Sample viewer

vx.netlux.org/Virus.DOS.Storm.1172

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:10:40.511251854Z 48 PC: 1516d | Get DOS version
2018-12-17T22:10:40.512739523Z 53 PC: 15176 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:10:40.514411937Z 53 PC: 15197 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:10:40.515747974Z 75 PC: 151b4 | Execute program
2018-12-17T22:10:40.518734768Z 80 PC: 9f863 | Set current PSP
2018-12-17T22:10:40.520052163Z 26 PC: 9f86f | Set disk transfer address
2018-12-17T22:10:40.521344638Z 37 PC: 9f8ba | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:10:40.522478667Z 42 PC: 9f8be | Get date 0x9f8be: cmp dh, 3
0x9f8c1: jne 0x9f8eb
0x9f8c3: cmp dh, dl
0x9f8c5: jne 0x9f8eb
0x9f8c7: mov si, 0x18c
0x9f8ca: mov cx, 0x43
0x9f8cd: mov es, word ptr [0x567]
0x9f8d1: sub di, di
0x9f8d3: mov ah, 4
0x9f8d5: nop
0x9f8d6: nop
0x9f8d7: lodsb al, byte ptr [si]
0x9f8d8: xor al, 0xff
0x9f8da: stosw word ptr es:[di], ax
0x9f8db: loop 0x9f8d7
0x9f8dd: mov word ptr [0x55b], 0xfd20
0x9f8e3: mov dx, 0x3fb
0x9f8e6: mov ax, 0x2508
0x9f8e9: int 0x21
0x9f8eb: mov bx, ss
2018-12-17T22:10:40.527922338Z 9 PC: 13165 | Display string (String= '')
2018-12-17T22:10:40.530223592Z 9 PC: 1316c | Display string (Could not find end pointer)
2018-12-17T22:10:40.541384184Z 76 PC: 13182 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2308,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:45:29.388562772Z 48 PC: 1516d | Get DOS version
2018-12-25T11:45:29.390445653Z 53 PC: 15176 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T11:45:29.392169437Z 53 PC: 15197 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:29.39362641Z 75 PC: 151b4 | Execute program
2018-12-25T11:45:29.396916456Z 80 PC: 9f863 | Set current PSP
2018-12-25T11:45:29.397989772Z 26 PC: 9f86f | Set disk transfer address
2018-12-25T11:45:29.399402738Z 37 PC: 9f8ba | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:29.401798238Z 42 PC: 9f8be | Get date 0x9f8be: cmp dh, 3
0x9f8c1: jne 0x9f8eb
0x9f8c3: cmp dh, dl
0x9f8c5: jne 0x9f8eb
0x9f8c7: mov si, 0x18c
0x9f8ca: mov cx, 0x43
0x9f8cd: mov es, word ptr [0x567]
0x9f8d1: sub di, di
0x9f8d3: mov ah, 4
0x9f8d5: nop
0x9f8d6: nop
0x9f8d7: lodsb al, byte ptr [si]
0x9f8d8: xor al, 0xff
0x9f8da: stosw word ptr es:[di], ax
0x9f8db: loop 0x9f8d7
0x9f8dd: mov word ptr [0x55b], 0xfd20
0x9f8e3: mov dx, 0x3fb
0x9f8e6: mov ax, 0x2508
0x9f8e9: int 0x21
0x9f8eb: mov bx, ss
2018-12-25T11:45:29.414341258Z 9 PC: 13165 | Display string (String= '')
2018-12-25T11:45:29.416924331Z 9 PC: 1316c | Display string (Could not find end pointer)
2018-12-25T11:45:29.441935877Z 76 PC: 13182 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":3,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2308,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:45:29.43627695Z 48 PC: 1516d | Get DOS version
2018-12-25T11:45:29.446681174Z 53 PC: 15176 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T11:45:29.447894054Z 53 PC: 15197 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:29.448882846Z 75 PC: 151b4 | Execute program
2018-12-25T11:45:29.451304308Z 80 PC: 9f863 | Set current PSP
2018-12-25T11:45:29.452573666Z 26 PC: 9f86f | Set disk transfer address
2018-12-25T11:45:29.454118413Z 37 PC: 9f8ba | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:29.455757941Z 42 PC: 9f8be | Get date 0x9f8be: cmp dh, 3
0x9f8c1: jne 0x9f8eb
0x9f8c3: cmp dh, dl
0x9f8c5: jne 0x9f8eb
0x9f8c7: mov si, 0x18c
0x9f8ca: mov cx, 0x43
0x9f8cd: mov es, word ptr [0x567]
0x9f8d1: sub di, di
0x9f8d3: mov ah, 4
0x9f8d5: nop
0x9f8d6: nop
0x9f8d7: lodsb al, byte ptr [si]
0x9f8d8: xor al, 0xff
0x9f8da: stosw word ptr es:[di], ax
0x9f8db: loop 0x9f8d7
0x9f8dd: mov word ptr [0x55b], 0xfd20
0x9f8e3: mov dx, 0x3fb
0x9f8e6: mov ax, 0x2508
0x9f8e9: int 0x21
0x9f8eb: mov bx, ss
2018-12-25T11:45:29.458949334Z 9 PC: 13165 | Display string (String= '')
2018-12-25T11:45:29.460976271Z 9 PC: 1316c | Display string (Could not find end pointer)
2018-12-25T11:45:29.47317285Z 76 PC: 13182 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":3,"Month":3,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2308,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:45:29.513280692Z 48 PC: 1516d | Get DOS version
2018-12-25T11:45:29.51474211Z 53 PC: 15176 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T11:45:29.516576806Z 53 PC: 15197 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:29.518440972Z 75 PC: 151b4 | Execute program
2018-12-25T11:45:29.520741901Z 80 PC: 9f863 | Set current PSP
2018-12-25T11:45:29.521953649Z 26 PC: 9f86f | Set disk transfer address
2018-12-25T11:45:29.523194833Z 37 PC: 9f8ba | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:29.524570627Z 42 PC: 9f8be | Get date 0x9f8be: cmp dh, 3
0x9f8c1: jne 0x9f8eb
0x9f8c3: cmp dh, dl
0x9f8c5: jne 0x9f8eb
0x9f8c7: mov si, 0x18c
0x9f8ca: mov cx, 0x43
0x9f8cd: mov es, word ptr [0x567]
0x9f8d1: sub di, di
0x9f8d3: mov ah, 4
0x9f8d5: nop
0x9f8d6: nop
0x9f8d7: lodsb al, byte ptr [si]
0x9f8d8: xor al, 0xff
0x9f8da: stosw word ptr es:[di], ax
0x9f8db: loop 0x9f8d7
0x9f8dd: mov word ptr [0x55b], 0xfd20
0x9f8e3: mov dx, 0x3fb
0x9f8e6: mov ax, 0x2508
0x9f8e9: int 0x21
0x9f8eb: mov bx, ss
2018-12-25T11:45:29.527027673Z 37 PC: 9f8eb | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T11:45:29.529176807Z 9 PC: 13165 | Display string (String= '')
2018-12-25T11:45:29.530620535Z 9 PC: 1316c | Display string (Could not find end pointer)
2018-12-25T11:45:29.537514222Z 76 PC: 13182 | Terminate with return code (Return code = '0')