Sample viewer

vx.netlux.org/Virus.DOS.Keeper.Joker.1080

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:22:24.557072879Z 44 PC: 12e42 | Get time 0x12e42: cmp dl, dh
0x12e44: je 0x12e48
0x12e46: jmp 0x12ec7
0x12e48: inc dl
0x12e4a: xor dh, dh
0x12e4c: mov ax, dx
0x12e4e: mov dl, 0xa
0x12e50: div dl
0x12e52: cmp al, 1
0x12e54: je 0x12e7c
0x12e56: cmp al, 2
0x12e58: je 0x12e82
0x12e5a: cmp al, 3
0x12e5c: je 0x12e88
0x12e5e: cmp al, 4
0x12e60: je 0x12e8e
0x12e62: cmp al, 5
0x12e64: je 0x12e94
0x12e66: cmp al, 6
0x12e68: je 0x12e9a
2018-12-17T22:22:24.559800584Z 53 PC: 12ef4 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:22:24.560995049Z 37 PC: 12f2b | Set interrupt vector (Interrupt = '33' AKA 'Random read')

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":3930,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:50:30.898128473Z 44 PC: 12e42 | Get time 0x12e42: cmp dl, dh
0x12e44: je 0x12e48
0x12e46: jmp 0x12ec7
0x12e48: inc dl
0x12e4a: xor dh, dh
0x12e4c: mov ax, dx
0x12e4e: mov dl, 0xa
0x12e50: div dl
0x12e52: cmp al, 1
0x12e54: je 0x12e7c
0x12e56: cmp al, 2
0x12e58: je 0x12e82
0x12e5a: cmp al, 3
0x12e5c: je 0x12e88
0x12e5e: cmp al, 4
0x12e60: je 0x12e8e
0x12e62: cmp al, 5
0x12e64: je 0x12e94
0x12e66: cmp al, 6
0x12e68: je 0x12e9a
2018-12-25T11:50:30.900755659Z 53 PC: 12ef4 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:50:30.902515686Z 37 PC: 12f2b | Set interrupt vector (Interrupt = '33' AKA 'Random read')

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":1,"TimeBased":true,"OriginalID":3930,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:50:31.314321636Z 44 PC: 12e42 | Get time 0x12e42: cmp dl, dh
0x12e44: je 0x12e48
0x12e46: jmp 0x12ec7
0x12e48: inc dl
0x12e4a: xor dh, dh
0x12e4c: mov ax, dx
0x12e4e: mov dl, 0xa
0x12e50: div dl
0x12e52: cmp al, 1
0x12e54: je 0x12e7c
0x12e56: cmp al, 2
0x12e58: je 0x12e82
0x12e5a: cmp al, 3
0x12e5c: je 0x12e88
0x12e5e: cmp al, 4
0x12e60: je 0x12e8e
0x12e62: cmp al, 5
0x12e64: je 0x12e94
0x12e66: cmp al, 6
0x12e68: je 0x12e9a
2018-12-25T11:50:31.31806232Z 53 PC: 12ef4 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:50:31.320081618Z 37 PC: 12f2b | Set interrupt vector (Interrupt = '33' AKA 'Random read')