Sample viewer

vx.netlux.org/Virus.DOS.Kela.2520

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:17:18.729799867Z 255 PC: 13def | UNKNOWN!
2018-12-17T22:17:18.731246675Z 72 PC: 13e1b | Allocate memory
2018-12-17T22:17:18.733196362Z 82 PC: 13e68 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:17:18.734493763Z 53 PC: 9f2b5 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:17:18.736213106Z 37 PC: 9f2c8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:17:18.737696679Z 42 PC: 9f2cc | Get date 0x9f2cc: cmp dh, 0xb
0x9f2cf: jb 0x9f2ee
0x9f2d1: cmp al, 3
0x9f2d3: jb 0x9f2ee
0x9f2d5: push ds
0x9f2d6: mov ax, 0x3508
0x9f2d9: int 0x21
0x9f2db: mov word ptr cs:[0x91e], bx
0x9f2e0: mov word ptr cs:[0x920], es
0x9f2e5: pop ds
0x9f2e6: mov dx, 0x91c
0x9f2e9: mov ax, 0x2508
0x9f2ec: int 0x21
0x9f2ee: mov cx, 0x10
0x9f2f1: mov si, 0x13a
0x9f2f4: mov byte ptr cs:[si], 0x90
0x9f2f8: inc si
0x9f2f9: loop 0x9f2f4
0x9f2fb: mov byte ptr cs:[0x98c], 0
0x9f301: pop es

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":3037,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:48:05.464873423Z 255 PC: 13def | UNKNOWN!
2018-12-25T11:48:05.466635448Z 72 PC: 13e1b | Allocate memory
2018-12-25T11:48:05.46835498Z 82 PC: 13e68 | Get DOS internal pointers (SYSVARS)
2018-12-25T11:48:05.469546301Z 53 PC: 9f2b5 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:48:05.471724534Z 37 PC: 9f2c8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:48:05.472970417Z 42 PC: 9f2cc | Get date 0x9f2cc: cmp dh, 0xb
0x9f2cf: jb 0x9f2ee
0x9f2d1: cmp al, 3
0x9f2d3: jb 0x9f2ee
0x9f2d5: push ds
0x9f2d6: mov ax, 0x3508
0x9f2d9: int 0x21
0x9f2db: mov word ptr cs:[0x91e], bx
0x9f2e0: mov word ptr cs:[0x920], es
0x9f2e5: pop ds
0x9f2e6: mov dx, 0x91c
0x9f2e9: mov ax, 0x2508
0x9f2ec: int 0x21
0x9f2ee: mov cx, 0x10
0x9f2f1: mov si, 0x13a
0x9f2f4: mov byte ptr cs:[si], 0x90
0x9f2f8: inc si
0x9f2f9: loop 0x9f2f4
0x9f2fb: mov byte ptr cs:[0x98c], 0
0x9f301: pop es

{"DateBased":true,"Day":1,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":3037,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:48:05.870862411Z 255 PC: 13def | UNKNOWN!
2018-12-25T11:48:05.871864242Z 72 PC: 13e1b | Allocate memory
2018-12-25T11:48:05.873095088Z 82 PC: 13e68 | Get DOS internal pointers (SYSVARS)
2018-12-25T11:48:05.874005506Z 53 PC: 9f2b5 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:48:05.874965202Z 37 PC: 9f2c8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:48:05.876272381Z 42 PC: 9f2cc | Get date 0x9f2cc: cmp dh, 0xb
0x9f2cf: jb 0x9f2ee
0x9f2d1: cmp al, 3
0x9f2d3: jb 0x9f2ee
0x9f2d5: push ds
0x9f2d6: mov ax, 0x3508
0x9f2d9: int 0x21
0x9f2db: mov word ptr cs:[0x91e], bx
0x9f2e0: mov word ptr cs:[0x920], es
0x9f2e5: pop ds
0x9f2e6: mov dx, 0x91c
0x9f2e9: mov ax, 0x2508
0x9f2ec: int 0x21
0x9f2ee: mov cx, 0x10
0x9f2f1: mov si, 0x13a
0x9f2f4: mov byte ptr cs:[si], 0x90
0x9f2f8: inc si
0x9f2f9: loop 0x9f2f4
0x9f2fb: mov byte ptr cs:[0x98c], 0
0x9f301: pop es
2018-12-25T11:48:05.877901234Z 53 PC: 9f2db | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T11:48:05.878876881Z 37 PC: 9f2ee | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')

{"DateBased":true,"Day":2,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":3037,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:48:05.807331976Z 255 PC: 13def | UNKNOWN!
2018-12-25T11:48:05.808518365Z 72 PC: 13e1b | Allocate memory
2018-12-25T11:48:05.810085231Z 82 PC: 13e68 | Get DOS internal pointers (SYSVARS)
2018-12-25T11:48:05.811177147Z 53 PC: 9f2b5 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:48:05.812717401Z 37 PC: 9f2c8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:48:05.813924687Z 42 PC: 9f2cc | Get date 0x9f2cc: cmp dh, 0xb
0x9f2cf: jb 0x9f2ee
0x9f2d1: cmp al, 3
0x9f2d3: jb 0x9f2ee
0x9f2d5: push ds
0x9f2d6: mov ax, 0x3508
0x9f2d9: int 0x21
0x9f2db: mov word ptr cs:[0x91e], bx
0x9f2e0: mov word ptr cs:[0x920], es
0x9f2e5: pop ds
0x9f2e6: mov dx, 0x91c
0x9f2e9: mov ax, 0x2508
0x9f2ec: int 0x21
0x9f2ee: mov cx, 0x10
0x9f2f1: mov si, 0x13a
0x9f2f4: mov byte ptr cs:[si], 0x90
0x9f2f8: inc si
0x9f2f9: loop 0x9f2f4
0x9f2fb: mov byte ptr cs:[0x98c], 0
0x9f301: pop es