Sample viewer

vx.netlux.org/Virus.DOS.Peasant.1243

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:11:49.623335755Z 255 PC: 12b80 | UNKNOWN!
2018-12-17T22:11:49.624904779Z 73 PC: 12b98 | Release memory
2018-12-17T22:11:49.626662394Z 72 PC: 12b9f | Allocate memory
2018-12-17T22:11:49.628842077Z 74 PC: 12bac | Reallocate memory
2018-12-17T22:11:49.633532282Z 74 PC: 12bbc | Reallocate memory
2018-12-17T22:11:49.635104494Z 37 PC: 12bf0 | Set interrupt vector (Interrupt = '255' AKA 'UNKNOWN!')
2018-12-17T22:11:49.636705981Z 53 PC: 12bf5 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:11:49.639271384Z 42 PC: 12c01 | Get date 0x12c01: cmp al, 1
0x12c03: je 0x12c0b
0x12c05: mov dx, 0x204
0x12c08: jmp 0x12c19
0x12c0a: nop
0x12c0b: cmp dh, 3
0x12c0e: ja 0x12c16
0x12c10: mov dx, 0x204
0x12c13: jmp 0x12c19
0x12c15: nop
0x12c16: mov dx, 0x127
0x12c19: mov ax, 0x2521
0x12c1c: int 0x21
0x12c1e: pop si
0x12c1f: push cs
0x12c20: pop ds
0x12c21: push cs
0x12c22: pop es
0x12c23: int 0xff
0x12c25: push ds
2018-12-17T22:11:49.641775564Z 37 PC: 12c1e | Set interrupt vector (Interrupt = '33' AKA 'Random read')

{"DateBased":true,"Day":7,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2437,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:45:49.764437499Z 255 PC: 12b80 | UNKNOWN!
2018-12-25T11:45:49.771879827Z 73 PC: 12b98 | Release memory
2018-12-25T11:45:49.772988217Z 72 PC: 12b9f | Allocate memory
2018-12-25T11:45:49.774476865Z 74 PC: 12bac | Reallocate memory
2018-12-25T11:45:49.776451971Z 74 PC: 12bbc | Reallocate memory
2018-12-25T11:45:49.778152948Z 37 PC: 12bf0 | Set interrupt vector (Interrupt = '255' AKA 'UNKNOWN!')
2018-12-25T11:45:49.7791337Z 53 PC: 12bf5 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:49.780717458Z 42 PC: 12c01 | Get date 0x12c01: cmp al, 1
0x12c03: je 0x12c0b
0x12c05: mov dx, 0x204
0x12c08: jmp 0x12c19
0x12c0a: nop
0x12c0b: cmp dh, 3
0x12c0e: ja 0x12c16
0x12c10: mov dx, 0x204
0x12c13: jmp 0x12c19
0x12c15: nop
0x12c16: mov dx, 0x127
0x12c19: mov ax, 0x2521
0x12c1c: int 0x21
0x12c1e: pop si
0x12c1f: push cs
0x12c20: pop ds
0x12c21: push cs
0x12c22: pop es
0x12c23: int 0xff
0x12c25: push ds
2018-12-25T11:45:49.782801025Z 37 PC: 12c1e | Set interrupt vector (Interrupt = '33' AKA 'Random read')

{"DateBased":true,"Day":7,"Month":4,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2437,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:45:50.107514335Z 255 PC: 12b80 | UNKNOWN!
2018-12-25T11:45:50.109231771Z 73 PC: 12b98 | Release memory
2018-12-25T11:45:50.110464111Z 72 PC: 12b9f | Allocate memory
2018-12-25T11:45:50.112046429Z 74 PC: 12bac | Reallocate memory
2018-12-25T11:45:50.113978151Z 74 PC: 12bbc | Reallocate memory
2018-12-25T11:45:50.115696754Z 37 PC: 12bf0 | Set interrupt vector (Interrupt = '255' AKA 'UNKNOWN!')
2018-12-25T11:45:50.116707174Z 53 PC: 12bf5 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:50.122900999Z 42 PC: 12c01 | Get date 0x12c01: cmp al, 1
0x12c03: je 0x12c0b
0x12c05: mov dx, 0x204
0x12c08: jmp 0x12c19
0x12c0a: nop
0x12c0b: cmp dh, 3
0x12c0e: ja 0x12c16
0x12c10: mov dx, 0x204
0x12c13: jmp 0x12c19
0x12c15: nop
0x12c16: mov dx, 0x127
0x12c19: mov ax, 0x2521
0x12c1c: int 0x21
0x12c1e: pop si
0x12c1f: push cs
0x12c20: pop ds
0x12c21: push cs
0x12c22: pop es
0x12c23: int 0xff
0x12c25: push ds
2018-12-25T11:45:50.124828114Z 37 PC: 12c1e | Set interrupt vector (Interrupt = '33' AKA 'Random read')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2437,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:45:50.737515747Z 255 PC: 12b80 | UNKNOWN!
2018-12-25T11:45:50.739255427Z 73 PC: 12b98 | Release memory
2018-12-25T11:45:50.740453263Z 72 PC: 12b9f | Allocate memory
2018-12-25T11:45:50.742098111Z 74 PC: 12bac | Reallocate memory
2018-12-25T11:45:50.743935735Z 74 PC: 12bbc | Reallocate memory
2018-12-25T11:45:50.746170813Z 37 PC: 12bf0 | Set interrupt vector (Interrupt = '255' AKA 'UNKNOWN!')
2018-12-25T11:45:50.747098381Z 53 PC: 12bf5 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:50.748075523Z 42 PC: 12c01 | Get date 0x12c01: cmp al, 1
0x12c03: je 0x12c0b
0x12c05: mov dx, 0x204
0x12c08: jmp 0x12c19
0x12c0a: nop
0x12c0b: cmp dh, 3
0x12c0e: ja 0x12c16
0x12c10: mov dx, 0x204
0x12c13: jmp 0x12c19
0x12c15: nop
0x12c16: mov dx, 0x127
0x12c19: mov ax, 0x2521
0x12c1c: int 0x21
0x12c1e: pop si
0x12c1f: push cs
0x12c20: pop ds
0x12c21: push cs
0x12c22: pop es
0x12c23: int 0xff
0x12c25: push ds
2018-12-25T11:45:50.756187752Z 37 PC: 12c1e | Set interrupt vector (Interrupt = '33' AKA 'Random read')