Sample viewer

vx.netlux.org/Virus.DOS.Berserker.3561

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:12:56.155971858Z 69 PC: 13eb5 | Duplicate handle
2018-12-17T23:12:56.157909622Z 250 PC: 13ed7 | UNKNOWN!
2018-12-17T23:12:56.159804583Z 42 PC: 9de79 | Get date 0x9de79: cmp cx, 0x7c9
0x9de7d: jne 0x9dee6
0x9de7f: cmp dh, 9
0x9de82: jb 0x9dee6
0x9de84: cmp dh, 0xb
0x9de87: ja 0x9dee6
0x9de89: mov bx, 5
0x9de8c: call 0x9e4a9
0x9de8f: cmp al, 5
0x9de91: jne 0x9dec7
0x9de93: call 0x9dfa7
0x9de96: mov ah, 8
0x9de98: mov dl, 0x80
0x9de9a: int 0x13
0x9de9c: xor bx, bx
0x9de9e: mov bl, dl
0x9dea0: call 0x9e4a9
0x9dea3: mov dl, al
0x9dea5: add dl, 0x7f
0x9dea8: mov bx, 0x11
2018-12-17T23:12:56.164518466Z 9 PC: 9df10 | Display string (String= 'Its time for me to commit suicide! I'm taking you with me! Can you handle a Berserker Death frenzy? ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":17679,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:56:19.711899018Z 69 PC: 13eb5 | Duplicate handle
2018-12-25T12:56:19.719295866Z 250 PC: 13ed7 | UNKNOWN!
2018-12-25T12:56:19.720990032Z 42 PC: 9de79 | Get date 0x9de79: cmp cx, 0x7c9
0x9de7d: jne 0x9dee6
0x9de7f: cmp dh, 9
0x9de82: jb 0x9dee6
0x9de84: cmp dh, 0xb
0x9de87: ja 0x9dee6
0x9de89: mov bx, 5
0x9de8c: call 0x9e4a9
0x9de8f: cmp al, 5
0x9de91: jne 0x9dec7
0x9de93: call 0x9dfa7
0x9de96: mov ah, 8
0x9de98: mov dl, 0x80
0x9de9a: int 0x13
0x9de9c: xor bx, bx
0x9de9e: mov bl, dl
0x9dea0: call 0x9e4a9
0x9dea3: mov dl, al
0x9dea5: add dl, 0x7f
0x9dea8: mov bx, 0x11
2018-12-25T12:56:19.724654108Z 9 PC: 9df10 | Display string (String= 'Its time for me to commit suicide! I'm taking you with me! Can you handle a Berserker Death frenzy? ')

{"DateBased":true,"Day":1,"Month":1,"Year":1993,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":17679,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:56:19.759889244Z 69 PC: 13eb5 | Duplicate handle
2018-12-25T12:56:19.762279867Z 250 PC: 13ed7 | UNKNOWN!
2018-12-25T12:56:19.763771482Z 42 PC: 9de79 | Get date 0x9de79: cmp cx, 0x7c9
0x9de7d: jne 0x9dee6
0x9de7f: cmp dh, 9
0x9de82: jb 0x9dee6
0x9de84: cmp dh, 0xb
0x9de87: ja 0x9dee6
0x9de89: mov bx, 5
0x9de8c: call 0x9e4a9
0x9de8f: cmp al, 5
0x9de91: jne 0x9dec7
0x9de93: call 0x9dfa7
0x9de96: mov ah, 8
0x9de98: mov dl, 0x80
0x9de9a: int 0x13
0x9de9c: xor bx, bx
0x9de9e: mov bl, dl
0x9dea0: call 0x9e4a9
0x9dea3: mov dl, al
0x9dea5: add dl, 0x7f
0x9dea8: mov bx, 0x11
2018-12-25T12:56:19.767179088Z 9 PC: 9df10 | Display string (String= 'Its time for me to commit suicide! I'm taking you with me! Can you handle a Berserker Death frenzy? ')

{"DateBased":true,"Day":1,"Month":9,"Year":1993,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":17679,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:56:19.77218485Z 69 PC: 13eb5 | Duplicate handle
2018-12-25T12:56:19.774443865Z 250 PC: 13ed7 | UNKNOWN!
2018-12-25T12:56:19.775936765Z 42 PC: 9de79 | Get date 0x9de79: cmp cx, 0x7c9
0x9de7d: jne 0x9dee6
0x9de7f: cmp dh, 9
0x9de82: jb 0x9dee6
0x9de84: cmp dh, 0xb
0x9de87: ja 0x9dee6
0x9de89: mov bx, 5
0x9de8c: call 0x9e4a9
0x9de8f: cmp al, 5
0x9de91: jne 0x9dec7
0x9de93: call 0x9dfa7
0x9de96: mov ah, 8
0x9de98: mov dl, 0x80
0x9de9a: int 0x13
0x9de9c: xor bx, bx
0x9de9e: mov bl, dl
0x9dea0: call 0x9e4a9
0x9dea3: mov dl, al
0x9dea5: add dl, 0x7f
0x9dea8: mov bx, 0x11
2018-12-25T12:56:19.778472285Z 98 PC: 9df50 | Get current PSP
2018-12-25T12:56:19.780782521Z 9 PC: 12a85 | Display string (String= ' ')
2018-12-25T12:56:19.785995409Z 0 PC: 12a89 | Program terminate

{"DateBased":true,"Day":1,"Month":12,"Year":1993,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":17679,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:56:19.882253133Z 69 PC: 13eb5 | Duplicate handle
2018-12-25T12:56:19.886481503Z 250 PC: 13ed7 | UNKNOWN!
2018-12-25T12:56:19.888766535Z 42 PC: 9de79 | Get date 0x9de79: cmp cx, 0x7c9
0x9de7d: jne 0x9dee6
0x9de7f: cmp dh, 9
0x9de82: jb 0x9dee6
0x9de84: cmp dh, 0xb
0x9de87: ja 0x9dee6
0x9de89: mov bx, 5
0x9de8c: call 0x9e4a9
0x9de8f: cmp al, 5
0x9de91: jne 0x9dec7
0x9de93: call 0x9dfa7
0x9de96: mov ah, 8
0x9de98: mov dl, 0x80
0x9de9a: int 0x13
0x9de9c: xor bx, bx
0x9de9e: mov bl, dl
0x9dea0: call 0x9e4a9
0x9dea3: mov dl, al
0x9dea5: add dl, 0x7f
0x9dea8: mov bx, 0x11
2018-12-25T12:56:19.89328803Z 9 PC: 9df10 | Display string (String= 'Its time for me to commit suicide! I'm taking you with me! Can you handle a Berserker Death frenzy? ')