Sample viewer

vx.netlux.org/Virus.DOS.FaxFree.Abstract.1024

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:23:14.656431107Z 42 PC: 12d9b | Get date 0x12d9b: cmp dh, 0xb
0x12d9e: jne 0x12da6
0x12da0: mov si, 0x4456
0x12da3: jmp 0x12a70
0x12da6: xor si, si
0x12da8: jmp 0x12a70
0x12dab: nop
0x12dac: mov ah, 0x4c
0x12dae: int 0x21
0x12db0: stc
0x12db1: ret
0x12db2: mov word ptr cs:[0x96], 0
0x12db9: int 0xec
0x12dbb: push -0x33
0x12dbd: in ax, dx
0x12dbe: sub bl, byte ptr [bp + di - 0x20d2]
0x12dc2: push ds
0x12dc3: xchg ax, si
0x12dc4: add bl, al
0x12dc6: mov dx, word ptr cs:[0x180]
2018-12-17T22:23:14.659711752Z 48 PC: 12abb | Get DOS version
2018-12-17T22:23:14.661819867Z 53 PC: 12b24 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:23:14.663357388Z 7 PC: 12a44 | Direct console input without echo

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4071,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:50:55.933170902Z 42 PC: 12d9b | Get date 0x12d9b: cmp dh, 0xb
0x12d9e: jne 0x12da6
0x12da0: mov si, 0x4456
0x12da3: jmp 0x12a70
0x12da6: xor si, si
0x12da8: jmp 0x12a70
0x12dab: nop
0x12dac: mov ah, 0x4c
0x12dae: int 0x21
0x12db0: stc
0x12db1: ret
0x12db2: mov word ptr cs:[0x96], 0
0x12db9: int 0xec
0x12dbb: push -0x33
0x12dbd: in ax, dx
0x12dbe: sub bl, byte ptr [bp + di - 0x20d2]
0x12dc2: push ds
0x12dc3: xchg ax, si
0x12dc4: add bl, al
0x12dc6: mov dx, word ptr cs:[0x180]
2018-12-25T11:50:55.936003282Z 48 PC: 12abb | Get DOS version
2018-12-25T11:50:55.937504953Z 53 PC: 12b24 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:50:55.939190602Z 7 PC: 12a44 | Direct console input without echo

{"DateBased":true,"Day":1,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4071,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:50:55.93285502Z 42 PC: 12d9b | Get date 0x12d9b: cmp dh, 0xb
0x12d9e: jne 0x12da6
0x12da0: mov si, 0x4456
0x12da3: jmp 0x12a70
0x12da6: xor si, si
0x12da8: jmp 0x12a70
0x12dab: nop
0x12dac: mov ah, 0x4c
0x12dae: int 0x21
0x12db0: stc
0x12db1: ret
0x12db2: mov word ptr cs:[0x96], 0
0x12db9: int 0xec
0x12dbb: push -0x33
0x12dbd: in ax, dx
0x12dbe: sub bl, byte ptr [bp + di - 0x20d2]
0x12dc2: push ds
0x12dc3: xchg ax, si
0x12dc4: add bl, al
0x12dc6: mov dx, word ptr cs:[0x180]
2018-12-25T11:50:55.934984929Z 7 PC: 12a44 | Direct console input without echo