Sample viewer

vx.netlux.org/Virus.DOS.Hi.802

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:28:06.956372828Z 53 PC: 19dfc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:28:06.958587132Z 53 PC: 19e09 | Get interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-17T22:28:06.959771854Z 37 PC: 19e19 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:28:06.961007842Z 42 PC: 19e1d | Get date 0x19e1d: cmp al, 4
0x19e1f: jne 0x19e29
0x19e21: mov ax, 0x2517
0x19e24: mov dx, 0xf7
0x19e27: int 0x21
0x19e29: jmp 0x19d86
0x19e2c: add byte ptr [bx + si], al
0x19e2e: add byte ptr [bx + si], al
0x19e30: sbb bx, word ptr [si - 0x4a]
0x19e33: sbb al, bh
0x19e35: inc ax
0x19e36: adc word ptr [bx + si], ax
0x19e38: shr bh, cl
0x19e3a: add al, dh
0x19e3c: push bp
0x19e3d: add word ptr [bx + si], bp
0x19e3f: push cs
0x19e40: xor ax, word ptr [bx]
0x19e42: add byte ptr [bx + di], al
0x19e44: add byte ptr [bx + si], al
2018-12-17T22:28:06.967833851Z 76 PC: 19d70 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5010,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:53:22.845324843Z 53 PC: 19dfc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:22.850687848Z 53 PC: 19e09 | Get interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-25T11:53:22.855633997Z 37 PC: 19e19 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:22.856960718Z 42 PC: 19e1d | Get date 0x19e1d: cmp al, 4
0x19e1f: jne 0x19e29
0x19e21: mov ax, 0x2517
0x19e24: mov dx, 0xf7
0x19e27: int 0x21
0x19e29: jmp 0x19d86
0x19e2c: add byte ptr [bx + si], al
0x19e2e: add byte ptr [bx + si], al
0x19e30: sbb bx, word ptr [si - 0x4a]
0x19e33: sbb al, bh
0x19e35: inc ax
0x19e36: adc word ptr [bx + si], ax
0x19e38: shr bh, cl
0x19e3a: add al, dh
0x19e3c: push bp
0x19e3d: add word ptr [bx + si], bp
0x19e3f: push cs
0x19e40: xor ax, word ptr [bx]
0x19e42: add byte ptr [bx + di], al
0x19e44: add byte ptr [bx + si], al
2018-12-25T11:53:22.881161582Z 76 PC: 19d70 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":3,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5010,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:53:22.943451848Z 53 PC: 19dfc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:22.945371744Z 53 PC: 19e09 | Get interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-25T11:53:22.947286434Z 37 PC: 19e19 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:22.949016026Z 42 PC: 19e1d | Get date 0x19e1d: cmp al, 4
0x19e1f: jne 0x19e29
0x19e21: mov ax, 0x2517
0x19e24: mov dx, 0xf7
0x19e27: int 0x21
0x19e29: jmp 0x19d86
0x19e2c: add byte ptr [bx + si], al
0x19e2e: add byte ptr [bx + si], al
0x19e30: sbb bx, word ptr [si - 0x4a]
0x19e33: sbb al, bh
0x19e35: inc ax
0x19e36: adc word ptr [bx + si], ax
0x19e38: shr bh, cl
0x19e3a: add al, dh
0x19e3c: push bp
0x19e3d: add word ptr [bx + si], bp
0x19e3f: push cs
0x19e40: xor ax, word ptr [bx]
0x19e42: add byte ptr [bx + di], al
0x19e44: add byte ptr [bx + si], al
2018-12-25T11:53:22.952435577Z 37 PC: 19e29 | Set interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-25T11:53:22.957298939Z 76 PC: 19d70 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5010,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:53:23.952362061Z 53 PC: 19dfc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:23.954649407Z 53 PC: 19e09 | Get interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-25T11:53:23.957055368Z 37 PC: 19e19 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:23.959500128Z 42 PC: 19e1d | Get date 0x19e1d: cmp al, 4
0x19e1f: jne 0x19e29
0x19e21: mov ax, 0x2517
0x19e24: mov dx, 0xf7
0x19e27: int 0x21
0x19e29: jmp 0x19d86
0x19e2c: add byte ptr [bx + si], al
0x19e2e: add byte ptr [bx + si], al
0x19e30: sbb bx, word ptr [si - 0x4a]
0x19e33: sbb al, bh
0x19e35: inc ax
0x19e36: adc word ptr [bx + si], ax
0x19e38: shr bh, cl
0x19e3a: add al, dh
0x19e3c: push bp
0x19e3d: add word ptr [bx + si], bp
0x19e3f: push cs
0x19e40: xor ax, word ptr [bx]
0x19e42: add byte ptr [bx + di], al
0x19e44: add byte ptr [bx + si], al
2018-12-25T11:53:23.965860673Z 76 PC: 19d70 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":5,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5010,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:53:26.071079161Z 53 PC: 19dfc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:26.073502684Z 53 PC: 19e09 | Get interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-25T11:53:26.075182129Z 37 PC: 19e19 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:26.076657187Z 42 PC: 19e1d | Get date 0x19e1d: cmp al, 4
0x19e1f: jne 0x19e29
0x19e21: mov ax, 0x2517
0x19e24: mov dx, 0xf7
0x19e27: int 0x21
0x19e29: jmp 0x19d86
0x19e2c: add byte ptr [bx + si], al
0x19e2e: add byte ptr [bx + si], al
0x19e30: sbb bx, word ptr [si - 0x4a]
0x19e33: sbb al, bh
0x19e35: inc ax
0x19e36: adc word ptr [bx + si], ax
0x19e38: shr bh, cl
0x19e3a: add al, dh
0x19e3c: push bp
0x19e3d: add word ptr [bx + si], bp
0x19e3f: push cs
0x19e40: xor ax, word ptr [bx]
0x19e42: add byte ptr [bx + di], al
0x19e44: add byte ptr [bx + si], al
2018-12-25T11:53:26.083950875Z 76 PC: 19d70 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":14,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5010,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:53:27.002191022Z 53 PC: 19dfc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:27.004086912Z 53 PC: 19e09 | Get interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-25T11:53:27.005419846Z 37 PC: 19e19 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:27.006775146Z 42 PC: 19e1d | Get date 0x19e1d: cmp al, 4
0x19e1f: jne 0x19e29
0x19e21: mov ax, 0x2517
0x19e24: mov dx, 0xf7
0x19e27: int 0x21
0x19e29: jmp 0x19d86
0x19e2c: add byte ptr [bx + si], al
0x19e2e: add byte ptr [bx + si], al
0x19e30: sbb bx, word ptr [si - 0x4a]
0x19e33: sbb al, bh
0x19e35: inc ax
0x19e36: adc word ptr [bx + si], ax
0x19e38: shr bh, cl
0x19e3a: add al, dh
0x19e3c: push bp
0x19e3d: add word ptr [bx + si], bp
0x19e3f: push cs
0x19e40: xor ax, word ptr [bx]
0x19e42: add byte ptr [bx + di], al
0x19e44: add byte ptr [bx + si], al
2018-12-25T11:53:27.01315319Z 76 PC: 19d70 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":25,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5010,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:53:27.342964739Z 53 PC: 19dfc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:27.345410319Z 53 PC: 19e09 | Get interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-25T11:53:27.347014372Z 37 PC: 19e19 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:27.348757784Z 42 PC: 19e1d | Get date 0x19e1d: cmp al, 4
0x19e1f: jne 0x19e29
0x19e21: mov ax, 0x2517
0x19e24: mov dx, 0xf7
0x19e27: int 0x21
0x19e29: jmp 0x19d86
0x19e2c: add byte ptr [bx + si], al
0x19e2e: add byte ptr [bx + si], al
0x19e30: sbb bx, word ptr [si - 0x4a]
0x19e33: sbb al, bh
0x19e35: inc ax
0x19e36: adc word ptr [bx + si], ax
0x19e38: shr bh, cl
0x19e3a: add al, dh
0x19e3c: push bp
0x19e3d: add word ptr [bx + si], bp
0x19e3f: push cs
0x19e40: xor ax, word ptr [bx]
0x19e42: add byte ptr [bx + di], al
0x19e44: add byte ptr [bx + si], al
2018-12-25T11:53:27.355874485Z 76 PC: 19d70 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":5,"Month":10,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5010,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:53:27.413864579Z 53 PC: 19dfc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:27.41544112Z 53 PC: 19e09 | Get interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-25T11:53:27.41663556Z 37 PC: 19e19 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:27.417722957Z 42 PC: 19e1d | Get date 0x19e1d: cmp al, 4
0x19e1f: jne 0x19e29
0x19e21: mov ax, 0x2517
0x19e24: mov dx, 0xf7
0x19e27: int 0x21
0x19e29: jmp 0x19d86
0x19e2c: add byte ptr [bx + si], al
0x19e2e: add byte ptr [bx + si], al
0x19e30: sbb bx, word ptr [si - 0x4a]
0x19e33: sbb al, bh
0x19e35: inc ax
0x19e36: adc word ptr [bx + si], ax
0x19e38: shr bh, cl
0x19e3a: add al, dh
0x19e3c: push bp
0x19e3d: add word ptr [bx + si], bp
0x19e3f: push cs
0x19e40: xor ax, word ptr [bx]
0x19e42: add byte ptr [bx + di], al
0x19e44: add byte ptr [bx + si], al
2018-12-25T11:53:27.423717853Z 76 PC: 19d70 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":25,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5010,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:53:27.594528245Z 53 PC: 19dfc | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:27.596448499Z 53 PC: 19e09 | Get interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-25T11:53:27.597637767Z 37 PC: 19e19 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:53:27.59884616Z 42 PC: 19e1d | Get date 0x19e1d: cmp al, 4
0x19e1f: jne 0x19e29
0x19e21: mov ax, 0x2517
0x19e24: mov dx, 0xf7
0x19e27: int 0x21
0x19e29: jmp 0x19d86
0x19e2c: add byte ptr [bx + si], al
0x19e2e: add byte ptr [bx + si], al
0x19e30: sbb bx, word ptr [si - 0x4a]
0x19e33: sbb al, bh
0x19e35: inc ax
0x19e36: adc word ptr [bx + si], ax
0x19e38: shr bh, cl
0x19e3a: add al, dh
0x19e3c: push bp
0x19e3d: add word ptr [bx + si], bp
0x19e3f: push cs
0x19e40: xor ax, word ptr [bx]
0x19e42: add byte ptr [bx + di], al
0x19e44: add byte ptr [bx + si], al
2018-12-25T11:53:27.60214056Z 37 PC: 19e29 | Set interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-25T11:53:27.606354279Z 76 PC: 19d70 | Terminate with return code (Return code = '0')