Sample viewer

vx.netlux.org/Worm.DOS.Red.1669

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:27:18.206651716Z 74 PC: 12a5a | Reallocate memory
2018-12-17T22:27:18.208519553Z 25 PC: 12a5e | Get default drive
2018-12-17T22:27:18.210177084Z 78 PC: 12a6d | Find first file
2018-12-17T22:27:18.217481978Z 61 PC: 12a78 | Open file (Filename = 'A:RED.COM')
2018-12-17T22:27:18.224963884Z 75 PC: 12b18 | Execute program
2018-12-17T22:27:18.232353729Z 42 PC: 12b1c | Get date 0x12b1c: cmp dh, 0xb
0x12b1f: jb 0x12b29
0x12b21: cmp dl, 0xf
0x12b24: jb 0x12b29
0x12b26: call 0x12d20
0x12b29: mov ah, 0x4c
0x12b2b: int 0x21
0x12b2d: add byte ptr [di], cl
0x12b2f: ja 0x12b9a
0x12b31: outsb dx, byte ptr [si]
0x12b32: or ax, 0x4554
0x12b35: dec bp
0x12b36: push ax
0x12b37: cmp ax, 0x3a43
0x12b3a: pop sp
0x12b3b: push di
0x12b3c: dec cx
0x12b3d: dec si
0x12b3e: inc sp
0x12b3f: dec di
2018-12-17T22:27:18.234861414Z 76 PC: 12b2d | Terminate with return code (Return code = '1')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4851,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:52:59.069639052Z 74 PC: 12a5a | Reallocate memory
2018-12-25T11:52:59.071631971Z 25 PC: 12a5e | Get default drive
2018-12-25T11:52:59.072773908Z 78 PC: 12a6d | Find first file
2018-12-25T11:52:59.077735783Z 61 PC: 12a78 | Open file (Filename = 'A:RED.COM')
2018-12-25T11:52:59.083978468Z 75 PC: 12b18 | Execute program
2018-12-25T11:52:59.090107316Z 42 PC: 12b1c | Get date 0x12b1c: cmp dh, 0xb
0x12b1f: jb 0x12b29
0x12b21: cmp dl, 0xf
0x12b24: jb 0x12b29
0x12b26: call 0x12d20
0x12b29: mov ah, 0x4c
0x12b2b: int 0x21
0x12b2d: add byte ptr [di], cl
0x12b2f: ja 0x12b9a
0x12b31: outsb dx, byte ptr [si]
0x12b32: or ax, 0x4554
0x12b35: dec bp
0x12b36: push ax
0x12b37: cmp ax, 0x3a43
0x12b3a: pop sp
0x12b3b: push di
0x12b3c: dec cx
0x12b3d: dec si
0x12b3e: inc sp
0x12b3f: dec di
2018-12-25T11:52:59.092449534Z 76 PC: 12b2d | Terminate with return code (Return code = '2')

{"DateBased":true,"Day":1,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4851,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:52:59.003866688Z 64 PC: 0 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T11:52:59.010525481Z 41 PC: 94fae | Parse filename
2018-12-25T11:52:59.014940948Z 41 PC: 9502f | Parse filename
2018-12-25T11:52:59.04040071Z 41 PC: 9504c | Parse filename
2018-12-25T11:52:59.043954524Z 26 PC: 984f7 | Set disk transfer address
2018-12-25T11:52:59.046420374Z 71 PC: 986f3 | Get current directory
2018-12-25T11:52:59.050060985Z 78 PC: 986fe | Find first file
2018-12-25T11:52:59.060997567Z 71 PC: 986f3 | Get current directory (See above)
2018-12-25T11:52:59.064204713Z 78 PC: 986fe | Find first file (See above)
2018-12-25T11:52:59.07538842Z 64 PC: 9a848 | Write file or device (Write 26 bytes on handle 2)
2018-12-25T11:52:59.081171223Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T11:52:59.083034818Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:52:59.085354277Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:52:59.087424787Z 62 PC: 122ab | Close file
2018-12-25T11:52:59.089384469Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:52:59.097534797Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:52:59.099608336Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:52:59.101647089Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:52:59.104631432Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:52:59.106317401Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:52:59.108199994Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:52:59.110466686Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:52:59.113427247Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:52:59.115588355Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:52:59.11727831Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:52:59.120400614Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:52:59.121951983Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:52:59.123868241Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:52:59.127434438Z 99 PC: 9a5d7 | Get DBCS lead byte table pointer
2018-12-25T11:52:59.128969518Z 56 PC: 94df9 | Get or set country info
2018-12-25T11:52:59.131008444Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T11:52:59.146485145Z 25 PC: 94e62 | Get default drive
2018-12-25T11:52:59.148503259Z 71 PC: 970dd | Get current directory
2018-12-25T11:52:59.154719123Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T11:52:59.158507411Z 2 PC: 970b2 | Character output (Char = '3e')
2018-12-25T11:52:59.162035373Z 93 PC: 94f20 | File sharing functions
2018-12-25T11:52:59.164279271Z 93 PC: 94f27 | File sharing functions
2018-12-25T11:52:59.166578477Z 10 PC: 94f39 | Buffered keyboard input
2018-12-25T11:53:14.051066598Z 0 PC: 0 | Program terminate (See above)
2018-12-25T11:53:15.412647469Z 0 PC: 0 | Program terminate (See above)
2018-12-25T11:53:15.515178849Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T11:53:15.519283993Z 41 PC: 94fae | Parse filename (See above)
2018-12-25T11:53:15.521383473Z 41 PC: 9502f | Parse filename (See above)
2018-12-25T11:53:15.523709963Z 41 PC: 9504c | Parse filename (See above)
2018-12-25T11:53:15.52724184Z 26 PC: 984f7 | Set disk transfer address (See above)
2018-12-25T11:53:15.529564805Z 71 PC: 986f3 | Get current directory (See above)
2018-12-25T11:53:15.538794294Z 78 PC: 986fe | Find first file (See above)
2018-12-25T11:53:15.549443986Z 71 PC: 9856c | Get current directory
2018-12-25T11:53:15.553921154Z 73 PC: 97c09 | Release memory
2018-12-25T11:53:15.556716759Z 75 PC: 11821 | Execute program
2018-12-25T11:53:15.571869974Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-25T11:53:15.57616953Z 76 PC: 12a4b | Terminate with return code (Return code = '36')

{"DateBased":true,"Day":15,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4851,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:52:59.07372801Z 74 PC: 12a5a | Reallocate memory
2018-12-25T11:52:59.075342873Z 25 PC: 12a5e | Get default drive
2018-12-25T11:52:59.077047195Z 78 PC: 12a6d | Find first file
2018-12-25T11:52:59.08359535Z 61 PC: 12a78 | Open file (Filename = 'A:RED.COM')
2018-12-25T11:52:59.094985762Z 75 PC: 12b18 | Execute program
2018-12-25T11:52:59.102795518Z 42 PC: 12b1c | Get date 0x12b1c: cmp dh, 0xb
0x12b1f: jb 0x12b29
0x12b21: cmp dl, 0xf
0x12b24: jb 0x12b29
0x12b26: call 0x12d20
0x12b29: mov ah, 0x4c
0x12b2b: int 0x21
0x12b2d: add byte ptr [di], cl
0x12b2f: ja 0x12b9a
0x12b31: outsb dx, byte ptr [si]
0x12b32: or ax, 0x4554
0x12b35: dec bp
0x12b36: push ax
0x12b37: cmp ax, 0x3a43
0x12b3a: pop sp
0x12b3b: push di
0x12b3c: dec cx
0x12b3d: dec si
0x12b3e: inc sp
0x12b3f: dec di
2018-12-25T11:52:59.105423335Z 76 PC: 12b2d | Terminate with return code (Return code = '6')