Sample viewer

vx.netlux.org/Virus.DOS.Kolumna.2048

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:27:47.85997089Z 48 PC: 136a9 | Get DOS version
2018-12-17T22:27:47.86180414Z 42 PC: 136b5 | Get date 0x136b5: cmp dx, 0x10a
0x136b9: jne 0x136c8
0x136bb: mov ax, 0x900
0x136be: mov dx, 0x36d
0x136c1: add dx, si
0x136c3: int 0x21
0x136c5: jmp 0x13702
0x136c7: nop
0x136c8: cmp dx, 0x10b
0x136cc: jne 0x136db
0x136ce: mov ax, 0x900
0x136d1: mov dx, 0x3af
0x136d4: add dx, si
0x136d6: int 0x21
0x136d8: jmp 0x13702
0x136da: nop
0x136db: cmp dx, 0x10c
0x136df: jne 0x136f2
0x136e1: mov dx, 0x634
0x136e4: add dx, si
2018-12-17T22:27:47.865787907Z 240 PC: 13a40 | UNKNOWN!
2018-12-17T22:27:47.867354313Z 53 PC: 13720 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:27:47.869415415Z 37 PC: 1373e | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:27:47.872304727Z 76 PC: 13640 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4948,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:53:16.422533852Z 48 PC: 136a9 | Get DOS version
2018-12-25T11:53:16.424638408Z 42 PC: 136b5 | Get date 0x136b5: cmp dx, 0x10a
0x136b9: jne 0x136c8
0x136bb: mov ax, 0x900
0x136be: mov dx, 0x36d
0x136c1: add dx, si
0x136c3: int 0x21
0x136c5: jmp 0x13702
0x136c7: nop
0x136c8: cmp dx, 0x10b
0x136cc: jne 0x136db
0x136ce: mov ax, 0x900
0x136d1: mov dx, 0x3af
0x136d4: add dx, si
0x136d6: int 0x21
0x136d8: jmp 0x13702
0x136da: nop
0x136db: cmp dx, 0x10c
0x136df: jne 0x136f2
0x136e1: mov dx, 0x634
0x136e4: add dx, si
2018-12-25T11:53:16.426612277Z 240 PC: 13a40 | UNKNOWN!
2018-12-25T11:53:16.427358234Z 53 PC: 13720 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:16.429102451Z 37 PC: 1373e | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:16.43020154Z 76 PC: 13640 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":10,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4948,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:53:16.427441078Z 48 PC: 136a9 | Get DOS version
2018-12-25T11:53:16.429521661Z 42 PC: 136b5 | Get date 0x136b5: cmp dx, 0x10a
0x136b9: jne 0x136c8
0x136bb: mov ax, 0x900
0x136be: mov dx, 0x36d
0x136c1: add dx, si
0x136c3: int 0x21
0x136c5: jmp 0x13702
0x136c7: nop
0x136c8: cmp dx, 0x10b
0x136cc: jne 0x136db
0x136ce: mov ax, 0x900
0x136d1: mov dx, 0x3af
0x136d4: add dx, si
0x136d6: int 0x21
0x136d8: jmp 0x13702
0x136da: nop
0x136db: cmp dx, 0x10c
0x136df: jne 0x136f2
0x136e1: mov dx, 0x634
0x136e4: add dx, si
2018-12-25T11:53:16.432069103Z 9 PC: 136c5 | Display string (String= ' I co teraz doktorku ? ')
2018-12-25T11:53:16.437902735Z 240 PC: 13a40 | UNKNOWN!
2018-12-25T11:53:16.439168904Z 53 PC: 13720 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:16.441690564Z 37 PC: 1373e | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:16.443147456Z 76 PC: 13640 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":11,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4948,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:53:16.795480029Z 48 PC: 136a9 | Get DOS version
2018-12-25T11:53:16.797201652Z 42 PC: 136b5 | Get date 0x136b5: cmp dx, 0x10a
0x136b9: jne 0x136c8
0x136bb: mov ax, 0x900
0x136be: mov dx, 0x36d
0x136c1: add dx, si
0x136c3: int 0x21
0x136c5: jmp 0x13702
0x136c7: nop
0x136c8: cmp dx, 0x10b
0x136cc: jne 0x136db
0x136ce: mov ax, 0x900
0x136d1: mov dx, 0x3af
0x136d4: add dx, si
0x136d6: int 0x21
0x136d8: jmp 0x13702
0x136da: nop
0x136db: cmp dx, 0x10c
0x136df: jne 0x136f2
0x136e1: mov dx, 0x634
0x136e4: add dx, si
2018-12-25T11:53:16.799764748Z 9 PC: 136d8 | Display string (String= '  ������� Robal to ja ! ')
2018-12-25T11:53:16.808287877Z 240 PC: 13a40 | UNKNOWN!
2018-12-25T11:53:16.809371414Z 53 PC: 13720 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:16.811425085Z 37 PC: 1373e | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:16.812844545Z 76 PC: 13640 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":12,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4948,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:53:17.916335669Z 48 PC: 136a9 | Get DOS version
2018-12-25T11:53:17.918461635Z 42 PC: 136b5 | Get date 0x136b5: cmp dx, 0x10a
0x136b9: jne 0x136c8
0x136bb: mov ax, 0x900
0x136be: mov dx, 0x36d
0x136c1: add dx, si
0x136c3: int 0x21
0x136c5: jmp 0x13702
0x136c7: nop
0x136c8: cmp dx, 0x10b
0x136cc: jne 0x136db
0x136ce: mov ax, 0x900
0x136d1: mov dx, 0x3af
0x136d4: add dx, si
0x136d6: int 0x21
0x136d8: jmp 0x13702
0x136da: nop
0x136db: cmp dx, 0x10c
0x136df: jne 0x136f2
0x136e1: mov dx, 0x634
0x136e4: add dx, si
2018-12-25T11:53:17.920663173Z 9 PC: 136eb | Display string (Could not find end pointer)
2018-12-25T11:53:17.940898763Z 7 PC: 136ef | Direct console input without echo

{"DateBased":true,"Day":13,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":4948,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:53:18.016761994Z 48 PC: 136a9 | Get DOS version
2018-12-25T11:53:18.018661741Z 42 PC: 136b5 | Get date 0x136b5: cmp dx, 0x10a
0x136b9: jne 0x136c8
0x136bb: mov ax, 0x900
0x136be: mov dx, 0x36d
0x136c1: add dx, si
0x136c3: int 0x21
0x136c5: jmp 0x13702
0x136c7: nop
0x136c8: cmp dx, 0x10b
0x136cc: jne 0x136db
0x136ce: mov ax, 0x900
0x136d1: mov dx, 0x3af
0x136d4: add dx, si
0x136d6: int 0x21
0x136d8: jmp 0x13702
0x136da: nop
0x136db: cmp dx, 0x10c
0x136df: jne 0x136f2
0x136e1: mov dx, 0x634
0x136e4: add dx, si
2018-12-25T11:53:18.024687029Z 9 PC: 13702 | Display string (String= ' - I co ? - Nie wiem. ')
2018-12-25T11:53:18.03175759Z 240 PC: 13a40 | UNKNOWN!
2018-12-25T11:53:18.032956141Z 53 PC: 13720 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:18.035307911Z 37 PC: 1373e | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:18.036695754Z 76 PC: 13640 | Terminate with return code (Return code = '0')