Sample viewer

vx.netlux.org/Virus.DOS.KeyPress.1479

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:07:20.187940758Z 42 PC: 12c75 | Get date 0x12c75: cmp cx, 0x7c9
0x12c79: jb 0x12c9e
0x12c7b: ja 0x12c82
0x12c7d: cmp dh, 6
0x12c80: jb 0x12c9e
0x12c82: mov bx, 0x70
0x12c85: mov byte ptr [0x310], 1
0x12c8a: nop
0x12c8b: mov dx, 0x311
0x12c8e: cli
0x12c8f: mov es, si
0x12c91: call 0x12d40
0x12c94: mov dx, 0x5ee
0x12c97: mov bx, 0x24
0x12c9a: call 0x12d40
0x12c9d: sti
0x12c9e: mov byte ptr [0x30f], 0
0x12ca3: nop
0x12ca4: mov dx, 0x410
0x12ca7: mov es, si
2018-12-17T23:07:20.190376957Z 48 PC: 12cae | Get DOS version
2018-12-17T23:07:20.193159728Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15828,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:44:39.87867526Z 42 PC: 12c75 | Get date 0x12c75: cmp cx, 0x7c9
0x12c79: jb 0x12c9e
0x12c7b: ja 0x12c82
0x12c7d: cmp dh, 6
0x12c80: jb 0x12c9e
0x12c82: mov bx, 0x70
0x12c85: mov byte ptr [0x310], 1
0x12c8a: nop
0x12c8b: mov dx, 0x311
0x12c8e: cli
0x12c8f: mov es, si
0x12c91: call 0x12d40
0x12c94: mov dx, 0x5ee
0x12c97: mov bx, 0x24
0x12c9a: call 0x12d40
0x12c9d: sti
0x12c9e: mov byte ptr [0x30f], 0
0x12ca3: nop
0x12ca4: mov dx, 0x410
0x12ca7: mov es, si
2018-12-25T12:44:39.88138819Z 48 PC: 12cae | Get DOS version
2018-12-25T12:44:39.882734171Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1993,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15828,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:44:40.228949791Z 42 PC: 12c75 | Get date 0x12c75: cmp cx, 0x7c9
0x12c79: jb 0x12c9e
0x12c7b: ja 0x12c82
0x12c7d: cmp dh, 6
0x12c80: jb 0x12c9e
0x12c82: mov bx, 0x70
0x12c85: mov byte ptr [0x310], 1
0x12c8a: nop
0x12c8b: mov dx, 0x311
0x12c8e: cli
0x12c8f: mov es, si
0x12c91: call 0x12d40
0x12c94: mov dx, 0x5ee
0x12c97: mov bx, 0x24
0x12c9a: call 0x12d40
0x12c9d: sti
0x12c9e: mov byte ptr [0x30f], 0
0x12ca3: nop
0x12ca4: mov dx, 0x410
0x12ca7: mov es, si
2018-12-25T12:44:40.231729779Z 48 PC: 12cae | Get DOS version
2018-12-25T12:44:40.233183689Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":1,"Month":6,"Year":1993,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15828,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:44:40.49976662Z 42 PC: 12c75 | Get date 0x12c75: cmp cx, 0x7c9
0x12c79: jb 0x12c9e
0x12c7b: ja 0x12c82
0x12c7d: cmp dh, 6
0x12c80: jb 0x12c9e
0x12c82: mov bx, 0x70
0x12c85: mov byte ptr [0x310], 1
0x12c8a: nop
0x12c8b: mov dx, 0x311
0x12c8e: cli
0x12c8f: mov es, si
0x12c91: call 0x12d40
0x12c94: mov dx, 0x5ee
0x12c97: mov bx, 0x24
0x12c9a: call 0x12d40
0x12c9d: sti
0x12c9e: mov byte ptr [0x30f], 0
0x12ca3: nop
0x12ca4: mov dx, 0x410
0x12ca7: mov es, si
2018-12-25T12:44:40.502411643Z 48 PC: 12cae | Get DOS version
2018-12-25T12:44:40.503789078Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1994,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15828,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:44:40.85710028Z 42 PC: 12c75 | Get date 0x12c75: cmp cx, 0x7c9
0x12c79: jb 0x12c9e
0x12c7b: ja 0x12c82
0x12c7d: cmp dh, 6
0x12c80: jb 0x12c9e
0x12c82: mov bx, 0x70
0x12c85: mov byte ptr [0x310], 1
0x12c8a: nop
0x12c8b: mov dx, 0x311
0x12c8e: cli
0x12c8f: mov es, si
0x12c91: call 0x12d40
0x12c94: mov dx, 0x5ee
0x12c97: mov bx, 0x24
0x12c9a: call 0x12d40
0x12c9d: sti
0x12c9e: mov byte ptr [0x30f], 0
0x12ca3: nop
0x12ca4: mov dx, 0x410
0x12ca7: mov es, si
2018-12-25T12:44:40.861992359Z 48 PC: 12cae | Get DOS version
2018-12-25T12:44:40.864433397Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')