Sample viewer

vx.netlux.org/Virus.DOS.Lyceum.1788

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:05:56.454065864Z 187 PC: 13dd5 | UNKNOWN!
2018-12-17T23:05:56.45618024Z 42 PC: 13e15 | Get date 0x13e15: xor al, al
0x13e17: cmp dl, 0xd
0x13e1a: jne 0x13e1e
0x13e1c: dec al
0x13e1e: mov byte ptr [0x70a], al
0x13e21: mov ax, 0x3508
0x13e24: int 0x21
0x13e26: mov word ptr [0x6fc], bx
0x13e2a: mov word ptr [0x6fe], es
0x13e2e: mov al, 9
0x13e30: int 0x21
0x13e32: mov word ptr [0x700], bx
0x13e36: mov word ptr [0x702], es
0x13e3a: mov al, 0x21
0x13e3c: int 0x21
0x13e3e: mov word ptr [0x704], bx
0x13e42: mov word ptr [0x706], es
0x13e46: mov dx, 0xd6
0x13e49: mov ax, 0x2508
0x13e4c: int 0x21
2018-12-17T23:05:56.458921344Z 53 PC: 13e26 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:05:56.460526702Z 53 PC: 13e32 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:05:56.463055006Z 53 PC: 13e3e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:05:56.465198827Z 37 PC: 13e4e | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:05:56.46704068Z 37 PC: 13e55 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:05:56.468844281Z 37 PC: 13e5c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:05:56.471953457Z 9 PC: 13dc6 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15361,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:43:15.01576217Z 187 PC: 13dd5 | UNKNOWN!
2018-12-25T12:43:15.029675628Z 42 PC: 13e15 | Get date 0x13e15: xor al, al
0x13e17: cmp dl, 0xd
0x13e1a: jne 0x13e1e
0x13e1c: dec al
0x13e1e: mov byte ptr [0x70a], al
0x13e21: mov ax, 0x3508
0x13e24: int 0x21
0x13e26: mov word ptr [0x6fc], bx
0x13e2a: mov word ptr [0x6fe], es
0x13e2e: mov al, 9
0x13e30: int 0x21
0x13e32: mov word ptr [0x700], bx
0x13e36: mov word ptr [0x702], es
0x13e3a: mov al, 0x21
0x13e3c: int 0x21
0x13e3e: mov word ptr [0x704], bx
0x13e42: mov word ptr [0x706], es
0x13e46: mov dx, 0xd6
0x13e49: mov ax, 0x2508
0x13e4c: int 0x21
2018-12-25T12:43:15.032788624Z 53 PC: 13e26 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T12:43:15.034376659Z 53 PC: 13e32 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:43:15.036055339Z 53 PC: 13e3e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:43:15.038813474Z 37 PC: 13e4e | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T12:43:15.040369094Z 37 PC: 13e55 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:43:15.041710088Z 37 PC: 13e5c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:43:15.043779198Z 9 PC: 13dc6 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":13,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15361,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:43:15.472799963Z 187 PC: 13dd5 | UNKNOWN!
2018-12-25T12:43:15.474846678Z 42 PC: 13e15 | Get date 0x13e15: xor al, al
0x13e17: cmp dl, 0xd
0x13e1a: jne 0x13e1e
0x13e1c: dec al
0x13e1e: mov byte ptr [0x70a], al
0x13e21: mov ax, 0x3508
0x13e24: int 0x21
0x13e26: mov word ptr [0x6fc], bx
0x13e2a: mov word ptr [0x6fe], es
0x13e2e: mov al, 9
0x13e30: int 0x21
0x13e32: mov word ptr [0x700], bx
0x13e36: mov word ptr [0x702], es
0x13e3a: mov al, 0x21
0x13e3c: int 0x21
0x13e3e: mov word ptr [0x704], bx
0x13e42: mov word ptr [0x706], es
0x13e46: mov dx, 0xd6
0x13e49: mov ax, 0x2508
0x13e4c: int 0x21
2018-12-25T12:43:15.477385149Z 53 PC: 13e26 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T12:43:15.478619984Z 53 PC: 13e32 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:43:15.479845569Z 53 PC: 13e3e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:43:15.481440319Z 37 PC: 13e4e | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T12:43:15.482601523Z 37 PC: 13e55 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:43:15.483779782Z 37 PC: 13e5c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:43:15.486239697Z 9 PC: 13dc6 | Display string (String= 'Hello - Copyright S & S International, 1990 ')