Sample viewer

vx.netlux.org/Virus.DOS.Vienna.Feliz.923

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:08:35.814644005Z 37 PC: 17d1f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:08:35.816103275Z 42 PC: 17d23 | Get date 0x17d23: cmp dx, 0x104
0x17d27: je 0x17d32
0x17d29: cmp dx, 0x60a
0x17d2d: je 0x17d32
0x17d2f: jmp 0x17d40
0x17d31: nop
0x17d32: push di
0x17d33: mov dx, di
0x17d35: add dx, 0x61
0x17d38: mov ah, 9
0x17d3a: int 0x21
0x17d3c: call 0x17e99
0x17d3f: pop di
0x17d40: mov dx, 0x2c
0x17d43: add dx, di
0x17d45: mov bx, dx
0x17d47: mov ah, 0x1a
0x17d49: int 0x21
0x17d4b: mov bp, 0
0x17d4e: mov dx, di
2018-12-17T22:08:35.818202742Z 26 PC: 17d4b | Set disk transfer address
2018-12-17T22:08:35.819098591Z 78 PC: 17d5a | Find first file
2018-12-17T22:08:35.825454718Z 67 PC: 17db2 | Get or set file attributes
2018-12-17T22:08:35.830880223Z 67 PC: 17dc2 | Get or set file attributes
2018-12-17T22:08:35.846361117Z 61 PC: 17dd1 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:08:35.857488374Z 87 PC: 17ddd | Get or set file date and time
2018-12-17T22:08:35.858786917Z 63 PC: 17dec | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:08:35.864806081Z 66 PC: 17dff | Move file pointer
2018-12-17T22:08:35.867255592Z 64 PC: 17e3b | Write file or device (Write 923 bytes on handle 5)
2018-12-17T22:08:35.875791592Z 66 PC: 17e4f | Move file pointer
2018-12-17T22:08:35.877223548Z 64 PC: 17e5d | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:08:35.884988878Z 87 PC: 17e7a | Get or set file date and time
2018-12-17T22:08:35.886662367Z 62 PC: 17e7e | Close file
2018-12-17T22:08:35.894586927Z 67 PC: 17e8c | Get or set file attributes
2018-12-17T22:08:35.901321943Z 26 PC: 17e93 | Set disk transfer address
2018-12-17T22:08:35.907860533Z 48 PC: 18097 | Get DOS version
2018-12-17T22:08:35.90928207Z 37 PC: 182f6 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:08:35.912759956Z 37 PC: 1832a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:08:35.914315658Z 37 PC: 182c4 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2084,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:44:55.546357711Z 37 PC: 17d1f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:44:55.548030875Z 42 PC: 17d23 | Get date 0x17d23: cmp dx, 0x104
0x17d27: je 0x17d32
0x17d29: cmp dx, 0x60a
0x17d2d: je 0x17d32
0x17d2f: jmp 0x17d40
0x17d31: nop
0x17d32: push di
0x17d33: mov dx, di
0x17d35: add dx, 0x61
0x17d38: mov ah, 9
0x17d3a: int 0x21
0x17d3c: call 0x17e99
0x17d3f: pop di
0x17d40: mov dx, 0x2c
0x17d43: add dx, di
0x17d45: mov bx, dx
0x17d47: mov ah, 0x1a
0x17d49: int 0x21
0x17d4b: mov bp, 0
0x17d4e: mov dx, di
2018-12-25T11:44:55.550020737Z 26 PC: 17d4b | Set disk transfer address
2018-12-25T11:44:55.550921775Z 78 PC: 17d5a | Find first file
2018-12-25T11:44:55.557444195Z 67 PC: 17db2 | Get or set file attributes
2018-12-25T11:44:55.562813767Z 67 PC: 17dc2 | Get or set file attributes
2018-12-25T11:44:55.57893091Z 61 PC: 17dd1 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:44:55.586430384Z 87 PC: 17ddd | Get or set file date and time
2018-12-25T11:44:55.587977725Z 63 PC: 17dec | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:44:55.59455922Z 66 PC: 17dff | Move file pointer
2018-12-25T11:44:55.597069816Z 64 PC: 17e3b | Write file or device (Write 923 bytes on handle 5)
2018-12-25T11:44:55.606607971Z 66 PC: 17e4f | Move file pointer
2018-12-25T11:44:55.608332903Z 64 PC: 17e5d | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:44:55.617196701Z 87 PC: 17e7a | Get or set file date and time
2018-12-25T11:44:55.620209391Z 62 PC: 17e7e | Close file
2018-12-25T11:44:55.628318929Z 67 PC: 17e8c | Get or set file attributes
2018-12-25T11:44:55.632983703Z 26 PC: 17e93 | Set disk transfer address
2018-12-25T11:44:55.640567074Z 48 PC: 18097 | Get DOS version
2018-12-25T11:44:55.641861239Z 37 PC: 182f6 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-25T11:44:55.642931235Z 37 PC: 1832a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:44:55.645146036Z 37 PC: 182c4 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')

{"DateBased":true,"Day":4,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2084,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:44:55.673595526Z 37 PC: 17d1f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:44:55.675554955Z 42 PC: 17d23 | Get date 0x17d23: cmp dx, 0x104
0x17d27: je 0x17d32
0x17d29: cmp dx, 0x60a
0x17d2d: je 0x17d32
0x17d2f: jmp 0x17d40
0x17d31: nop
0x17d32: push di
0x17d33: mov dx, di
0x17d35: add dx, 0x61
0x17d38: mov ah, 9
0x17d3a: int 0x21
0x17d3c: call 0x17e99
0x17d3f: pop di
0x17d40: mov dx, 0x2c
0x17d43: add dx, di
0x17d45: mov bx, dx
0x17d47: mov ah, 0x1a
0x17d49: int 0x21
0x17d4b: mov bp, 0
0x17d4e: mov dx, di
2018-12-25T11:44:55.677645624Z 9 PC: 17d3c | Display string (String= ' Si amas algo d�jalo libre. Si regresa es tuyo si no, nunca lo fu�. Feliz Cumplea�os. ')
2018-12-25T11:44:55.898021106Z 26 PC: 17d4b | Set disk transfer address
2018-12-25T11:44:55.899500278Z 78 PC: 17d5a | Find first file
2018-12-25T11:44:55.905226786Z 67 PC: 17db2 | Get or set file attributes
2018-12-25T11:44:55.910515598Z 67 PC: 17dc2 | Get or set file attributes
2018-12-25T11:44:55.926889828Z 61 PC: 17dd1 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:44:55.933054269Z 87 PC: 17ddd | Get or set file date and time
2018-12-25T11:44:55.934110595Z 63 PC: 17dec | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:44:55.940577338Z 66 PC: 17dff | Move file pointer
2018-12-25T11:44:55.94241152Z 64 PC: 17e3b | Write file or device (Write 923 bytes on handle 5)
2018-12-25T11:44:55.951134313Z 66 PC: 17e4f | Move file pointer
2018-12-25T11:44:55.953167692Z 64 PC: 17e5d | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:44:55.959589754Z 87 PC: 17e7a | Get or set file date and time
2018-12-25T11:44:55.961227607Z 62 PC: 17e7e | Close file
2018-12-25T11:44:55.969360043Z 67 PC: 17e8c | Get or set file attributes
2018-12-25T11:44:55.972021951Z 26 PC: 17e93 | Set disk transfer address
2018-12-25T11:44:55.975499513Z 48 PC: 18097 | Get DOS version
2018-12-25T11:44:55.976492495Z 37 PC: 182f6 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-25T11:44:55.977491691Z 37 PC: 1832a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:44:55.978223527Z 37 PC: 182c4 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')

{"DateBased":true,"Day":10,"Month":6,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2084,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:44:55.955858185Z 37 PC: 17d1f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:44:55.957938092Z 42 PC: 17d23 | Get date 0x17d23: cmp dx, 0x104
0x17d27: je 0x17d32
0x17d29: cmp dx, 0x60a
0x17d2d: je 0x17d32
0x17d2f: jmp 0x17d40
0x17d31: nop
0x17d32: push di
0x17d33: mov dx, di
0x17d35: add dx, 0x61
0x17d38: mov ah, 9
0x17d3a: int 0x21
0x17d3c: call 0x17e99
0x17d3f: pop di
0x17d40: mov dx, 0x2c
0x17d43: add dx, di
0x17d45: mov bx, dx
0x17d47: mov ah, 0x1a
0x17d49: int 0x21
0x17d4b: mov bp, 0
0x17d4e: mov dx, di
2018-12-25T11:44:55.960361306Z 9 PC: 17d3c | Display string (String= ' Si amas algo d�jalo libre. Si regresa es tuyo si no, nunca lo fu�. Feliz Cumplea�os. ')
2018-12-25T11:44:56.256102642Z 26 PC: 17d4b | Set disk transfer address
2018-12-25T11:44:56.258702125Z 78 PC: 17d5a | Find first file
2018-12-25T11:44:56.26581098Z 67 PC: 17db2 | Get or set file attributes
2018-12-25T11:44:56.273302303Z 67 PC: 17dc2 | Get or set file attributes
2018-12-25T11:44:56.292097793Z 61 PC: 17dd1 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:44:56.299720218Z 87 PC: 17ddd | Get or set file date and time
2018-12-25T11:44:56.302149818Z 63 PC: 17dec | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:44:56.310141052Z 66 PC: 17dff | Move file pointer
2018-12-25T11:44:56.312877855Z 64 PC: 17e3b | Write file or device (Write 923 bytes on handle 5)
2018-12-25T11:44:56.322650767Z 66 PC: 17e4f | Move file pointer
2018-12-25T11:44:56.324403345Z 64 PC: 17e5d | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:44:56.332206301Z 87 PC: 17e7a | Get or set file date and time
2018-12-25T11:44:56.333933996Z 62 PC: 17e7e | Close file
2018-12-25T11:44:56.342884125Z 67 PC: 17e8c | Get or set file attributes
2018-12-25T11:44:56.354544712Z 26 PC: 17e93 | Set disk transfer address
2018-12-25T11:44:56.362128347Z 48 PC: 18097 | Get DOS version
2018-12-25T11:44:56.36387464Z 37 PC: 182f6 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-25T11:44:56.366188598Z 37 PC: 1832a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:44:56.368055198Z 37 PC: 182c4 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')