Sample viewer

vx.netlux.org/Virus.DOS.Cpw.1527

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:33:58.816876342Z 73 PC: 16069 | Release memory
2018-12-17T22:33:58.81869115Z 72 PC: 16070 | Allocate memory
2018-12-17T22:33:58.820633035Z 74 PC: 1607e | Reallocate memory
2018-12-17T22:33:58.82188955Z 74 PC: 1608d | Reallocate memory
2018-12-17T22:33:58.823608366Z 53 PC: 160b7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:33:58.824934652Z 26 PC: 12c79 | Set disk transfer address
2018-12-17T22:33:58.826321211Z 99 PC: 146e6 | Get DBCS lead byte table pointer
2018-12-17T22:33:58.828600118Z 68 PC: 14700 | I/O control for devices (Set for = '')
2018-12-17T22:33:58.829943348Z 68 PC: 1470b | I/O control for devices (Set for = '')
2018-12-17T22:33:58.831889377Z 68 PC: 14716 | I/O control for devices (Set for = '')
2018-12-17T22:33:58.833811454Z 68 PC: 1471e | I/O control for devices (Set for = '��b���g�t�S3����[r�2��W�<t�<u�6�u����>��>W')
2018-12-17T22:33:58.835908632Z 48 PC: 12ec3 | Get DOS version
2018-12-17T22:33:58.837979902Z 64 PC: 1483c | Write file or device (Write 23 bytes on handle 2)
2018-12-17T22:33:58.843390489Z 76 PC: 12ccb | Terminate with return code (Return code = '1')

{"DateBased":true,"Day":28,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6078,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:58:26.152260594Z 73 PC: 16069 | Release memory
2018-12-25T11:58:26.154603533Z 72 PC: 16070 | Allocate memory
2018-12-25T11:58:26.15637845Z 74 PC: 1607e | Reallocate memory
2018-12-25T11:58:26.157750478Z 74 PC: 1608d | Reallocate memory
2018-12-25T11:58:26.159441601Z 53 PC: 160b7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:58:26.161538578Z 26 PC: 12c79 | Set disk transfer address
2018-12-25T11:58:26.163117761Z 99 PC: 146e6 | Get DBCS lead byte table pointer
2018-12-25T11:58:26.164946357Z 68 PC: 14700 | I/O control for devices (Set for = '')
2018-12-25T11:58:26.167099872Z 68 PC: 1470b | I/O control for devices (Set for = '')
2018-12-25T11:58:26.16899148Z 68 PC: 14716 | I/O control for devices (Set for = '')
2018-12-25T11:58:26.170455758Z 68 PC: 1471e | I/O control for devices (Set for = '��b���g�t�S3����[r�2��W�<t�<u�6�u����>��>W')
2018-12-25T11:58:26.173605982Z 48 PC: 12ec3 | Get DOS version
2018-12-25T11:58:26.175525547Z 64 PC: 1483c | Write file or device (Write 23 bytes on handle 2)
2018-12-25T11:58:26.181250853Z 76 PC: 12ccb | Terminate with return code (Return code = '1')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6078,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:58:26.202333517Z 73 PC: 16069 | Release memory
2018-12-25T11:58:26.203992371Z 72 PC: 16070 | Allocate memory
2018-12-25T11:58:26.205853167Z 74 PC: 1607e | Reallocate memory
2018-12-25T11:58:26.207134296Z 74 PC: 1608d | Reallocate memory
2018-12-25T11:58:26.20874312Z 53 PC: 160b7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:58:26.209906844Z 26 PC: 12c79 | Set disk transfer address
2018-12-25T11:58:26.211205898Z 99 PC: 146e6 | Get DBCS lead byte table pointer
2018-12-25T11:58:26.212669595Z 68 PC: 14700 | I/O control for devices (Set for = '')
2018-12-25T11:58:26.214121352Z 68 PC: 1470b | I/O control for devices (Set for = '')
2018-12-25T11:58:26.215645999Z 68 PC: 14716 | I/O control for devices (Set for = '')
2018-12-25T11:58:26.217267248Z 68 PC: 1471e | I/O control for devices (Set for = '��b���g�t�S3����[r�2��W�<t�<u�6�u����>��>W')
2018-12-25T11:58:26.218860725Z 48 PC: 12ec3 | Get DOS version
2018-12-25T11:58:26.220406717Z 64 PC: 1483c | Write file or device (Write 23 bytes on handle 2)
2018-12-25T11:58:26.22520444Z 76 PC: 12ccb | Terminate with return code (Return code = '1')

{"DateBased":true,"Day":27,"Month":5,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6078,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:58:26.68920242Z 73 PC: 16069 | Release memory
2018-12-25T11:58:26.690852995Z 72 PC: 16070 | Allocate memory
2018-12-25T11:58:26.692363873Z 74 PC: 1607e | Reallocate memory
2018-12-25T11:58:26.693497818Z 74 PC: 1608d | Reallocate memory
2018-12-25T11:58:26.695418437Z 53 PC: 160b7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:58:26.696591509Z 26 PC: 12c79 | Set disk transfer address
2018-12-25T11:58:26.697876418Z 99 PC: 146e6 | Get DBCS lead byte table pointer
2018-12-25T11:58:26.699528357Z 68 PC: 14700 | I/O control for devices (Set for = '')
2018-12-25T11:58:26.700964337Z 68 PC: 1470b | I/O control for devices (Set for = '')
2018-12-25T11:58:26.702540197Z 68 PC: 14716 | I/O control for devices (Set for = '')
2018-12-25T11:58:26.704488886Z 68 PC: 1471e | I/O control for devices (Set for = '��b���g�t�S3����[r�2��W�<t�<u�6�u����>��>W')
2018-12-25T11:58:26.706169669Z 48 PC: 12ec3 | Get DOS version
2018-12-25T11:58:26.707703948Z 64 PC: 1483c | Write file or device (Write 23 bytes on handle 2)
2018-12-25T11:58:26.713118821Z 76 PC: 12ccb | Terminate with return code (Return code = '1')

{"DateBased":true,"Day":11,"Month":9,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6078,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:58:26.703211344Z 73 PC: 16069 | Release memory
2018-12-25T11:58:26.705298558Z 72 PC: 16070 | Allocate memory
2018-12-25T11:58:26.706963655Z 74 PC: 1607e | Reallocate memory
2018-12-25T11:58:26.708193438Z 74 PC: 1608d | Reallocate memory
2018-12-25T11:58:26.710100976Z 53 PC: 160b7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:58:26.711567083Z 26 PC: 12c79 | Set disk transfer address
2018-12-25T11:58:26.713005621Z 99 PC: 146e6 | Get DBCS lead byte table pointer
2018-12-25T11:58:26.718791005Z 68 PC: 14700 | I/O control for devices (Set for = '')
2018-12-25T11:58:26.720392056Z 68 PC: 1470b | I/O control for devices (Set for = '')
2018-12-25T11:58:26.722265077Z 68 PC: 14716 | I/O control for devices (Set for = '')
2018-12-25T11:58:26.725018154Z 68 PC: 1471e | I/O control for devices (Set for = '��b���g�t�S3����[r�2��W�<t�<u�6�u����>��>W')
2018-12-25T11:58:26.72658304Z 48 PC: 12ec3 | Get DOS version
2018-12-25T11:58:26.728357245Z 64 PC: 1483c | Write file or device (Write 23 bytes on handle 2)
2018-12-25T11:58:26.735044465Z 76 PC: 12ccb | Terminate with return code (Return code = '1')