Sample viewer

vx.netlux.org/Virus.DOS.Kthulhu.512

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:07:05.479115648Z 26 PC: 12a71 | Set disk transfer address
2018-12-17T23:07:05.480342634Z 78 PC: 12a7b | Find first file
2018-12-17T23:07:05.487376754Z 78 PC: 12a84 | Find first file
2018-12-17T23:07:05.494639422Z 26 PC: 12a8d | Set disk transfer address
2018-12-17T23:07:05.496159809Z 79 PC: 12a97 | Find next file
2018-12-17T23:07:05.499727257Z 26 PC: 12a8d | Set disk transfer address
2018-12-17T23:07:05.501040253Z 79 PC: 12a97 | Find next file
2018-12-17T23:07:05.504215348Z 26 PC: 12a8d | Set disk transfer address
2018-12-17T23:07:05.506603789Z 79 PC: 12a97 | Find next file
2018-12-17T23:07:05.509489216Z 26 PC: 12a8d | Set disk transfer address
2018-12-17T23:07:05.510716533Z 79 PC: 12a97 | Find next file
2018-12-17T23:07:05.53095836Z 26 PC: 12a8d | Set disk transfer address
2018-12-17T23:07:05.532384807Z 79 PC: 12a97 | Find next file
2018-12-17T23:07:05.535496856Z 26 PC: 12a8d | Set disk transfer address
2018-12-17T23:07:05.537443317Z 79 PC: 12a97 | Find next file
2018-12-17T23:07:05.540803868Z 26 PC: 12a8d | Set disk transfer address
2018-12-17T23:07:05.542063644Z 79 PC: 12a97 | Find next file
2018-12-17T23:07:05.54515914Z 67 PC: 12ab1 | Get or set file attributes
2018-12-17T23:07:05.552335964Z 67 PC: 12abc | Get or set file attributes
2018-12-17T23:07:05.569498267Z 86 PC: 12acd | Rename file
2018-12-17T23:07:05.581999467Z 61 PC: 12ad5 | Open file (Filename = 'KTHULHU')
2018-12-17T23:07:05.590627619Z 87 PC: 12adf | Get or set file date and time
2018-12-17T23:07:05.592306951Z 66 PC: 12aed | Move file pointer
2018-12-17T23:07:05.593880215Z 63 PC: 12af6 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T23:07:05.601785892Z 87 PC: 12b3d | Get or set file date and time
2018-12-17T23:07:05.603495361Z 62 PC: 12b43 | Close file
2018-12-17T23:07:05.610910345Z 86 PC: 12b58 | Rename file
2018-12-17T23:07:05.627759657Z 67 PC: 12b64 | Get or set file attributes
2018-12-17T23:07:05.6425261Z 26 PC: 12a8d | Set disk transfer address
2018-12-17T23:07:05.645186319Z 79 PC: 12a97 | Find next file
2018-12-17T23:07:05.648650234Z 42 PC: 12b79 | Get date 0x12b79: mov ah, 5
0x12b7b: cmp dh, ah
0x12b7d: jne 0x12baf
0x12b7f: mov al, 0
0x12b81: add al, dl
0x12b83: cmp al, 0x14
0x12b85: mov ah, 9
0x12b87: je 0x12b8d
0x12b89: ja 0x12ba5
0x12b8b: jb 0x12b98
0x12b8d: mov dx, 0x288
0x12b90: int 0x21
0x12b92: mov ah, 7
0x12b94: int 0x21
0x12b96: int 0x19
0x12b98: mov dx, 0x2a1
0x12b9b: int 0x21
0x12b9d: mov dx, 0x2a5
0x12ba0: int 0x21
0x12ba2: jmp 0x12baf
2018-12-17T23:07:05.652403408Z 9 PC: 12e26 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":10,"Month":5,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15746,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:44:23.566186318Z 26 PC: 12a71 | Set disk transfer address
2018-12-25T12:44:23.567794454Z 78 PC: 12a7b | Find first file
2018-12-25T12:44:23.574471477Z 78 PC: 12a84 | Find first file
2018-12-25T12:44:23.581183444Z 26 PC: 12a8d | Set disk transfer address
2018-12-25T12:44:23.583371153Z 79 PC: 12a97 | Find next file
2018-12-25T12:44:23.586948876Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.587911679Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.590427105Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.592510498Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.596302984Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.597512057Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.60160769Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.603951176Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.608345358Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.612112909Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.61499889Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.616246752Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.620021688Z 67 PC: 12ab1 | Get or set file attributes
2018-12-25T12:44:23.627316322Z 67 PC: 12abc | Get or set file attributes
2018-12-25T12:44:23.64689308Z 86 PC: 12acd | Rename file
2018-12-25T12:44:23.660608497Z 61 PC: 12ad5 | Open file (Filename = 'KTHULHU')
2018-12-25T12:44:23.668288659Z 87 PC: 12adf | Get or set file date and time
2018-12-25T12:44:23.671121206Z 66 PC: 12aed | Move file pointer
2018-12-25T12:44:23.673940838Z 63 PC: 12af6 | Read file or device (Read 512 bytes on handle 5)
2018-12-25T12:44:23.6824862Z 87 PC: 12b3d | Get or set file date and time
2018-12-25T12:44:23.685879577Z 62 PC: 12b43 | Close file
2018-12-25T12:44:23.692201532Z 86 PC: 12b58 | Rename file
2018-12-25T12:44:23.712589736Z 67 PC: 12b64 | Get or set file attributes
2018-12-25T12:44:23.724173302Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.725820543Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.729341833Z 42 PC: 12b79 | Get date 0x12b79: mov ah, 5
0x12b7b: cmp dh, ah
0x12b7d: jne 0x12baf
0x12b7f: mov al, 0
0x12b81: add al, dl
0x12b83: cmp al, 0x14
0x12b85: mov ah, 9
0x12b87: je 0x12b8d
0x12b89: ja 0x12ba5
0x12b8b: jb 0x12b98
0x12b8d: mov dx, 0x288
0x12b90: int 0x21
0x12b92: mov ah, 7
0x12b94: int 0x21
0x12b96: int 0x19
0x12b98: mov dx, 0x2a1
0x12b9b: int 0x21
0x12b9d: mov dx, 0x2a5
0x12ba0: int 0x21
0x12ba2: jmp 0x12baf
2018-12-25T12:44:23.731884525Z 9 PC: 12b9d | Display string (String= 'IT ')
2018-12-25T12:44:23.734336905Z 9 PC: 12ba2 | Display string (String= 'is coming. ')
2018-12-25T12:44:23.739709478Z 9 PC: 12e26 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15746,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:44:23.687680272Z 26 PC: 12a71 | Set disk transfer address
2018-12-25T12:44:23.689311253Z 78 PC: 12a7b | Find first file
2018-12-25T12:44:23.6953768Z 78 PC: 12a84 | Find first file
2018-12-25T12:44:23.705714965Z 26 PC: 12a8d | Set disk transfer address
2018-12-25T12:44:23.707993093Z 79 PC: 12a97 | Find next file
2018-12-25T12:44:23.710392944Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.711334932Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.714520899Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.715599299Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.717909563Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.719062712Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.721775178Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.722913129Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.72534754Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.726890839Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.729148226Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.73005963Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.733083186Z 67 PC: 12ab1 | Get or set file attributes
2018-12-25T12:44:23.73919025Z 67 PC: 12abc | Get or set file attributes
2018-12-25T12:44:23.755618071Z 86 PC: 12acd | Rename file
2018-12-25T12:44:23.765722274Z 61 PC: 12ad5 | Open file (Filename = 'KTHULHU')
2018-12-25T12:44:23.784695344Z 87 PC: 12adf | Get or set file date and time
2018-12-25T12:44:23.78609505Z 66 PC: 12aed | Move file pointer
2018-12-25T12:44:23.788162866Z 63 PC: 12af6 | Read file or device (Read 512 bytes on handle 5)
2018-12-25T12:44:23.795257597Z 87 PC: 12b3d | Get or set file date and time
2018-12-25T12:44:23.796626568Z 62 PC: 12b43 | Close file
2018-12-25T12:44:23.809158014Z 86 PC: 12b58 | Rename file
2018-12-25T12:44:23.820603279Z 67 PC: 12b64 | Get or set file attributes
2018-12-25T12:44:23.829034535Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.830162157Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.832014208Z 42 PC: 12b79 | Get date 0x12b79: mov ah, 5
0x12b7b: cmp dh, ah
0x12b7d: jne 0x12baf
0x12b7f: mov al, 0
0x12b81: add al, dl
0x12b83: cmp al, 0x14
0x12b85: mov ah, 9
0x12b87: je 0x12b8d
0x12b89: ja 0x12ba5
0x12b8b: jb 0x12b98
0x12b8d: mov dx, 0x288
0x12b90: int 0x21
0x12b92: mov ah, 7
0x12b94: int 0x21
0x12b96: int 0x19
0x12b98: mov dx, 0x2a1
0x12b9b: int 0x21
0x12b9d: mov dx, 0x2a5
0x12ba0: int 0x21
0x12ba2: jmp 0x12baf
2018-12-25T12:44:23.833573448Z 9 PC: 12e26 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":1,"Month":5,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15746,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:44:23.746495754Z 26 PC: 12a71 | Set disk transfer address
2018-12-25T12:44:23.748866823Z 78 PC: 12a7b | Find first file
2018-12-25T12:44:23.756698173Z 78 PC: 12a84 | Find first file
2018-12-25T12:44:23.763830766Z 26 PC: 12a8d | Set disk transfer address
2018-12-25T12:44:23.765147009Z 79 PC: 12a97 | Find next file
2018-12-25T12:44:23.768685137Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.769889365Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.772726852Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.774853305Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.778197092Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.779465226Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.783275054Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.784524025Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.787699124Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.790017914Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.793247405Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.794982658Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.80254898Z 67 PC: 12ab1 | Get or set file attributes
2018-12-25T12:44:23.80979746Z 67 PC: 12abc | Get or set file attributes
2018-12-25T12:44:23.827428614Z 86 PC: 12acd | Rename file
2018-12-25T12:44:23.839972553Z 61 PC: 12ad5 | Open file (Filename = 'KTHULHU')
2018-12-25T12:44:23.847868569Z 87 PC: 12adf | Get or set file date and time
2018-12-25T12:44:23.849452449Z 66 PC: 12aed | Move file pointer
2018-12-25T12:44:23.851248712Z 63 PC: 12af6 | Read file or device (Read 512 bytes on handle 5)
2018-12-25T12:44:23.859386185Z 87 PC: 12b3d | Get or set file date and time
2018-12-25T12:44:23.861483984Z 62 PC: 12b43 | Close file
2018-12-25T12:44:23.869817909Z 86 PC: 12b58 | Rename file
2018-12-25T12:44:23.886464491Z 67 PC: 12b64 | Get or set file attributes
2018-12-25T12:44:23.8975263Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.898762724Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:23.902587648Z 42 PC: 12b79 | Get date 0x12b79: mov ah, 5
0x12b7b: cmp dh, ah
0x12b7d: jne 0x12baf
0x12b7f: mov al, 0
0x12b81: add al, dl
0x12b83: cmp al, 0x14
0x12b85: mov ah, 9
0x12b87: je 0x12b8d
0x12b89: ja 0x12ba5
0x12b8b: jb 0x12b98
0x12b8d: mov dx, 0x288
0x12b90: int 0x21
0x12b92: mov ah, 7
0x12b94: int 0x21
0x12b96: int 0x19
0x12b98: mov dx, 0x2a1
0x12b9b: int 0x21
0x12b9d: mov dx, 0x2a5
0x12ba0: int 0x21
0x12ba2: jmp 0x12baf
2018-12-25T12:44:23.905886354Z 9 PC: 12b9d | Display string (String= 'IT ')
2018-12-25T12:44:23.908761858Z 9 PC: 12ba2 | Display string (String= 'is coming. ')
2018-12-25T12:44:23.914321388Z 9 PC: 12e26 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":9,"Month":5,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15746,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:44:23.977468037Z 26 PC: 12a71 | Set disk transfer address
2018-12-25T12:44:23.978863184Z 78 PC: 12a7b | Find first file
2018-12-25T12:44:23.985155408Z 78 PC: 12a84 | Find first file
2018-12-25T12:44:23.99113761Z 26 PC: 12a8d | Set disk transfer address
2018-12-25T12:44:23.992555495Z 79 PC: 12a97 | Find next file
2018-12-25T12:44:23.996453277Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:23.997866839Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:24.001878564Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:24.004201295Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:24.00686401Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:24.00797256Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:24.0115588Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:24.012673726Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:24.015176316Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:24.016643272Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:24.020016422Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:24.021039982Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:24.023635064Z 67 PC: 12ab1 | Get or set file attributes
2018-12-25T12:44:24.030264929Z 67 PC: 12abc | Get or set file attributes
2018-12-25T12:44:24.045666299Z 86 PC: 12acd | Rename file
2018-12-25T12:44:24.056932667Z 61 PC: 12ad5 | Open file (Filename = 'KTHULHU')
2018-12-25T12:44:24.066041256Z 87 PC: 12adf | Get or set file date and time
2018-12-25T12:44:24.067493017Z 66 PC: 12aed | Move file pointer
2018-12-25T12:44:24.068888502Z 63 PC: 12af6 | Read file or device (Read 512 bytes on handle 5)
2018-12-25T12:44:24.07635163Z 87 PC: 12b3d | Get or set file date and time
2018-12-25T12:44:24.077909835Z 62 PC: 12b43 | Close file
2018-12-25T12:44:24.086055484Z 86 PC: 12b58 | Rename file
2018-12-25T12:44:24.103597746Z 67 PC: 12b64 | Get or set file attributes
2018-12-25T12:44:24.113747836Z 26 PC: 12a8d | Set disk transfer address (See above)
2018-12-25T12:44:24.114805164Z 79 PC: 12a97 | Find next file (See above)
2018-12-25T12:44:24.117889994Z 42 PC: 12b79 | Get date 0x12b79: mov ah, 5
0x12b7b: cmp dh, ah
0x12b7d: jne 0x12baf
0x12b7f: mov al, 0
0x12b81: add al, dl
0x12b83: cmp al, 0x14
0x12b85: mov ah, 9
0x12b87: je 0x12b8d
0x12b89: ja 0x12ba5
0x12b8b: jb 0x12b98
0x12b8d: mov dx, 0x288
0x12b90: int 0x21
0x12b92: mov ah, 7
0x12b94: int 0x21
0x12b96: int 0x19
0x12b98: mov dx, 0x2a1
0x12b9b: int 0x21
0x12b9d: mov dx, 0x2a5
0x12ba0: int 0x21
0x12ba2: jmp 0x12baf
2018-12-25T12:44:24.120302045Z 9 PC: 12b9d | Display string (String= 'IT ')
2018-12-25T12:44:24.122726035Z 9 PC: 12ba2 | Display string (String= 'is coming. ')
2018-12-25T12:44:24.127943173Z 9 PC: 12e26 | Display string (String= 'Hello - Copyright S & S International, 1990 ')