Sample viewer

vx.netlux.org/Virus.DOS.ARCV.Ice.678

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:24:08.132465931Z 42 PC: 13e51 | Get date 0x13e51: cmp dh, 1
0x13e54: jne 0x13e7d
0x13e56: cmp dl, 7
0x13e59: jae 0x13e7d
0x13e5b: mov di, 0x313
0x13e5e: add di, si
0x13e60: mov al, 0x99
0x13e62: mov cx, 0x95
0x13e65: mov ah, byte ptr [di]
0x13e67: mov dl, ah
0x13e69: xor ah, al
0x13e6b: mov byte ptr [di], ah
0x13e6d: mov al, dl
0x13e6f: inc di
0x13e70: loop 0x13e65
0x13e72: mov ah, 9
0x13e74: mov dx, 0x313
0x13e77: add dx, si
0x13e79: int 0x21
0x13e7b: jmp 0x13e7b
2018-12-17T22:24:08.14831548Z 255 PC: 13e91 | UNKNOWN!
2018-12-17T22:24:08.149317629Z 49 PC: 13ed7 | Terminate and stay resident (Return code = '0' | Memory size = '72')

{"DateBased":true,"Day":1,"Month":2,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4233,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:51:21.103090625Z 42 PC: 13e51 | Get date 0x13e51: cmp dh, 1
0x13e54: jne 0x13e7d
0x13e56: cmp dl, 7
0x13e59: jae 0x13e7d
0x13e5b: mov di, 0x313
0x13e5e: add di, si
0x13e60: mov al, 0x99
0x13e62: mov cx, 0x95
0x13e65: mov ah, byte ptr [di]
0x13e67: mov dl, ah
0x13e69: xor ah, al
0x13e6b: mov byte ptr [di], ah
0x13e6d: mov al, dl
0x13e6f: inc di
0x13e70: loop 0x13e65
0x13e72: mov ah, 9
0x13e74: mov dx, 0x313
0x13e77: add dx, si
0x13e79: int 0x21
0x13e7b: jmp 0x13e7b
2018-12-25T11:51:21.106230219Z 255 PC: 13e91 | UNKNOWN!
2018-12-25T11:51:21.118852606Z 49 PC: 13ed7 | Terminate and stay resident (Return code = '0' | Memory size = '72')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4233,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:51:21.063455241Z 42 PC: 13e51 | Get date 0x13e51: cmp dh, 1
0x13e54: jne 0x13e7d
0x13e56: cmp dl, 7
0x13e59: jae 0x13e7d
0x13e5b: mov di, 0x313
0x13e5e: add di, si
0x13e60: mov al, 0x99
0x13e62: mov cx, 0x95
0x13e65: mov ah, byte ptr [di]
0x13e67: mov dl, ah
0x13e69: xor ah, al
0x13e6b: mov byte ptr [di], ah
0x13e6d: mov al, dl
0x13e6f: inc di
0x13e70: loop 0x13e65
0x13e72: mov ah, 9
0x13e74: mov dx, 0x313
0x13e77: add dx, si
0x13e79: int 0x21
0x13e7b: jmp 0x13e7b
2018-12-25T11:51:21.066208081Z 9 PC: 13e7b | Display string (String= ' Happy New Year from the ARCV Released 1 June 1992. Made in England by ICE-9 Look out for New Year Boot Virus ')

{"DateBased":true,"Day":8,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4233,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:51:21.125761879Z 42 PC: 13e51 | Get date 0x13e51: cmp dh, 1
0x13e54: jne 0x13e7d
0x13e56: cmp dl, 7
0x13e59: jae 0x13e7d
0x13e5b: mov di, 0x313
0x13e5e: add di, si
0x13e60: mov al, 0x99
0x13e62: mov cx, 0x95
0x13e65: mov ah, byte ptr [di]
0x13e67: mov dl, ah
0x13e69: xor ah, al
0x13e6b: mov byte ptr [di], ah
0x13e6d: mov al, dl
0x13e6f: inc di
0x13e70: loop 0x13e65
0x13e72: mov ah, 9
0x13e74: mov dx, 0x313
0x13e77: add dx, si
0x13e79: int 0x21
0x13e7b: jmp 0x13e7b
2018-12-25T11:51:21.128514119Z 255 PC: 13e91 | UNKNOWN!
2018-12-25T11:51:21.129555081Z 49 PC: 13ed7 | Terminate and stay resident (Return code = '0' | Memory size = '72')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4233,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:51:21.124547387Z 42 PC: 13e51 | Get date 0x13e51: cmp dh, 1
0x13e54: jne 0x13e7d
0x13e56: cmp dl, 7
0x13e59: jae 0x13e7d
0x13e5b: mov di, 0x313
0x13e5e: add di, si
0x13e60: mov al, 0x99
0x13e62: mov cx, 0x95
0x13e65: mov ah, byte ptr [di]
0x13e67: mov dl, ah
0x13e69: xor ah, al
0x13e6b: mov byte ptr [di], ah
0x13e6d: mov al, dl
0x13e6f: inc di
0x13e70: loop 0x13e65
0x13e72: mov ah, 9
0x13e74: mov dx, 0x313
0x13e77: add dx, si
0x13e79: int 0x21
0x13e7b: jmp 0x13e7b
2018-12-25T11:51:21.127185614Z 9 PC: 13e7b | Display string (String= ' Happy New Year from the ARCV Released 1 June 1992. Made in England by ICE-9 Look out for New Year Boot Virus ')

{"DateBased":true,"Day":8,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4233,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:51:21.292510746Z 42 PC: 13e51 | Get date 0x13e51: cmp dh, 1
0x13e54: jne 0x13e7d
0x13e56: cmp dl, 7
0x13e59: jae 0x13e7d
0x13e5b: mov di, 0x313
0x13e5e: add di, si
0x13e60: mov al, 0x99
0x13e62: mov cx, 0x95
0x13e65: mov ah, byte ptr [di]
0x13e67: mov dl, ah
0x13e69: xor ah, al
0x13e6b: mov byte ptr [di], ah
0x13e6d: mov al, dl
0x13e6f: inc di
0x13e70: loop 0x13e65
0x13e72: mov ah, 9
0x13e74: mov dx, 0x313
0x13e77: add dx, si
0x13e79: int 0x21
0x13e7b: jmp 0x13e7b
2018-12-25T11:51:21.295064753Z 255 PC: 13e91 | UNKNOWN!
2018-12-25T11:51:21.295782923Z 49 PC: 13ed7 | Terminate and stay resident (Return code = '0' | Memory size = '72')

{"DateBased":true,"Day":1,"Month":2,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4233,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:51:21.537004603Z 42 PC: 13e51 | Get date 0x13e51: cmp dh, 1
0x13e54: jne 0x13e7d
0x13e56: cmp dl, 7
0x13e59: jae 0x13e7d
0x13e5b: mov di, 0x313
0x13e5e: add di, si
0x13e60: mov al, 0x99
0x13e62: mov cx, 0x95
0x13e65: mov ah, byte ptr [di]
0x13e67: mov dl, ah
0x13e69: xor ah, al
0x13e6b: mov byte ptr [di], ah
0x13e6d: mov al, dl
0x13e6f: inc di
0x13e70: loop 0x13e65
0x13e72: mov ah, 9
0x13e74: mov dx, 0x313
0x13e77: add dx, si
0x13e79: int 0x21
0x13e7b: jmp 0x13e7b
2018-12-25T11:51:21.539904533Z 255 PC: 13e91 | UNKNOWN!
2018-12-25T11:51:21.540864414Z 49 PC: 13ed7 | Terminate and stay resident (Return code = '0' | Memory size = '72')