Sample viewer

vx.netlux.org/Virus.DOS.Andromeda.713.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:10:12.454308777Z 42 PC: 12e51 | Get date 0x12e51: cmp dl, 5
0x12e54: jne 0x12e68
0x12e56: cmp dh, 0xa
0x12e59: jne 0x12e68
0x12e5b: mov al, 0
0x12e5d: mov cx, 0xd
0x12e60: mov dx, 1
0x12e63: mov bx, 0x100
0x12e66: int 0x26
0x12e68: mov si, 0x1234
0x12e6b: mov ah, 0x30
0x12e6d: int 0x21
0x12e6f: cmp di, -0x23
0x12e72: jne 0x12e8c
0x12e74: mov si, 0x3b7
0x12e77: pop bx
0x12e78: push bx
0x12e79: sub bx, 0x103
0x12e7d: add si, bx
0x12e7f: mov di, 0x100
2018-12-17T22:10:12.45758417Z 48 PC: 12e6f | Get DOS version
2018-12-17T22:10:12.458879903Z 38 PC: 12ea8 | Create PSP
2018-12-17T22:10:12.46032649Z 53 PC: 12edc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:10:12.461902892Z 37 PC: 12efc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:10:12.463684885Z 9 PC: 12e26 | Display string (String= 'BCDEF- This is a 1000 byte COM test, 1994 ')

{"DateBased":true,"Day":5,"Month":10,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2257,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:45:21.978535771Z 42 PC: 12e51 | Get date 0x12e51: cmp dl, 5
0x12e54: jne 0x12e68
0x12e56: cmp dh, 0xa
0x12e59: jne 0x12e68
0x12e5b: mov al, 0
0x12e5d: mov cx, 0xd
0x12e60: mov dx, 1
0x12e63: mov bx, 0x100
0x12e66: int 0x26
0x12e68: mov si, 0x1234
0x12e6b: mov ah, 0x30
0x12e6d: int 0x21
0x12e6f: cmp di, -0x23
0x12e72: jne 0x12e8c
0x12e74: mov si, 0x3b7
0x12e77: pop bx
0x12e78: push bx
0x12e79: sub bx, 0x103
0x12e7d: add si, bx
0x12e7f: mov di, 0x100
2018-12-25T11:45:21.990945669Z 48 PC: 12e6f | Get DOS version
2018-12-25T11:45:21.992187769Z 38 PC: 12ea8 | Create PSP
2018-12-25T11:45:21.993545439Z 53 PC: 12edc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:21.994937784Z 37 PC: 12efc | Set interrupt vector (Interrupt = '33' AKA 'Random read')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2257,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:45:22.651631718Z 42 PC: 12e51 | Get date 0x12e51: cmp dl, 5
0x12e54: jne 0x12e68
0x12e56: cmp dh, 0xa
0x12e59: jne 0x12e68
0x12e5b: mov al, 0
0x12e5d: mov cx, 0xd
0x12e60: mov dx, 1
0x12e63: mov bx, 0x100
0x12e66: int 0x26
0x12e68: mov si, 0x1234
0x12e6b: mov ah, 0x30
0x12e6d: int 0x21
0x12e6f: cmp di, -0x23
0x12e72: jne 0x12e8c
0x12e74: mov si, 0x3b7
0x12e77: pop bx
0x12e78: push bx
0x12e79: sub bx, 0x103
0x12e7d: add si, bx
0x12e7f: mov di, 0x100
2018-12-25T11:45:22.654414869Z 48 PC: 12e6f | Get DOS version
2018-12-25T11:45:22.655558675Z 38 PC: 12ea8 | Create PSP
2018-12-25T11:45:22.656757562Z 53 PC: 12edc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:22.65867933Z 37 PC: 12efc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:22.659769645Z 9 PC: 12e26 | Display string (String= 'BCDEF- This is a 1000 byte COM test, 1994 ')

{"DateBased":true,"Day":5,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2257,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:45:22.961239479Z 42 PC: 12e51 | Get date 0x12e51: cmp dl, 5
0x12e54: jne 0x12e68
0x12e56: cmp dh, 0xa
0x12e59: jne 0x12e68
0x12e5b: mov al, 0
0x12e5d: mov cx, 0xd
0x12e60: mov dx, 1
0x12e63: mov bx, 0x100
0x12e66: int 0x26
0x12e68: mov si, 0x1234
0x12e6b: mov ah, 0x30
0x12e6d: int 0x21
0x12e6f: cmp di, -0x23
0x12e72: jne 0x12e8c
0x12e74: mov si, 0x3b7
0x12e77: pop bx
0x12e78: push bx
0x12e79: sub bx, 0x103
0x12e7d: add si, bx
0x12e7f: mov di, 0x100
2018-12-25T11:45:22.965015695Z 48 PC: 12e6f | Get DOS version
2018-12-25T11:45:22.966598213Z 38 PC: 12ea8 | Create PSP
2018-12-25T11:45:22.968417975Z 53 PC: 12edc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:22.970266549Z 37 PC: 12efc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:22.972738917Z 9 PC: 12e26 | Display string (String= 'BCDEF- This is a 1000 byte COM test, 1994 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2257,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:45:23.145906706Z 42 PC: 12e51 | Get date 0x12e51: cmp dl, 5
0x12e54: jne 0x12e68
0x12e56: cmp dh, 0xa
0x12e59: jne 0x12e68
0x12e5b: mov al, 0
0x12e5d: mov cx, 0xd
0x12e60: mov dx, 1
0x12e63: mov bx, 0x100
0x12e66: int 0x26
0x12e68: mov si, 0x1234
0x12e6b: mov ah, 0x30
0x12e6d: int 0x21
0x12e6f: cmp di, -0x23
0x12e72: jne 0x12e8c
0x12e74: mov si, 0x3b7
0x12e77: pop bx
0x12e78: push bx
0x12e79: sub bx, 0x103
0x12e7d: add si, bx
0x12e7f: mov di, 0x100
2018-12-25T11:45:23.14872874Z 48 PC: 12e6f | Get DOS version
2018-12-25T11:45:23.149873659Z 38 PC: 12ea8 | Create PSP
2018-12-25T11:45:23.151340582Z 53 PC: 12edc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:23.153296773Z 37 PC: 12efc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:23.15440289Z 9 PC: 12e26 | Display string (String= 'BCDEF- This is a 1000 byte COM test, 1994 ')

{"DateBased":true,"Day":6,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2257,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:45:23.817106571Z 42 PC: 12e51 | Get date 0x12e51: cmp dl, 5
0x12e54: jne 0x12e68
0x12e56: cmp dh, 0xa
0x12e59: jne 0x12e68
0x12e5b: mov al, 0
0x12e5d: mov cx, 0xd
0x12e60: mov dx, 1
0x12e63: mov bx, 0x100
0x12e66: int 0x26
0x12e68: mov si, 0x1234
0x12e6b: mov ah, 0x30
0x12e6d: int 0x21
0x12e6f: cmp di, -0x23
0x12e72: jne 0x12e8c
0x12e74: mov si, 0x3b7
0x12e77: pop bx
0x12e78: push bx
0x12e79: sub bx, 0x103
0x12e7d: add si, bx
0x12e7f: mov di, 0x100
2018-12-25T11:45:23.819622735Z 48 PC: 12e6f | Get DOS version
2018-12-25T11:45:23.820855013Z 38 PC: 12ea8 | Create PSP
2018-12-25T11:45:23.822267788Z 53 PC: 12edc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:23.823515142Z 37 PC: 12efc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:23.825482308Z 9 PC: 12e26 | Display string (String= 'BCDEF- This is a 1000 byte COM test, 1994 ')