Sample viewer

vx.netlux.org/Virus.DOS.Joker3.1084

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:31:04.925791242Z 44 PC: 12a5a | Get time 0x12a5a: cmp dl, dh
0x12a5c: je 0x12a60
0x12a5e: jmp 0x12adf
0x12a60: inc dl
0x12a62: xor dh, dh
0x12a64: mov ax, dx
0x12a66: mov dl, 0xa
0x12a68: div dl
0x12a6a: cmp al, 1
0x12a6c: je 0x12a94
0x12a6e: cmp al, 2
0x12a70: je 0x12a9a
0x12a72: cmp al, 3
0x12a74: je 0x12aa0
0x12a76: cmp al, 4
0x12a78: je 0x12aa6
0x12a7a: cmp al, 5
0x12a7c: je 0x12aac
0x12a7e: cmp al, 6
0x12a80: je 0x12ab2
2018-12-17T22:31:04.928708501Z 53 PC: 12b0d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:31:04.932061281Z 37 PC: 12b45 | Set interrupt vector (Interrupt = '33' AKA 'Random read')

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":5555,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:46.212934568Z 44 PC: 12a5a | Get time 0x12a5a: cmp dl, dh
0x12a5c: je 0x12a60
0x12a5e: jmp 0x12adf
0x12a60: inc dl
0x12a62: xor dh, dh
0x12a64: mov ax, dx
0x12a66: mov dl, 0xa
0x12a68: div dl
0x12a6a: cmp al, 1
0x12a6c: je 0x12a94
0x12a6e: cmp al, 2
0x12a70: je 0x12a9a
0x12a72: cmp al, 3
0x12a74: je 0x12aa0
0x12a76: cmp al, 4
0x12a78: je 0x12aa6
0x12a7a: cmp al, 5
0x12a7c: je 0x12aac
0x12a7e: cmp al, 6
0x12a80: je 0x12ab2
2018-12-25T11:54:46.224427564Z 53 PC: 12b0d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:46.227616344Z 37 PC: 12b45 | Set interrupt vector (Interrupt = '33' AKA 'Random read')

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":1,"TimeBased":true,"OriginalID":5555,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:46.273818083Z 44 PC: 12a5a | Get time 0x12a5a: cmp dl, dh
0x12a5c: je 0x12a60
0x12a5e: jmp 0x12adf
0x12a60: inc dl
0x12a62: xor dh, dh
0x12a64: mov ax, dx
0x12a66: mov dl, 0xa
0x12a68: div dl
0x12a6a: cmp al, 1
0x12a6c: je 0x12a94
0x12a6e: cmp al, 2
0x12a70: je 0x12a9a
0x12a72: cmp al, 3
0x12a74: je 0x12aa0
0x12a76: cmp al, 4
0x12a78: je 0x12aa6
0x12a7a: cmp al, 5
0x12a7c: je 0x12aac
0x12a7e: cmp al, 6
0x12a80: je 0x12ab2
2018-12-25T11:54:46.275914188Z 53 PC: 12b0d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:46.278318876Z 37 PC: 12b45 | Set interrupt vector (Interrupt = '33' AKA 'Random read')