Sample viewer

vx.netlux.org/Virus.DOS.Andreew.805

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:28:07.787548848Z 249 PC: 12b0c | UNKNOWN!
2018-12-17T22:28:07.789038243Z 44 PC: 12b94 | Get time 0x12b94: cmp cl, dh
0x12b96: jne 0x12bce
0x12b98: mov dx, 0x9f
0x12b9b: add dx, bx
0x12b9d: mov ah, 9
0x12b9f: int 0x21
0x12ba1: mov ah, 0x2a
0x12ba3: int 0x21
0x12ba5: cmp dh, 7
0x12ba8: jbe 0x12bce
0x12baa: mov al, 2
0x12bac: mov cx, 1
0x12baf: xor dx, dx
0x12bb1: add bx, 0x353
0x12bb5: mov si, bx
0x12bb7: push cs
0x12bb8: pop ds
0x12bb9: int 0x25
0x12bbb: jb 0x12bcd
0x12bbd: popf

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":5015,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:53:28.476181681Z 249 PC: 12b0c | UNKNOWN!
2018-12-25T11:53:28.489726132Z 44 PC: 12b94 | Get time 0x12b94: cmp cl, dh
0x12b96: jne 0x12bce
0x12b98: mov dx, 0x9f
0x12b9b: add dx, bx
0x12b9d: mov ah, 9
0x12b9f: int 0x21
0x12ba1: mov ah, 0x2a
0x12ba3: int 0x21
0x12ba5: cmp dh, 7
0x12ba8: jbe 0x12bce
0x12baa: mov al, 2
0x12bac: mov cx, 1
0x12baf: xor dx, dx
0x12bb1: add bx, 0x353
0x12bb5: mov si, bx
0x12bb7: push cs
0x12bb8: pop ds
0x12bb9: int 0x25
0x12bbb: jb 0x12bcd
0x12bbd: popf

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":1,"TimeBased":true,"OriginalID":5015,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:53:28.599045143Z 249 PC: 12b0c | UNKNOWN!
2018-12-25T11:53:28.600413323Z 44 PC: 12b94 | Get time 0x12b94: cmp cl, dh
0x12b96: jne 0x12bce
0x12b98: mov dx, 0x9f
0x12b9b: add dx, bx
0x12b9d: mov ah, 9
0x12b9f: int 0x21
0x12ba1: mov ah, 0x2a
0x12ba3: int 0x21
0x12ba5: cmp dh, 7
0x12ba8: jbe 0x12bce
0x12baa: mov al, 2
0x12bac: mov cx, 1
0x12baf: xor dx, dx
0x12bb1: add bx, 0x353
0x12bb5: mov si, bx
0x12bb7: push cs
0x12bb8: pop ds
0x12bb9: int 0x25
0x12bbb: jb 0x12bcd
0x12bbd: popf