Sample viewer

vx.netlux.org/Virus.DOS.ARCV.1060

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:23:10.420712582Z 42 PC: 12afa | Get date 0x12afa: cmp cx, 0x7c9
0x12afe: jb 0x12b14
0x12b00: mov ax, 0xff45
0x12b03: int 0x13
0x12b05: cmp ax, 0xbb
0x12b08: jne 0x12b14
0x12b0a: mov ah, 9
0x12b0c: lea dx, word ptr [di + 0x491]
0x12b10: int 0x21
0x12b12: jmp 0x12b12
0x12b14: mov ax, 0xff45
0x12b17: int 0x21
0x12b19: cmp ax, 0xbb
0x12b1c: je 0x12b21
0x12b1e: call 0x12b53
0x12b21: mov ax, word ptr [di + 0x53a]
0x12b25: mov bx, word ptr [di + 0x53c]
0x12b29: cli
0x12b2a: mov ss, ax
0x12b2c: mov sp, bx
2018-12-17T22:23:10.423729137Z 255 PC: 12b19 | UNKNOWN!
2018-12-17T22:23:10.425368195Z 76 PC: 12aa4 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4057,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:50:51.84154169Z 42 PC: 12afa | Get date 0x12afa: cmp cx, 0x7c9
0x12afe: jb 0x12b14
0x12b00: mov ax, 0xff45
0x12b03: int 0x13
0x12b05: cmp ax, 0xbb
0x12b08: jne 0x12b14
0x12b0a: mov ah, 9
0x12b0c: lea dx, word ptr [di + 0x491]
0x12b10: int 0x21
0x12b12: jmp 0x12b12
0x12b14: mov ax, 0xff45
0x12b17: int 0x21
0x12b19: cmp ax, 0xbb
0x12b1c: je 0x12b21
0x12b1e: call 0x12b53
0x12b21: mov ax, word ptr [di + 0x53a]
0x12b25: mov bx, word ptr [di + 0x53c]
0x12b29: cli
0x12b2a: mov ss, ax
0x12b2c: mov sp, bx
2018-12-25T11:50:51.844081855Z 255 PC: 12b19 | UNKNOWN!
2018-12-25T11:50:51.84520473Z 76 PC: 12aa4 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1993,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4057,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:50:51.941850432Z 42 PC: 12afa | Get date 0x12afa: cmp cx, 0x7c9
0x12afe: jb 0x12b14
0x12b00: mov ax, 0xff45
0x12b03: int 0x13
0x12b05: cmp ax, 0xbb
0x12b08: jne 0x12b14
0x12b0a: mov ah, 9
0x12b0c: lea dx, word ptr [di + 0x491]
0x12b10: int 0x21
0x12b12: jmp 0x12b12
0x12b14: mov ax, 0xff45
0x12b17: int 0x21
0x12b19: cmp ax, 0xbb
0x12b1c: je 0x12b21
0x12b1e: call 0x12b53
0x12b21: mov ax, word ptr [di + 0x53a]
0x12b25: mov bx, word ptr [di + 0x53c]
0x12b29: cli
0x12b2a: mov ss, ax
0x12b2c: mov sp, bx
2018-12-25T11:50:51.945111538Z 255 PC: 12b19 | UNKNOWN!
2018-12-25T11:50:51.946086001Z 76 PC: 12aa4 | Terminate with return code (Return code = '0')