Sample viewer

vx.netlux.org/Virus.DOS.Miss-D.1360

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:07:27.701011707Z 239 PC: 12e27 | UNKNOWN!
2018-12-17T23:07:27.710396499Z 42 PC: 12e30 | Get date 0x12e30: cmp dh, 0xc
0x12e33: jne 0x12e5c
0x12e35: cmp dl, 0xa
0x12e38: ja 0x12e5c
0x12e3a: mov ax, 0x3509
0x12e3d: int 0x21
0x12e3f: mov word ptr cs:[0x51d], bx
0x12e44: mov word ptr cs:[0x51f], es
0x12e49: cmp bx, 0x485
0x12e4d: je 0x12e59
0x12e4f: mov dx, 0x485
0x12e52: push cs
0x12e53: pop ds
0x12e54: mov ax, 0x2509
0x12e57: int 0x21
0x12e59: jmp 0x12e5c
0x12e5b: nop
0x12e5c: ret
0x12e5d: add byte ptr [bx + si], al
0x12e5f: add byte ptr [bx + si], al
2018-12-17T23:07:27.713120404Z 53 PC: 12c82 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:27.715051449Z 239 PC: 12c91 | UNKNOWN!
2018-12-17T23:07:27.716511795Z 37 PC: 12ca6 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:27.719324495Z 38 PC: 12cc2 | Create PSP
2018-12-17T23:07:27.721049308Z 74 PC: 12cd2 | Reallocate memory
2018-12-17T23:07:27.723009866Z 72 PC: 12cd9 | Allocate memory
2018-12-17T23:07:27.732203557Z 72 PC: 12cdd | Allocate memory
2018-12-17T23:07:27.73484232Z 53 PC: 12cf1 | Get interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-17T23:07:27.736110768Z 37 PC: 12d05 | Set interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-17T23:07:27.73797812Z 53 PC: 12d0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:27.739275279Z 37 PC: 12d1e | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:27.740705956Z 9 PC: 12ff2 | Display string (String= 'ABCDE - This is a 100 byte COM test, 1994 ')
2018-12-17T23:07:27.746557353Z 73 PC: 12d68 | Release memory
2018-12-17T23:07:27.748087492Z 37 PC: 12d78 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:27.749371188Z 37 PC: 12d88 | Set interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-17T23:07:27.75163337Z 37 PC: 12d98 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:27.752989987Z 239 PC: 12d9d | UNKNOWN!
2018-12-17T23:07:27.753980333Z 37 PC: 12dac | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:27.755351503Z 49 PC: 12db1 | Terminate and stay resident (Return code = '0' | Memory size = '85')

{"DateBased":true,"Day":1,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15864,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:44:44.979980113Z 239 PC: 12e27 | UNKNOWN!
2018-12-25T12:44:44.983080311Z 42 PC: 12e30 | Get date 0x12e30: cmp dh, 0xc
0x12e33: jne 0x12e5c
0x12e35: cmp dl, 0xa
0x12e38: ja 0x12e5c
0x12e3a: mov ax, 0x3509
0x12e3d: int 0x21
0x12e3f: mov word ptr cs:[0x51d], bx
0x12e44: mov word ptr cs:[0x51f], es
0x12e49: cmp bx, 0x485
0x12e4d: je 0x12e59
0x12e4f: mov dx, 0x485
0x12e52: push cs
0x12e53: pop ds
0x12e54: mov ax, 0x2509
0x12e57: int 0x21
0x12e59: jmp 0x12e5c
0x12e5b: nop
0x12e5c: ret
0x12e5d: add byte ptr [bx + si], al
0x12e5f: add byte ptr [bx + si], al
2018-12-25T12:44:44.985077095Z 53 PC: 12e3f | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:44:44.986118446Z 37 PC: 12e59 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:44:44.987370418Z 53 PC: 12c82 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:44.988747474Z 239 PC: 12c91 | UNKNOWN!
2018-12-25T12:44:44.989742199Z 37 PC: 12ca6 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:44.990849438Z 38 PC: 12cc2 | Create PSP
2018-12-25T12:44:44.992988446Z 74 PC: 12cd2 | Reallocate memory
2018-12-25T12:44:44.994399211Z 72 PC: 12cd9 | Allocate memory
2018-12-25T12:44:44.996143281Z 72 PC: 12cdd | Allocate memory
2018-12-25T12:44:44.998310002Z 53 PC: 12cf1 | Get interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:44:44.999840417Z 37 PC: 12d05 | Set interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:44:45.002427853Z 53 PC: 12d0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:45.004208333Z 37 PC: 12d1e | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:45.005445624Z 9 PC: 12ff2 | Display string (String= 'ABCDE - This is a 100 byte COM test, 1994 ')
2018-12-25T12:44:45.016313287Z 73 PC: 12d68 | Release memory
2018-12-25T12:44:45.020355812Z 37 PC: 12d78 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:45.032098788Z 37 PC: 12d88 | Set interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:44:45.033293388Z 37 PC: 12d98 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:45.035258317Z 239 PC: 12d9d | UNKNOWN!
2018-12-25T12:44:45.036366536Z 37 PC: 12dac | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:45.037715191Z 49 PC: 12db1 | Terminate and stay resident (Return code = '0' | Memory size = '85')

{"DateBased":true,"Day":11,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15864,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:44:45.00530751Z 239 PC: 12e27 | UNKNOWN!
2018-12-25T12:44:45.00653896Z 42 PC: 12e30 | Get date 0x12e30: cmp dh, 0xc
0x12e33: jne 0x12e5c
0x12e35: cmp dl, 0xa
0x12e38: ja 0x12e5c
0x12e3a: mov ax, 0x3509
0x12e3d: int 0x21
0x12e3f: mov word ptr cs:[0x51d], bx
0x12e44: mov word ptr cs:[0x51f], es
0x12e49: cmp bx, 0x485
0x12e4d: je 0x12e59
0x12e4f: mov dx, 0x485
0x12e52: push cs
0x12e53: pop ds
0x12e54: mov ax, 0x2509
0x12e57: int 0x21
0x12e59: jmp 0x12e5c
0x12e5b: nop
0x12e5c: ret
0x12e5d: add byte ptr [bx + si], al
0x12e5f: add byte ptr [bx + si], al
2018-12-25T12:44:45.008997012Z 53 PC: 12c82 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:45.010125158Z 239 PC: 12c91 | UNKNOWN!
2018-12-25T12:44:45.011264182Z 37 PC: 12ca6 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:45.012467407Z 38 PC: 12cc2 | Create PSP
2018-12-25T12:44:45.014713911Z 74 PC: 12cd2 | Reallocate memory
2018-12-25T12:44:45.0164554Z 72 PC: 12cd9 | Allocate memory
2018-12-25T12:44:45.019962433Z 72 PC: 12cdd | Allocate memory
2018-12-25T12:44:45.021365035Z 53 PC: 12cf1 | Get interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:44:45.022381202Z 37 PC: 12d05 | Set interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:44:45.023778989Z 53 PC: 12d0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:45.024840379Z 37 PC: 12d1e | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:45.02603549Z 9 PC: 12ff2 | Display string (String= 'ABCDE - This is a 100 byte COM test, 1994 ')
2018-12-25T12:44:45.033691442Z 73 PC: 12d68 | Release memory
2018-12-25T12:44:45.035459031Z 37 PC: 12d78 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:45.036610059Z 37 PC: 12d88 | Set interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:44:45.038481462Z 37 PC: 12d98 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:45.03957881Z 239 PC: 12d9d | UNKNOWN!
2018-12-25T12:44:45.040321428Z 37 PC: 12dac | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:45.04198875Z 49 PC: 12db1 | Terminate and stay resident (Return code = '0' | Memory size = '85')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":15864,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:44:45.091653518Z 239 PC: 12e27 | UNKNOWN!
2018-12-25T12:44:45.09283086Z 42 PC: 12e30 | Get date 0x12e30: cmp dh, 0xc
0x12e33: jne 0x12e5c
0x12e35: cmp dl, 0xa
0x12e38: ja 0x12e5c
0x12e3a: mov ax, 0x3509
0x12e3d: int 0x21
0x12e3f: mov word ptr cs:[0x51d], bx
0x12e44: mov word ptr cs:[0x51f], es
0x12e49: cmp bx, 0x485
0x12e4d: je 0x12e59
0x12e4f: mov dx, 0x485
0x12e52: push cs
0x12e53: pop ds
0x12e54: mov ax, 0x2509
0x12e57: int 0x21
0x12e59: jmp 0x12e5c
0x12e5b: nop
0x12e5c: ret
0x12e5d: add byte ptr [bx + si], al
0x12e5f: add byte ptr [bx + si], al
2018-12-25T12:44:45.106002998Z 53 PC: 12c82 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:45.10932077Z 239 PC: 12c91 | UNKNOWN!
2018-12-25T12:44:45.111050977Z 37 PC: 12ca6 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:45.112413406Z 38 PC: 12cc2 | Create PSP
2018-12-25T12:44:45.114543439Z 74 PC: 12cd2 | Reallocate memory
2018-12-25T12:44:45.117157499Z 72 PC: 12cd9 | Allocate memory
2018-12-25T12:44:45.119097828Z 72 PC: 12cdd | Allocate memory
2018-12-25T12:44:45.120707154Z 53 PC: 12cf1 | Get interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:44:45.121868479Z 37 PC: 12d05 | Set interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:44:45.123840926Z 53 PC: 12d0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:45.125203154Z 37 PC: 12d1e | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:45.126570482Z 9 PC: 12ff2 | Display string (String= 'ABCDE - This is a 100 byte COM test, 1994 ')
2018-12-25T12:44:45.133834587Z 73 PC: 12d68 | Release memory
2018-12-25T12:44:45.135800386Z 37 PC: 12d78 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:45.137488347Z 37 PC: 12d88 | Set interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:44:45.14182783Z 37 PC: 12d98 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:45.144049066Z 239 PC: 12d9d | UNKNOWN!
2018-12-25T12:44:45.145261266Z 37 PC: 12dac | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:44:45.146938165Z 49 PC: 12db1 | Terminate and stay resident (Return code = '0' | Memory size = '85')