Sample viewer

vx.netlux.org/Virus.DOS.Boso.1037

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:29:34.666090897Z 75 PC: 17be2 | Execute program
2018-12-17T22:29:34.668988351Z 26 PC: 17c21 | Set disk transfer address
2018-12-17T22:29:34.670067535Z 53 PC: 17c26 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:29:34.671176683Z 37 PC: 17c37 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:29:34.672940129Z 44 PC: 17c3c | Get time 0x17c3c: cmp ch, 6
0x17c3f: jb 0x17c5b
0x17c41: cmp ch, 0xe
0x17c44: ja 0x17c5b
0x17c46: mov ax, 0x3528
0x17c49: int 0x21
0x17c4b: mov word ptr [0x9b], bx
0x17c4f: mov word ptr [0x9d], es
0x17c53: mov ax, 0x2528
0x17c56: mov dx, 0x29f
0x17c59: int 0x21
0x17c5b: pop es
0x17c5c: pop ds
0x17c5d: cli
0x17c5e: mov ss, word ptr cs:[0x72]
0x17c63: sti
0x17c64: push ds
0x17c65: mov ax, 0x100
0x17c68: push ax
0x17c69: retf
2018-12-17T22:29:34.675558297Z 9 PC: 12a47 | Display string (String= 'This GOAT file was generated by Andreas Marx. ROSEGOAT by RR! (16.08.1998) File: ROSE001.COM - 20.000 (4E20h) bytes length! ')

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":15,"Min":0,"Second":0,"TimeBased":true,"OriginalID":5284,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:05.8666051Z 75 PC: 17be2 | Execute program
2018-12-25T11:54:05.869043532Z 26 PC: 17c21 | Set disk transfer address
2018-12-25T11:54:05.870560888Z 53 PC: 17c26 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:05.871816916Z 37 PC: 17c37 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:05.873828822Z 44 PC: 17c3c | Get time 0x17c3c: cmp ch, 6
0x17c3f: jb 0x17c5b
0x17c41: cmp ch, 0xe
0x17c44: ja 0x17c5b
0x17c46: mov ax, 0x3528
0x17c49: int 0x21
0x17c4b: mov word ptr [0x9b], bx
0x17c4f: mov word ptr [0x9d], es
0x17c53: mov ax, 0x2528
0x17c56: mov dx, 0x29f
0x17c59: int 0x21
0x17c5b: pop es
0x17c5c: pop ds
0x17c5d: cli
0x17c5e: mov ss, word ptr cs:[0x72]
0x17c63: sti
0x17c64: push ds
0x17c65: mov ax, 0x100
0x17c68: push ax
0x17c69: retf
2018-12-25T11:54:05.87674168Z 9 PC: 12a47 | Display string (String= 'This GOAT file was generated by Andreas Marx. ROSEGOAT by RR! (16.08.1998) File: ROSE001.COM - 20.000 (4E20h) bytes length! ')

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":5284,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:06.43935094Z 75 PC: 17be2 | Execute program
2018-12-25T11:54:06.44219204Z 26 PC: 17c21 | Set disk transfer address
2018-12-25T11:54:06.443428776Z 53 PC: 17c26 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:06.444752704Z 37 PC: 17c37 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:06.446279533Z 44 PC: 17c3c | Get time 0x17c3c: cmp ch, 6
0x17c3f: jb 0x17c5b
0x17c41: cmp ch, 0xe
0x17c44: ja 0x17c5b
0x17c46: mov ax, 0x3528
0x17c49: int 0x21
0x17c4b: mov word ptr [0x9b], bx
0x17c4f: mov word ptr [0x9d], es
0x17c53: mov ax, 0x2528
0x17c56: mov dx, 0x29f
0x17c59: int 0x21
0x17c5b: pop es
0x17c5c: pop ds
0x17c5d: cli
0x17c5e: mov ss, word ptr cs:[0x72]
0x17c63: sti
0x17c64: push ds
0x17c65: mov ax, 0x100
0x17c68: push ax
0x17c69: retf
2018-12-25T11:54:06.449924047Z 9 PC: 12a47 | Display string (String= 'This GOAT file was generated by Andreas Marx. ROSEGOAT by RR! (16.08.1998) File: ROSE001.COM - 20.000 (4E20h) bytes length! ')

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":6,"Min":0,"Second":0,"TimeBased":true,"OriginalID":5284,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:07.220337514Z 75 PC: 17be2 | Execute program
2018-12-25T11:54:07.222883908Z 26 PC: 17c21 | Set disk transfer address
2018-12-25T11:54:07.224208653Z 53 PC: 17c26 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:07.225566754Z 37 PC: 17c37 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:07.228137721Z 44 PC: 17c3c | Get time 0x17c3c: cmp ch, 6
0x17c3f: jb 0x17c5b
0x17c41: cmp ch, 0xe
0x17c44: ja 0x17c5b
0x17c46: mov ax, 0x3528
0x17c49: int 0x21
0x17c4b: mov word ptr [0x9b], bx
0x17c4f: mov word ptr [0x9d], es
0x17c53: mov ax, 0x2528
0x17c56: mov dx, 0x29f
0x17c59: int 0x21
0x17c5b: pop es
0x17c5c: pop ds
0x17c5d: cli
0x17c5e: mov ss, word ptr cs:[0x72]
0x17c63: sti
0x17c64: push ds
0x17c65: mov ax, 0x100
0x17c68: push ax
0x17c69: retf
2018-12-25T11:54:07.230915024Z 53 PC: 17c4b | Get interrupt vector (Interrupt = '40' AKA 'Random block write')
2018-12-25T11:54:07.232338705Z 37 PC: 17c5b | Set interrupt vector (Interrupt = '40' AKA 'Random block write')
2018-12-25T11:54:07.233774352Z 9 PC: 12a47 | Display string (String= 'This GOAT file was generated by Andreas Marx. ROSEGOAT by RR! (16.08.1998) File: ROSE001.COM - 20.000 (4E20h) bytes length! ')