Sample viewer

vx.netlux.org/Virus.DOS.Squatter.8019

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:31:23.521821725Z 48 PC: 12b54 | Get DOS version
2018-12-17T22:31:23.523545764Z 82 PC: 12b62 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:31:23.527919906Z 53 PC: 12bfd | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:31:23.529098525Z 47 PC: 9ba5c | Get disk transfer address
2018-12-17T22:31:23.530550677Z 53 PC: 9ba6e | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:31:23.532549758Z 48 PC: 9ba9e | Get DOS version
2018-12-17T22:31:23.534527585Z 42 PC: 9c731 | Get date 0x9c731: pushf
0x9c732: cmp byte ptr cs:[0x1f5b], 3
0x9c738: je 0x9c73c
0x9c73a: popf
0x9c73b: ret
0x9c73c: popf
0x9c73d: stc
0x9c73e: ret
0x9c73f: mov ax, word ptr es:[di + 0x20]
0x9c743: cmp ax, 0x4843
0x9c746: jne 0x9c758
0x9c748: cmp word ptr es:[di + 0x22], 0x444b
0x9c74e: jne 0x9c758
0x9c750: cmp word ptr es:[di + 0x24], 0x4b53
0x9c756: je 0x9c781
0x9c758: cmp ax, 0x4b50
0x9c75b: je 0x9c781
0x9c75d: cmp ax, 0x5241
0x9c760: jne 0x9c769
0x9c762: cmp byte ptr es:[di + 0x22], 0x4a
2018-12-17T22:31:23.536882422Z 76 PC: 12a45 | Terminate with return code (Return code = '0')
2018-12-17T22:31:23.540724361Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:31:23.542285719Z 72 PC: 12174 | Allocate memory
2018-12-17T22:31:23.544291358Z 72 PC: 1218d | Allocate memory
2018-12-17T22:31:23.547341273Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:31:23.549743031Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T22:31:23.553702029Z 2 PC: 1268d | Character output (Char = '4d')
2018-12-17T22:31:23.556461631Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:31:23.559211985Z 2 PC: 1268d | Character output (Char = '6d')
2018-12-17T22:31:23.561615218Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:31:23.564738438Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:31:23.567329985Z 2 PC: 1268d | Character output (Char = '79')
2018-12-17T22:31:23.56965786Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:31:23.572171215Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:31:23.575144788Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:31:23.577565195Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:31:23.579840934Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:31:23.582907749Z 2 PC: 1268d | Character output (Char = '63')
2018-12-17T22:31:23.585571813Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:31:23.588057025Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:31:23.590870996Z 2 PC: 1268d | Character output (Char = '69')
2018-12-17T22:31:23.594017744Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:31:23.596154274Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:31:23.599097699Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:31:23.601877425Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:31:23.604666555Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:31:23.607686696Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:31:23.610400666Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:31:23.612900389Z 2 PC: 1268d | Character output (Char = '72')
2018-12-17T22:31:23.615866152Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:31:23.621169286Z 2 PC: 1268d | Character output (Char = '0a')
2018-12-17T22:31:23.625267637Z 2 PC: 1268d | Character output (Char = '43')
2018-12-17T22:31:23.628573538Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:31:23.630879892Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:31:23.633158247Z 2 PC: 1268d | Character output (Char = '6e')
2018-12-17T22:31:23.63549667Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:31:23.638258991Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:31:23.640602705Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:31:23.642830437Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:31:23.645346413Z 2 PC: 1268d | Character output (Char = '6f')
2018-12-17T22:31:23.647694622Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:31:23.650012252Z 2 PC: 1268d | Character output (Char = '64')
2018-12-17T22:31:23.653356092Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:31:23.655923079Z 2 PC: 1268d | Character output (Char = '43')
2018-12-17T22:31:23.660022899Z 2 PC: 1268d | Character output (Char = '4f')
2018-12-17T22:31:23.663758272Z 2 PC: 1268d | Character output (Char = '4d')
2018-12-17T22:31:23.667430286Z 2 PC: 1268d | Character output (Char = '4d')
2018-12-17T22:31:23.669957339Z 2 PC: 1268d | Character output (Char = '41')
2018-12-17T22:31:23.672783304Z 2 PC: 1268d | Character output (Char = '4e')
2018-12-17T22:31:23.675605999Z 2 PC: 1268d | Character output (Char = '44')
2018-12-17T22:31:23.678005961Z 2 PC: 1268d | Character output (Char = '2c')
2018-12-17T22:31:23.681212895Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:31:23.683537966Z 2 PC: 1268d | Character output (Char = '73')
2018-12-17T22:31:23.68666822Z 2 PC: 1268d | Character output (Char = '79')
2018-12-17T22:31:23.689762802Z 2 PC: 1268d | Character output (Char = '73')
2018-12-17T22:31:23.692853119Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:31:23.695230468Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:31:23.697437696Z 2 PC: 1268d | Character output (Char = '6d')
2018-12-17T22:31:23.702762676Z 2 PC: 1268d | Character output (Char = '20')
2018-12-17T22:31:23.705102762Z 2 PC: 1268d | Character output (Char = '68')
2018-12-17T22:31:23.707556003Z 2 PC: 1268d | Character output (Char = '61')
2018-12-17T22:31:23.711621096Z 2 PC: 1268d | Character output (Char = '6c')
2018-12-17T22:31:23.713837312Z 2 PC: 1268d | Character output (Char = '74')
2018-12-17T22:31:23.725186779Z 2 PC: 1268d | Character output (Char = '65')
2018-12-17T22:31:23.728071151Z 2 PC: 1268d | Character output (Char = '64')
2018-12-17T22:31:23.730916215Z 2 PC: 1268d | Character output (Char = '0d')
2018-12-17T22:31:23.733205905Z 2 PC: 1268d | Character output (Char = '0a')