Sample viewer

vx.netlux.org/Virus.DOS.IVP.335.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:22:46.700247295Z 53 PC: 12a50 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:22:46.701841667Z 37 PC: 12a61 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:22:46.703105391Z 78 PC: 12a87 | Find first file
2018-12-17T22:22:46.710697986Z 79 PC: 12a87 | Find next file
2018-12-17T22:22:46.714704354Z 79 PC: 12a87 | Find next file
2018-12-17T22:22:46.718059921Z 79 PC: 12a87 | Find next file
2018-12-17T22:22:46.72147398Z 79 PC: 12a87 | Find next file
2018-12-17T22:22:46.724780463Z 79 PC: 12a87 | Find next file
2018-12-17T22:22:46.728970725Z 79 PC: 12a87 | Find next file
2018-12-17T22:22:46.732150822Z 79 PC: 12a87 | Find next file
2018-12-17T22:22:46.735228176Z 79 PC: 12a87 | Find next file
2018-12-17T22:22:46.738436726Z 42 PC: 12ad9 | Get date 0x12ad9: cmp cx, 0x7ca
0x12add: jb 0x12b21
0x12adf: mov ah, 9
0x12ae1: mov dx, 0x209
0x12ae4: int 0x21
0x12ae6: mov cx, 2
0x12ae9: push cx
0x12aea: cli
0x12aeb: mov dx, 0x2ee0
0x12aee: sub dx, word ptr cs:[0x1388]
0x12af3: mov bx, 0x64
0x12af6: mov al, 0xb6
0x12af8: out 0x43, al
0x12afa: mov ax, bx
0x12afc: out 0x42, al
0x12afe: mov al, ah
0x12b00: out 0x42, al
0x12b02: in al, 0x61
0x12b04: mov ah, 0
0x12b06: or ax, 3
2018-12-17T22:22:46.741653179Z 9 PC: 12ae6 | Display string (String= 'Somehing is growing inside! And your not going to like it! [IVP] ')
2018-12-17T22:22:46.800979896Z 37 PC: 12a74 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":3990,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:50:36.761238012Z 53 PC: 12a50 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:50:36.762668654Z 37 PC: 12a61 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:50:36.765225825Z 78 PC: 12a87 | Find first file
2018-12-25T11:50:36.772463881Z 79 PC: 12a87 | Find next file (See above)
2018-12-25T11:50:36.775740689Z 79 PC: 12a87 | Find next file (See above)
2018-12-25T11:50:36.780227676Z 79 PC: 12a87 | Find next file (See above)
2018-12-25T11:50:36.78392457Z 79 PC: 12a87 | Find next file (See above)
2018-12-25T11:50:36.787163228Z 79 PC: 12a87 | Find next file (See above)
2018-12-25T11:50:36.791356966Z 79 PC: 12a87 | Find next file (See above)
2018-12-25T11:50:36.794576002Z 79 PC: 12a87 | Find next file (See above)
2018-12-25T11:50:36.797795415Z 79 PC: 12a87 | Find next file (See above)
2018-12-25T11:50:36.800712737Z 42 PC: 12ad9 | Get date 0x12ad9: cmp cx, 0x7ca
0x12add: jb 0x12b21
0x12adf: mov ah, 9
0x12ae1: mov dx, 0x209
0x12ae4: int 0x21
0x12ae6: mov cx, 2
0x12ae9: push cx
0x12aea: cli
0x12aeb: mov dx, 0x2ee0
0x12aee: sub dx, word ptr cs:[0x1388]
0x12af3: mov bx, 0x64
0x12af6: mov al, 0xb6
0x12af8: out 0x43, al
0x12afa: mov ax, bx
0x12afc: out 0x42, al
0x12afe: mov al, ah
0x12b00: out 0x42, al
0x12b02: in al, 0x61
0x12b04: mov ah, 0
0x12b06: or ax, 3
2018-12-25T11:50:36.80456177Z 37 PC: 12a74 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')

{"DateBased":true,"Day":1,"Month":1,"Year":1994,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":3990,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:50:38.250603871Z 53 PC: 12a50 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:50:38.252109972Z 37 PC: 12a61 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:50:38.253288378Z 78 PC: 12a87 | Find first file
2018-12-25T11:50:38.259155486Z 79 PC: 12a87 | Find next file (See above)
2018-12-25T11:50:38.261994054Z 79 PC: 12a87 | Find next file (See above)
2018-12-25T11:50:38.264508307Z 79 PC: 12a87 | Find next file (See above)
2018-12-25T11:50:38.266838514Z 79 PC: 12a87 | Find next file (See above)
2018-12-25T11:50:38.270334815Z 79 PC: 12a87 | Find next file (See above)
2018-12-25T11:50:38.27279593Z 79 PC: 12a87 | Find next file (See above)
2018-12-25T11:50:38.275188247Z 79 PC: 12a87 | Find next file (See above)
2018-12-25T11:50:38.278810318Z 79 PC: 12a87 | Find next file (See above)
2018-12-25T11:50:38.281142999Z 42 PC: 12ad9 | Get date 0x12ad9: cmp cx, 0x7ca
0x12add: jb 0x12b21
0x12adf: mov ah, 9
0x12ae1: mov dx, 0x209
0x12ae4: int 0x21
0x12ae6: mov cx, 2
0x12ae9: push cx
0x12aea: cli
0x12aeb: mov dx, 0x2ee0
0x12aee: sub dx, word ptr cs:[0x1388]
0x12af3: mov bx, 0x64
0x12af6: mov al, 0xb6
0x12af8: out 0x43, al
0x12afa: mov ax, bx
0x12afc: out 0x42, al
0x12afe: mov al, ah
0x12b00: out 0x42, al
0x12b02: in al, 0x61
0x12b04: mov ah, 0
0x12b06: or ax, 3
2018-12-25T11:50:38.283224475Z 9 PC: 12ae6 | Display string (String= 'Somehing is growing inside! And your not going to like it! [IVP] ')
2018-12-25T11:50:38.328456973Z 37 PC: 12a74 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')