12b08 | Get program return code
2018-12-17T23:04:51.248257657Z 49 PC: 12b11 | Terminate and stay resident (Return code = '0' | Memory size = '104')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15004,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:42:26.129323274Z 221 PC: 12a5f | UNKNOWN!
2018-12-25T12:42:26.130750123Z 53 PC: 12a8d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:42:26.132352482Z 37 PC: 12a9d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:42:26.133899254Z 53 PC: 12aa2 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:42:26.147985341Z 37 PC: 12ab2 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:42:26.149182022Z 74 PC: 12acd | Reallocate memory
2018-12-25T12:42:26.150657634Z 75 PC: 12b04 | Execute program
2018-12-25T12:42:26.165555679Z 9 PC: 13137 | Display string (String= '(C) 1993 American Eagle Poblications Inc., All Rights Reserved. Unauthorized use will be prosecuted under applicable copyright and software piracy laws. HOST #1 - You have just released a virus!')
2018-12-25T12:42:26.17348025Z 76 PC: 1313c | Terminate with return code (Return code = '0')
2018-12-25T12:42:26.176289278Z 77 PC: 12b08 | Get program return code
2018-12-25T12:42:26.177999015Z 49 PC: 12b11 | Terminate and stay resident (Return code = '0' | Memory size = '104')

{"DateBased":true,"Day":1,"Month":1,"Year":1988,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15004,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:42:26.536398019Z 221 PC: 12a5f | UNKNOWN!
2018-12-25T12:42:26.53820146Z 53 PC: 12a8d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:42:26.539482054Z 37 PC: 12a9d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:42:26.540694987Z 53 PC: 12aa2 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:42:26.541939126Z 37 PC: 12ab2 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:42:26.556903792Z 74 PC: 12acd | Reallocate memory
2018-12-25T12:42:26.5582221Z 75 PC: 12b04 | Execute program
2018-12-25T12:42:26.572344458Z 9 PC: 13137 | Display string (String= '(C) 1993 American Eagle Poblications Inc., All Rights Reserved. Unauthorized use will be prosecuted under applicable copyright and software piracy laws. HOST #1 - You have just released a virus!')
2018-12-25T12:42:26.579600989Z 76 PC: 1313c | Terminate with return code (Return code = '0')
2018-12-25T12:42:26.5823359Z 77 PC: 12b08 | Get program return code
2018-12-25T12:42:26.58331185Z 49 PC: 12b11 | Terminate and stay resident (Return code = '0' | Memory size = '104')

{"DateBased":true,"Day":2,"Month":8,"Year":1988,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15004,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:42:26.557208264Z 221 PC: 12a5f | UNKNOWN!
2018-12-25T12:42:26.558651263Z 53 PC: 12a8d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:42:26.563503705Z 37 PC: 12a9d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:42:26.564894767Z 53 PC: 12aa2 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:42:26.573868049Z 37 PC: 12ab2 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:42:26.574984227Z 74 PC: 12acd | Reallocate memory
2018-12-25T12:42:26.576307492Z 75 PC: 12b04 | Execute program
2018-12-25T12:42:26.596703477Z 9 PC: 13137 | Display string (String= '(C) 1993 American Eagle Poblications Inc., All Rights Reserved. Unauthorized use will be prosecuted under applicable copyright and software piracy laws. HOST #1 - You have just released a virus!')
2018-12-25T12:42:26.603898758Z 76 PC: 1313c | Terminate with return code (Return code = '0')
2018-12-25T12:42:26.606757872Z 77 PC: 12b08 | Get program return code
2018-12-25T12:42:26.608243842Z 49 PC: 12b11 | Terminate and stay resident (Return code = '0' | Memory size = '104')

{"DateBased":true,"Day":3,"Month":8,"Year":1988,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15004,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:42:26.605988873Z 221 PC: 12a5f | UNKNOWN!
2018-12-25T12:42:26.607181456Z 53 PC: 12a8d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:42:26.608313653Z 37 PC: 12a9d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:42:26.609373149Z 53 PC: 12aa2 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:42:26.610958846Z 37 PC: 12ab2 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:42:26.612075483Z 74 PC: 12acd | Reallocate memory
2018-12-25T12:42:26.613306585Z 75 PC: 12b04 | Execute program
2018-12-25T12:42:26.6278698Z 9 PC: 13137 | Display string (String= '(C) 1993 American Eagle Poblications Inc., All Rights Reserved. Unauthorized use will be prosecuted under applicable copyright and software piracy laws. HOST #1 - You have just released a virus!')
2018-12-25T12:42:26.635331812Z 76 PC: 1313c | Terminate with return code (Return code = '0')
2018-12-25T12:42:26.644426485Z 77 PC: 12b08 | Get program return code
2018-12-25T12:42:26.645814938Z 49 PC: 12b11 | Terminate and stay resident (Return code = '0' | Memory size = '104')