Sample viewer

vx.netlux.org/Virus.DOS.Gdog.Baron.2000.c

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:26:43.357550348Z 77 PC: 12a51 | Get program return code
2018-12-17T22:26:43.359451666Z 82 PC: 12a79 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:26:43.361581356Z 53 PC: 12a83 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:26:43.363021978Z 74 PC: 12aa8 | Reallocate memory
2018-12-17T22:26:43.365497655Z 72 PC: 12aae | Allocate memory
2018-12-17T22:26:43.369105137Z 37 PC: 12ad2 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:26:43.371268476Z 42 PC: 12ada | Get date 0x12ada: cmp dx, 0x80a
0x12ade: jne 0x12b32
0x12ae0: mov ax, 0xa000
0x12ae3: mov es, ax
0x12ae5: mov ax, 0x13
0x12ae8: int 0x10
0x12aea: mov di, 0x58c
0x12aed: mov cx, 0xc4
0x12af0: push cx
0x12af1: mov cx, 0x14
0x12af4: mov byte ptr es:[di], al
0x12af7: inc di
0x12af8: loop 0x12af4
0x12afa: add di, 0x12c
0x12afe: pop cx
0x12aff: loop 0x12af0
0x12b01: mov di, 0xbbc6
0x12b04: mov cx, 0x12
0x12b07: push cx
0x12b08: mov cx, 0xa0

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4746,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:52:47.023365897Z 77 PC: 12a51 | Get program return code
2018-12-25T11:52:47.025610191Z 82 PC: 12a79 | Get DOS internal pointers (SYSVARS)
2018-12-25T11:52:47.028052938Z 53 PC: 12a83 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:52:47.029889763Z 74 PC: 12aa8 | Reallocate memory
2018-12-25T11:52:47.031798816Z 72 PC: 12aae | Allocate memory
2018-12-25T11:52:47.036876086Z 37 PC: 12ad2 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:52:47.038261809Z 42 PC: 12ada | Get date 0x12ada: cmp dx, 0x80a
0x12ade: jne 0x12b32
0x12ae0: mov ax, 0xa000
0x12ae3: mov es, ax
0x12ae5: mov ax, 0x13
0x12ae8: int 0x10
0x12aea: mov di, 0x58c
0x12aed: mov cx, 0xc4
0x12af0: push cx
0x12af1: mov cx, 0x14
0x12af4: mov byte ptr es:[di], al
0x12af7: inc di
0x12af8: loop 0x12af4
0x12afa: add di, 0x12c
0x12afe: pop cx
0x12aff: loop 0x12af0
0x12b01: mov di, 0xbbc6
0x12b04: mov cx, 0x12
0x12b07: push cx
0x12b08: mov cx, 0xa0

{"DateBased":true,"Day":10,"Month":8,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4746,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:52:47.275324829Z 77 PC: 12a51 | Get program return code
2018-12-25T11:52:47.277546346Z 82 PC: 12a79 | Get DOS internal pointers (SYSVARS)
2018-12-25T11:52:47.278983912Z 53 PC: 12a83 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:52:47.281637112Z 74 PC: 12aa8 | Reallocate memory
2018-12-25T11:52:47.28427224Z 72 PC: 12aae | Allocate memory
2018-12-25T11:52:47.293509014Z 37 PC: 12ad2 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:52:47.312602101Z 42 PC: 12ada | Get date 0x12ada: cmp dx, 0x80a
0x12ade: jne 0x12b32
0x12ae0: mov ax, 0xa000
0x12ae3: mov es, ax
0x12ae5: mov ax, 0x13
0x12ae8: int 0x10
0x12aea: mov di, 0x58c
0x12aed: mov cx, 0xc4
0x12af0: push cx
0x12af1: mov cx, 0x14
0x12af4: mov byte ptr es:[di], al
0x12af7: inc di
0x12af8: loop 0x12af4
0x12afa: add di, 0x12c
0x12afe: pop cx
0x12aff: loop 0x12af0
0x12b01: mov di, 0xbbc6
0x12b04: mov cx, 0x12
0x12b07: push cx
0x12b08: mov cx, 0xa0
2018-12-25T11:52:47.323970248Z 9 PC: 12b20 | Display string (Could not find end pointer)