Sample viewer

vx.netlux.org/Virus.DOS.Cascade.1701.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:24:57.418458274Z 48 PC: 12b0d | Get DOS version
2018-12-17T22:24:57.421115055Z 75 PC: 12b1b | Execute program
2018-12-17T22:24:57.424096437Z 53 PC: 12b36 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:24:57.426238286Z 80 PC: 12b9d | Set current PSP
2018-12-17T22:24:57.427979898Z 37 PC: 12bdc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:24:57.430813513Z 26 PC: 12be4 | Set disk transfer address
2018-12-17T22:24:57.432477609Z 42 PC: 12beb | Get date 0x12beb: cmp cx, 0x7c4
0x12bef: ja 0x12c56
0x12bf1: je 0x12c1d
0x12bf3: cmp cx, 0x7bc
0x12bf7: jne 0x12c56
0x12bf9: push ds
0x12bfa: mov ax, 0x3528
0x12bfd: int 0x21
0x12bff: mov word ptr cs:[0x13b], bx
0x12c04: mov word ptr cs:[0x13d], es
0x12c09: mov ax, 0x2528
0x12c0c: mov dx, 0x722
0x12c0f: push cs
0x12c10: pop ds
0x12c11: int 0x21
0x12c13: pop ds
0x12c14: or byte ptr cs:[0x157], 8
0x12c1a: jmp 0x12c22
0x12c1c: nop
0x12c1d: cmp dh, 0xa
2018-12-17T22:24:57.43514709Z 64 PC: 1322a | Write file or device (Write 26 bytes on handle 1)
2018-12-17T22:24:57.442327115Z 76 PC: 13230 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":10,"Year":1988,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4404,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:51:38.119209308Z 48 PC: 12b0d | Get DOS version
2018-12-25T11:51:38.121348268Z 75 PC: 12b1b | Execute program
2018-12-25T11:51:38.122706852Z 53 PC: 12b36 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:51:38.123767112Z 80 PC: 12b9d | Set current PSP
2018-12-25T11:51:38.125772854Z 37 PC: 12bdc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:51:38.126996496Z 26 PC: 12be4 | Set disk transfer address
2018-12-25T11:51:38.12805341Z 42 PC: 12beb | Get date 0x12beb: cmp cx, 0x7c4
0x12bef: ja 0x12c56
0x12bf1: je 0x12c1d
0x12bf3: cmp cx, 0x7bc
0x12bf7: jne 0x12c56
0x12bf9: push ds
0x12bfa: mov ax, 0x3528
0x12bfd: int 0x21
0x12bff: mov word ptr cs:[0x13b], bx
0x12c04: mov word ptr cs:[0x13d], es
0x12c09: mov ax, 0x2528
0x12c0c: mov dx, 0x722
0x12c0f: push cs
0x12c10: pop ds
0x12c11: int 0x21
0x12c13: pop ds
0x12c14: or byte ptr cs:[0x157], 8
0x12c1a: jmp 0x12c22
0x12c1c: nop
0x12c1d: cmp dh, 0xa
2018-12-25T11:51:38.184747288Z 53 PC: 12c40 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T11:51:38.186041681Z 37 PC: 12c55 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T11:51:38.187204946Z 64 PC: 1322a | Write file or device (Write 26 bytes on handle 1)
2018-12-25T11:51:38.195328901Z 76 PC: 13230 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1989,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4404,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:51:38.563935837Z 48 PC: 12b0d | Get DOS version
2018-12-25T11:51:38.566519195Z 75 PC: 12b1b | Execute program
2018-12-25T11:51:38.567994871Z 53 PC: 12b36 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:51:38.569166838Z 80 PC: 12b9d | Set current PSP
2018-12-25T11:51:38.572873087Z 37 PC: 12bdc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:51:38.574092822Z 26 PC: 12be4 | Set disk transfer address
2018-12-25T11:51:38.575263298Z 42 PC: 12beb | Get date 0x12beb: cmp cx, 0x7c4
0x12bef: ja 0x12c56
0x12bf1: je 0x12c1d
0x12bf3: cmp cx, 0x7bc
0x12bf7: jne 0x12c56
0x12bf9: push ds
0x12bfa: mov ax, 0x3528
0x12bfd: int 0x21
0x12bff: mov word ptr cs:[0x13b], bx
0x12c04: mov word ptr cs:[0x13d], es
0x12c09: mov ax, 0x2528
0x12c0c: mov dx, 0x722
0x12c0f: push cs
0x12c10: pop ds
0x12c11: int 0x21
0x12c13: pop ds
0x12c14: or byte ptr cs:[0x157], 8
0x12c1a: jmp 0x12c22
0x12c1c: nop
0x12c1d: cmp dh, 0xa
2018-12-25T11:51:38.578439928Z 64 PC: 1322a | Write file or device (Write 26 bytes on handle 1)
2018-12-25T11:51:38.584697291Z 76 PC: 13230 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4404,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:51:38.971902281Z 48 PC: 12b0d | Get DOS version
2018-12-25T11:51:38.973754196Z 75 PC: 12b1b | Execute program
2018-12-25T11:51:38.975392355Z 53 PC: 12b36 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:51:38.976532758Z 80 PC: 12b9d | Set current PSP
2018-12-25T11:51:38.977761039Z 37 PC: 12bdc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:51:38.97948979Z 26 PC: 12be4 | Set disk transfer address
2018-12-25T11:51:38.980559214Z 42 PC: 12beb | Get date 0x12beb: cmp cx, 0x7c4
0x12bef: ja 0x12c56
0x12bf1: je 0x12c1d
0x12bf3: cmp cx, 0x7bc
0x12bf7: jne 0x12c56
0x12bf9: push ds
0x12bfa: mov ax, 0x3528
0x12bfd: int 0x21
0x12bff: mov word ptr cs:[0x13b], bx
0x12c04: mov word ptr cs:[0x13d], es
0x12c09: mov ax, 0x2528
0x12c0c: mov dx, 0x722
0x12c0f: push cs
0x12c10: pop ds
0x12c11: int 0x21
0x12c13: pop ds
0x12c14: or byte ptr cs:[0x157], 8
0x12c1a: jmp 0x12c22
0x12c1c: nop
0x12c1d: cmp dh, 0xa
2018-12-25T11:51:38.98258873Z 53 PC: 12bff | Get interrupt vector (Interrupt = '40' AKA 'Random block write')
2018-12-25T11:51:38.984530348Z 37 PC: 12c13 | Set interrupt vector (Interrupt = '40' AKA 'Random block write')
2018-12-25T11:51:39.048935668Z 53 PC: 12c40 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T11:51:39.050361249Z 37 PC: 12c55 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T11:51:39.05228891Z 64 PC: 1322a | Write file or device (Write 26 bytes on handle 1)
2018-12-25T11:51:39.057181964Z 76 PC: 13230 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1981,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4404,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:51:39.281333114Z 48 PC: 12b0d | Get DOS version
2018-12-25T11:51:39.282840991Z 75 PC: 12b1b | Execute program
2018-12-25T11:51:39.284166057Z 53 PC: 12b36 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:51:39.285264927Z 80 PC: 12b9d | Set current PSP
2018-12-25T11:51:39.287486308Z 37 PC: 12bdc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:51:39.288537129Z 26 PC: 12be4 | Set disk transfer address
2018-12-25T11:51:39.289613492Z 42 PC: 12beb | Get date 0x12beb: cmp cx, 0x7c4
0x12bef: ja 0x12c56
0x12bf1: je 0x12c1d
0x12bf3: cmp cx, 0x7bc
0x12bf7: jne 0x12c56
0x12bf9: push ds
0x12bfa: mov ax, 0x3528
0x12bfd: int 0x21
0x12bff: mov word ptr cs:[0x13b], bx
0x12c04: mov word ptr cs:[0x13d], es
0x12c09: mov ax, 0x2528
0x12c0c: mov dx, 0x722
0x12c0f: push cs
0x12c10: pop ds
0x12c11: int 0x21
0x12c13: pop ds
0x12c14: or byte ptr cs:[0x157], 8
0x12c1a: jmp 0x12c22
0x12c1c: nop
0x12c1d: cmp dh, 0xa
2018-12-25T11:51:39.291940689Z 64 PC: 1322a | Write file or device (Write 26 bytes on handle 1)
2018-12-25T11:51:39.298157073Z 76 PC: 13230 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1988,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4404,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:51:39.463002271Z 48 PC: 12b0d | Get DOS version
2018-12-25T11:51:39.465277136Z 75 PC: 12b1b | Execute program
2018-12-25T11:51:39.467805924Z 53 PC: 12b36 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:51:39.469578282Z 80 PC: 12b9d | Set current PSP
2018-12-25T11:51:39.471892094Z 37 PC: 12bdc | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:51:39.473425852Z 26 PC: 12be4 | Set disk transfer address
2018-12-25T11:51:39.474593041Z 42 PC: 12beb | Get date 0x12beb: cmp cx, 0x7c4
0x12bef: ja 0x12c56
0x12bf1: je 0x12c1d
0x12bf3: cmp cx, 0x7bc
0x12bf7: jne 0x12c56
0x12bf9: push ds
0x12bfa: mov ax, 0x3528
0x12bfd: int 0x21
0x12bff: mov word ptr cs:[0x13b], bx
0x12c04: mov word ptr cs:[0x13d], es
0x12c09: mov ax, 0x2528
0x12c0c: mov dx, 0x722
0x12c0f: push cs
0x12c10: pop ds
0x12c11: int 0x21
0x12c13: pop ds
0x12c14: or byte ptr cs:[0x157], 8
0x12c1a: jmp 0x12c22
0x12c1c: nop
0x12c1d: cmp dh, 0xa
2018-12-25T11:51:39.477413419Z 64 PC: 1322a | Write file or device (Write 26 bytes on handle 1)
2018-12-25T11:51:39.487016899Z 76 PC: 13230 | Terminate with return code (Return code = '0')