Sample viewer

vx.netlux.org/Virus.DOS.Brezhnev.974

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:25:16.08866363Z 215 PC: 1307a | UNKNOWN!
2018-12-17T22:25:16.090721499Z 53 PC: 13089 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:25:16.093223137Z 53 PC: 13095 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.09573644Z 37 PC: 130d7 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.09830864Z 37 PC: 130ed | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:25:16.10688609Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.109490337Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.112000735Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.119424965Z 37 PC: 130f7 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.121306571Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.123177222Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.125485814Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.126856355Z 42 PC: 130fc | Get date 0x130fc: or al, al
0x130fe: jne 0x13107
0x13100: mov dx, 0x111
0x13103: mov ah, 9
0x13105: int 0x21
0x13107: pop es
0x13108: mov ax, es
0x1310a: add ax, 0x10
0x1310d: add word ptr [0xd6], ax
0x13111: add word ptr [0xd8], ax
0x13115: pop ds
0x13116: pop ax
0x13117: cli
0x13118: mov sp, word ptr cs:[0xda]
0x1311d: mov ss, word ptr cs:[0xd8]
0x13122: sti
0x13123: ljmp 0:0
0x13128: add byte ptr [bx + si], al
0x1312a: add byte ptr [bx + si], al
0x1312c: push bp
2018-12-17T22:25:16.129461801Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.131942497Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.133236701Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.134655764Z 76 PC: 13040 | Terminate with return code (Return code = '0')
2018-12-17T22:25:16.138749819Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.140254289Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.141541637Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.143169756Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:25:16.146088635Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.147949658Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.149729182Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.151993129Z 72 PC: 12174 | Allocate memory
2018-12-17T22:25:16.154494832Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.156338371Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.158736239Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.160157997Z 72 PC: 1218d | Allocate memory
2018-12-17T22:25:16.162787273Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.166032194Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.167347977Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.168674392Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:25:16.175392805Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.177125052Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.178838888Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.180924311Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:25:16.182533108Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.184197502Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.186050874Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.188097378Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:25:16.189781589Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.191569692Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.194476248Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.196086588Z 62 PC: 122ab | Close file
2018-12-17T22:25:16.198257316Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.201114068Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.203247094Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.20498603Z 62 PC: 122ab | Close file
2018-12-17T22:25:16.208168131Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.210327855Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.211904839Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.214272809Z 62 PC: 122ab | Close file
2018-12-17T22:25:16.216467988Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.218135203Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.219923089Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.221634177Z 62 PC: 122ab | Close file
2018-12-17T22:25:16.22366684Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.225311164Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.227667614Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.229031869Z 62 PC: 122ab | Close file
2018-12-17T22:25:16.230735556Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.232981672Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.234683441Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.236299798Z 62 PC: 122ab | Close file
2018-12-17T22:25:16.239813129Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.242011839Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.244348323Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.246417263Z 62 PC: 122ab | Close file
2018-12-17T22:25:16.248751668Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.250687392Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.252641238Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.255778928Z 62 PC: 122ab | Close file
2018-12-17T22:25:16.260471687Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.261888836Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.263232932Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.265349454Z 62 PC: 122ab | Close file
2018-12-17T22:25:16.267233747Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.268625149Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.270485465Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.271729394Z 62 PC: 122ab | Close file
2018-12-17T22:25:16.273453326Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.275596668Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.276961811Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.278401203Z 62 PC: 122ab | Close file
2018-12-17T22:25:16.280970247Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.282708372Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.284149109Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.286677496Z 62 PC: 122ab | Close file
2018-12-17T22:25:16.288451989Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.289726721Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.293917682Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.295649365Z 62 PC: 122ab | Close file
2018-12-17T22:25:16.297747332Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.300459373Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.301747956Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.303900616Z 62 PC: 122ab | Close file
2018-12-17T22:25:16.306082831Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.307678359Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.308899058Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.31061795Z 62 PC: 122ab | Close file
2018-12-17T22:25:16.314241992Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.316073066Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.318171074Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.320382404Z 99 PC: 99e07 | Get DBCS lead byte table pointer
2018-12-17T22:25:16.322862533Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.325086901Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.327122108Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.32912914Z 56 PC: 94629 | Get or set country info
2018-12-17T22:25:16.331899562Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.333848643Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.335483911Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.337295702Z 64 PC: 9a078 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:25:16.342973179Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.344672211Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.34612041Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.348467829Z 25 PC: 94692 | Get default drive
2018-12-17T22:25:16.350572026Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.352173852Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.354828652Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.356836684Z 71 PC: 9690d | Get current directory
2018-12-17T22:25:16.361904092Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.364391125Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.366190295Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.368059316Z 64 PC: 9a078 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:25:16.372601464Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.374421792Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.376129544Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.378409959Z 2 PC: 968e2 | Character output (Char = '3e')
2018-12-17T22:25:16.381396443Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.383192525Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.385207014Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.38696318Z 93 PC: 94750 | File sharing functions
2018-12-17T22:25:16.389309752Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.391445416Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.39294387Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.394306331Z 93 PC: 94757 | File sharing functions
2018-12-17T22:25:16.39768847Z 53 PC: 9f64a | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.399339434Z 25 PC: 9f64a | Get default drive
2018-12-17T22:25:16.401041491Z 37 PC: 9f64a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:25:16.40505666Z 10 PC: 94769 | Buffered keyboard input