Sample viewer

vx.netlux.org/Virus.DOS.Yankee.2561

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:20:52.083967467Z 198 PC: 138be | UNKNOWN!
2018-12-17T22:20:52.085594301Z 42 PC: 139aa | Get date 0x139aa: cmp dl, 0x14
0x139ad: jne 0x139c3
0x139af: mov ax, 0x3508
0x139b2: int 0x21
0x139b4: mov word ptr [0x5c], es
0x139b8: mov word ptr [0x5a], bx
0x139bc: mov dx, 0x6a
0x139bf: mov ah, 0x25
0x139c1: int 0x21
0x139c3: mov ax, 0x3521
0x139c6: int 0x21
0x139c8: mov word ptr [0x2c], es
0x139cc: mov word ptr [0x2a], bx
0x139d0: mov word ptr [0x30], es
0x139d4: mov word ptr [0x2e], bx
0x139d8: mov ax, 0x3501
0x139db: int 0x21
0x139dd: mov si, bx
0x139df: mov di, es
0x139e1: mov ax, 0x351c
2018-12-17T22:20:52.08840383Z 53 PC: 139c8 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:20:52.090866173Z 53 PC: 139dd | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:20:52.092261968Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:20:52.093685652Z 37 PC: 139f7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:20:52.095636689Z 37 PC: 139ff | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:20:52.097414994Z 37 PC: 13a56 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:20:52.099059526Z 37 PC: 13a64 | Set interrupt vector (Interrupt = '1' AKA 'Character input')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":3631,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:49:45.931229697Z 198 PC: 138be | UNKNOWN!
2018-12-25T11:49:45.932988028Z 42 PC: 139aa | Get date 0x139aa: cmp dl, 0x14
0x139ad: jne 0x139c3
0x139af: mov ax, 0x3508
0x139b2: int 0x21
0x139b4: mov word ptr [0x5c], es
0x139b8: mov word ptr [0x5a], bx
0x139bc: mov dx, 0x6a
0x139bf: mov ah, 0x25
0x139c1: int 0x21
0x139c3: mov ax, 0x3521
0x139c6: int 0x21
0x139c8: mov word ptr [0x2c], es
0x139cc: mov word ptr [0x2a], bx
0x139d0: mov word ptr [0x30], es
0x139d4: mov word ptr [0x2e], bx
0x139d8: mov ax, 0x3501
0x139db: int 0x21
0x139dd: mov si, bx
0x139df: mov di, es
0x139e1: mov ax, 0x351c
2018-12-25T11:49:45.935274564Z 53 PC: 139c8 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:49:45.936540287Z 53 PC: 139dd | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T11:49:45.938490348Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T11:49:45.940103314Z 37 PC: 139f7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:49:45.941482249Z 37 PC: 139ff | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T11:49:45.944446996Z 37 PC: 13a56 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T11:49:45.946020761Z 37 PC: 13a64 | Set interrupt vector (Interrupt = '1' AKA 'Character input')

{"DateBased":true,"Day":20,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":3631,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:49:46.133524155Z 198 PC: 138be | UNKNOWN!
2018-12-25T11:49:46.134829749Z 42 PC: 139aa | Get date 0x139aa: cmp dl, 0x14
0x139ad: jne 0x139c3
0x139af: mov ax, 0x3508
0x139b2: int 0x21
0x139b4: mov word ptr [0x5c], es
0x139b8: mov word ptr [0x5a], bx
0x139bc: mov dx, 0x6a
0x139bf: mov ah, 0x25
0x139c1: int 0x21
0x139c3: mov ax, 0x3521
0x139c6: int 0x21
0x139c8: mov word ptr [0x2c], es
0x139cc: mov word ptr [0x2a], bx
0x139d0: mov word ptr [0x30], es
0x139d4: mov word ptr [0x2e], bx
0x139d8: mov ax, 0x3501
0x139db: int 0x21
0x139dd: mov si, bx
0x139df: mov di, es
0x139e1: mov ax, 0x351c
2018-12-25T11:49:46.137060668Z 53 PC: 139b4 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T11:49:46.138177634Z 37 PC: 139c3 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T11:49:46.13911205Z 53 PC: 139c8 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:49:46.140188223Z 53 PC: 139dd | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T11:49:46.141421442Z 53 PC: 139e6 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T11:49:46.143829339Z 37 PC: 139f7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:49:46.145067888Z 37 PC: 139ff | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T11:49:46.146327911Z 37 PC: 13a56 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T11:49:46.148174753Z 37 PC: 13a64 | Set interrupt vector (Interrupt = '1' AKA 'Character input')