Sample viewer

vx.netlux.org/Virus.DOS.HappyNewYear.556

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:34:31.521879478Z 82 PC: 18307 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:34:31.523560742Z 98 PC: 1834a | Get current PSP
2018-12-17T22:34:31.524468384Z 53 PC: 18377 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:34:31.525575714Z 37 PC: 18390 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:34:31.527620263Z 48 PC: 15d44 | Get DOS version
2018-12-17T22:34:31.529587205Z 9 PC: 15d58 | Display string (Could not find end pointer)
2018-12-17T22:34:31.549843229Z 53 PC: 15dfe | Get interrupt vector (Interrupt = '51' AKA 'Get or set Ctrl-Break')
2018-12-17T22:34:31.561211147Z 53 PC: 15e0b | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:34:31.563012395Z 53 PC: 15e20 | Get interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:34:31.565692509Z 53 PC: 15e32 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:34:31.566871389Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-17T22:34:31.568540244Z 53 PC: 15e54 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:34:31.573374555Z 37 PC: 1c61e | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:34:31.574775962Z 37 PC: 1c62c | Set interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-17T22:34:31.576523307Z 37 PC: 1c63a | Set interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:34:31.577637314Z 37 PC: 1c656 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:34:31.579056257Z 37 PC: 13069 | Set interrupt vector (Interrupt = '68' AKA 'I/O control for devices')
2018-12-17T22:34:31.581627626Z 37 PC: 1308e | Set interrupt vector (Interrupt = '31' AKA 'Get disk parameter block for default drive')
2018-12-17T22:34:31.584865507Z 73 PC: 156ae | Release memory
2018-12-17T22:34:31.586327148Z 49 PC: 156b1 | Terminate and stay resident (Return code = '0' | Memory size = '726')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6181,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:58:46.002172655Z 82 PC: 18307 | Get DOS internal pointers (SYSVARS)
2018-12-25T11:58:46.003850363Z 98 PC: 1834a | Get current PSP
2018-12-25T11:58:46.004840213Z 53 PC: 18377 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:58:46.006085119Z 37 PC: 18390 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:58:46.007584106Z 48 PC: 15d44 | Get DOS version
2018-12-25T11:58:46.008704945Z 9 PC: 15d58 | Display string (Could not find end pointer)
2018-12-25T11:58:46.02135553Z 53 PC: 15dfe | Get interrupt vector (Interrupt = '51' AKA 'Get or set Ctrl-Break')
2018-12-25T11:58:46.022508485Z 53 PC: 15e0b | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T11:58:46.024306688Z 53 PC: 15e20 | Get interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-25T11:58:46.026084931Z 53 PC: 15e32 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-25T11:58:46.027168045Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-25T11:58:46.028577484Z 53 PC: 15e54 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T11:58:46.031630127Z 37 PC: 1c61e | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T11:58:46.032461556Z 37 PC: 1c62c | Set interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-25T11:58:46.034329471Z 37 PC: 1c63a | Set interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-25T11:58:46.035227269Z 37 PC: 1c656 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T11:58:46.036080907Z 37 PC: 13069 | Set interrupt vector (Interrupt = '68' AKA 'I/O control for devices')
2018-12-25T11:58:46.045213669Z 37 PC: 1308e | Set interrupt vector (Interrupt = '31' AKA 'Get disk parameter block for default drive')
2018-12-25T11:58:46.0472663Z 73 PC: 156ae | Release memory
2018-12-25T11:58:46.0482622Z 49 PC: 156b1 | Terminate and stay resident (Return code = '0' | Memory size = '726')

{"DateBased":true,"Day":1,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6181,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:58:46.272914519Z 82 PC: 18307 | Get DOS internal pointers (SYSVARS)
2018-12-25T11:58:46.274985213Z 98 PC: 1834a | Get current PSP
2018-12-25T11:58:46.276236561Z 53 PC: 18377 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:58:46.27795605Z 37 PC: 18390 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:58:46.280160143Z 48 PC: 15d44 | Get DOS version
2018-12-25T11:58:46.281425554Z 9 PC: 15d58 | Display string (Could not find end pointer)
2018-12-25T11:58:46.305178951Z 53 PC: 15dfe | Get interrupt vector (Interrupt = '51' AKA 'Get or set Ctrl-Break')
2018-12-25T11:58:46.307198583Z 53 PC: 15e0b | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T11:58:46.308872805Z 53 PC: 15e20 | Get interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-25T11:58:46.311319128Z 53 PC: 15e32 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-25T11:58:46.312685895Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-25T11:58:46.3144648Z 53 PC: 15e54 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T11:58:46.320734898Z 37 PC: 1c61e | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T11:58:46.321979674Z 37 PC: 1c62c | Set interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-25T11:58:46.323833369Z 37 PC: 1c63a | Set interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-25T11:58:46.325255229Z 37 PC: 1c656 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T11:58:46.326685372Z 37 PC: 13069 | Set interrupt vector (Interrupt = '68' AKA 'I/O control for devices')
2018-12-25T11:58:46.328926771Z 37 PC: 1308e | Set interrupt vector (Interrupt = '31' AKA 'Get disk parameter block for default drive')
2018-12-25T11:58:46.332603174Z 73 PC: 156ae | Release memory
2018-12-25T11:58:46.334191399Z 49 PC: 156b1 | Terminate and stay resident (Return code = '0' | Memory size = '726')

{"DateBased":true,"Day":3,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6181,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:58:46.548597341Z 82 PC: 18307 | Get DOS internal pointers (SYSVARS)
2018-12-25T11:58:46.55082127Z 98 PC: 1834a | Get current PSP
2018-12-25T11:58:46.551689616Z 53 PC: 18377 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:58:46.552659728Z 37 PC: 18390 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:58:46.555873582Z 48 PC: 15d44 | Get DOS version
2018-12-25T11:58:46.558673991Z 9 PC: 15d58 | Display string (Could not find end pointer)
2018-12-25T11:58:46.578557919Z 53 PC: 15dfe | Get interrupt vector (Interrupt = '51' AKA 'Get or set Ctrl-Break')
2018-12-25T11:58:46.581010417Z 53 PC: 15e0b | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T11:58:46.582119225Z 53 PC: 15e20 | Get interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-25T11:58:46.584253144Z 53 PC: 15e32 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-25T11:58:46.586619545Z 53 PC: 15e3f | Get interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-25T11:58:46.588477521Z 53 PC: 15e54 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T11:58:46.593504244Z 37 PC: 1c61e | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T11:58:46.595462639Z 37 PC: 1c62c | Set interrupt vector (Interrupt = '47' AKA 'Get disk transfer address')
2018-12-25T11:58:46.597182651Z 37 PC: 1c63a | Set interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-25T11:58:46.598581805Z 37 PC: 1c656 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T11:58:46.600676061Z 37 PC: 13069 | Set interrupt vector (Interrupt = '68' AKA 'I/O control for devices')
2018-12-25T11:58:46.602552142Z 37 PC: 1308e | Set interrupt vector (Interrupt = '31' AKA 'Get disk parameter block for default drive')
2018-12-25T11:58:46.605727362Z 73 PC: 156ae | Release memory
2018-12-25T11:58:46.607232573Z 49 PC: 156b1 | Terminate and stay resident (Return code = '0' | Memory size = '726')