Sample viewer

vx.netlux.org/Virus.DOS.Chris.463

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:05:24.341085793Z 44 PC: 12aed | Get time 0x12aed: cmp ch, 0xa
0x12af0: jne 0x12b0d
0x12af2: pop bx
0x12af3: add bx, 0x95
0x12af7: mov cx, 0x16
0x12afa: mov si, cx
0x12afc: mov dl, byte ptr [bx + si]
0x12afe: sub dl, 0x30
0x12b01: mov ah, 2
0x12b03: int 0x21
0x12b05: mov dl, 7
0x12b07: int 0x21
0x12b09: loop 0x12afa
0x12b0b: jmp 0x12b0b
0x12b0d: pop bx
0x12b0e: add bx, 0x1c9
0x12b12: mov ax, word ptr cs:[bx]
0x12b15: mov word ptr cs:[0x100], ax
0x12b19: mov al, byte ptr cs:[bx + 2]
0x12b1d: mov byte ptr cs:[0x102], al

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":1725,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:44:07.928636384Z 44 PC: 12aed | Get time 0x12aed: cmp ch, 0xa
0x12af0: jne 0x12b0d
0x12af2: pop bx
0x12af3: add bx, 0x95
0x12af7: mov cx, 0x16
0x12afa: mov si, cx
0x12afc: mov dl, byte ptr [bx + si]
0x12afe: sub dl, 0x30
0x12b01: mov ah, 2
0x12b03: int 0x21
0x12b05: mov dl, 7
0x12b07: int 0x21
0x12b09: loop 0x12afa
0x12b0b: jmp 0x12b0b
0x12b0d: pop bx
0x12b0e: add bx, 0x1c9
0x12b12: mov ax, word ptr cs:[bx]
0x12b15: mov word ptr cs:[0x100], ax
0x12b19: mov al, byte ptr cs:[bx + 2]
0x12b1d: mov byte ptr cs:[0x102], al

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":10,"Min":0,"Second":0,"TimeBased":true,"OriginalID":1725,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:44:08.019158406Z 44 PC: 12aed | Get time 0x12aed: cmp ch, 0xa
0x12af0: jne 0x12b0d
0x12af2: pop bx
0x12af3: add bx, 0x95
0x12af7: mov cx, 0x16
0x12afa: mov si, cx
0x12afc: mov dl, byte ptr [bx + si]
0x12afe: sub dl, 0x30
0x12b01: mov ah, 2
0x12b03: int 0x21
0x12b05: mov dl, 7
0x12b07: int 0x21
0x12b09: loop 0x12afa
0x12b0b: jmp 0x12b0b
0x12b0d: pop bx
0x12b0e: add bx, 0x1c9
0x12b12: mov ax, word ptr cs:[bx]
0x12b15: mov word ptr cs:[0x100], ax
0x12b19: mov al, byte ptr cs:[bx + 2]
0x12b1d: mov byte ptr cs:[0x102], al
2018-12-25T11:44:08.022289984Z 2 PC: 12b05 | Character output (Char = '0d')
2018-12-25T11:44:08.024281016Z 2 PC: 12b09 | Character output (Char = '07')
2018-12-25T11:44:08.026217053Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.030052391Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:08.033395546Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.036997702Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:08.038923518Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.043753949Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:08.045669567Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.049277613Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:08.052157639Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.054264304Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:08.056454166Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.059188801Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:08.061120537Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.063241392Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:08.068654533Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.07099816Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:08.073571006Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.076694997Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:08.07868904Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.080769598Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:08.084455141Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.08721073Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:08.089483124Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.092054832Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:08.094070958Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.096389078Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:08.099384396Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.103282663Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:08.105846715Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.109092288Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:08.111243926Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.113571046Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:08.115797055Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.118315261Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:08.120586477Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.123139097Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:08.126783578Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.128840589Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:08.131820255Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.134705673Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:08.136658648Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:08.138698614Z 2 PC: 12b09 | Character output (See above)

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":1725,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:44:08.297228549Z 44 PC: 12aed | Get time 0x12aed: cmp ch, 0xa
0x12af0: jne 0x12b0d
0x12af2: pop bx
0x12af3: add bx, 0x95
0x12af7: mov cx, 0x16
0x12afa: mov si, cx
0x12afc: mov dl, byte ptr [bx + si]
0x12afe: sub dl, 0x30
0x12b01: mov ah, 2
0x12b03: int 0x21
0x12b05: mov dl, 7
0x12b07: int 0x21
0x12b09: loop 0x12afa
0x12b0b: jmp 0x12b0b
0x12b0d: pop bx
0x12b0e: add bx, 0x1c9
0x12b12: mov ax, word ptr cs:[bx]
0x12b15: mov word ptr cs:[0x100], ax
0x12b19: mov al, byte ptr cs:[bx + 2]
0x12b1d: mov byte ptr cs:[0x102], al

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":10,"Min":0,"Second":0,"TimeBased":true,"OriginalID":1725,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:44:11.086172313Z 44 PC: 12aed | Get time 0x12aed: cmp ch, 0xa
0x12af0: jne 0x12b0d
0x12af2: pop bx
0x12af3: add bx, 0x95
0x12af7: mov cx, 0x16
0x12afa: mov si, cx
0x12afc: mov dl, byte ptr [bx + si]
0x12afe: sub dl, 0x30
0x12b01: mov ah, 2
0x12b03: int 0x21
0x12b05: mov dl, 7
0x12b07: int 0x21
0x12b09: loop 0x12afa
0x12b0b: jmp 0x12b0b
0x12b0d: pop bx
0x12b0e: add bx, 0x1c9
0x12b12: mov ax, word ptr cs:[bx]
0x12b15: mov word ptr cs:[0x100], ax
0x12b19: mov al, byte ptr cs:[bx + 2]
0x12b1d: mov byte ptr cs:[0x102], al
2018-12-25T11:44:11.088879414Z 2 PC: 12b05 | Character output (Char = '0d')
2018-12-25T11:44:11.091559705Z 2 PC: 12b09 | Character output (Char = '07')
2018-12-25T11:44:11.09410489Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.098573938Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:11.101336477Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.106771965Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:11.108999158Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.113575477Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:11.115671364Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.119671007Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:11.122200372Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.124370269Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:11.126304279Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.128887873Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:11.131270356Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.1334028Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:11.136485008Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.138929016Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:11.14098328Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.143138518Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:11.145332506Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.147741306Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:11.149784537Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.163593088Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:11.165745491Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.168075141Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:11.17050744Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.172700849Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:11.175083355Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.17793875Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:11.180615419Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.182105036Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:11.184151467Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.186628607Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:11.18984798Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.193091787Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:11.195160592Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.19773682Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:11.201607976Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.204659938Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:11.206770683Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.210651494Z 2 PC: 12b09 | Character output (See above)
2018-12-25T11:44:11.213550697Z 2 PC: 12b05 | Character output (See above)
2018-12-25T11:44:11.21700876Z 2 PC: 12b09 | Character output (See above)