Sample viewer

vx.netlux.org/Virus.DOS.SVC.Piter.1228

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:39:48.334251719Z 131 PC: 13224 | UNKNOWN!
2018-12-17T22:39:48.336091669Z 73 PC: 1325e | Release memory
2018-12-17T22:39:48.337367035Z 72 PC: 13268 | Allocate memory
2018-12-17T22:39:48.339008934Z 74 PC: 13278 | Reallocate memory
2018-12-17T22:39:48.34099732Z 74 PC: 13288 | Reallocate memory
2018-12-17T22:39:48.342727719Z 42 PC: 132b4 | Get date 0x132b4: cmp cx, 0x7c7
0x132b8: jne 0x132c4
0x132ba: cmp dh, 0xc
0x132bd: jne 0x132c4
0x132bf: cmp dl, 0x14
0x132c2: jb 0x132d0
0x132c4: cli
0x132c5: mov word ptr [0x24], 0x126
0x132cb: mov word ptr [0x26], es
0x132cf: sti
0x132d0: pop cx
0x132d1: pop dx
0x132d2: pop ax
0x132d3: pop si
0x132d4: pop es
0x132d5: cld
0x132d6: cmp word ptr cs:[si + 0x482], 0x5a4d
0x132dd: je 0x13300
0x132df: mov di, 0x100
0x132e2: push cs

{"DateBased":true,"Day":1,"Month":12,"Year":1991,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6842,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:00:20.266517394Z 131 PC: 13224 | UNKNOWN!
2018-12-25T12:00:20.268178492Z 73 PC: 1325e | Release memory
2018-12-25T12:00:20.269346479Z 72 PC: 13268 | Allocate memory
2018-12-25T12:00:20.270759353Z 74 PC: 13278 | Reallocate memory
2018-12-25T12:00:20.272108502Z 74 PC: 13288 | Reallocate memory
2018-12-25T12:00:20.273568612Z 42 PC: 132b4 | Get date 0x132b4: cmp cx, 0x7c7
0x132b8: jne 0x132c4
0x132ba: cmp dh, 0xc
0x132bd: jne 0x132c4
0x132bf: cmp dl, 0x14
0x132c2: jb 0x132d0
0x132c4: cli
0x132c5: mov word ptr [0x24], 0x126
0x132cb: mov word ptr [0x26], es
0x132cf: sti
0x132d0: pop cx
0x132d1: pop dx
0x132d2: pop ax
0x132d3: pop si
0x132d4: pop es
0x132d5: cld
0x132d6: cmp word ptr cs:[si + 0x482], 0x5a4d
0x132dd: je 0x13300
0x132df: mov di, 0x100
0x132e2: push cs

{"DateBased":true,"Day":20,"Month":12,"Year":1991,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6842,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:00:21.026692245Z 131 PC: 13224 | UNKNOWN!
2018-12-25T12:00:21.028416274Z 73 PC: 1325e | Release memory
2018-12-25T12:00:21.029734152Z 72 PC: 13268 | Allocate memory
2018-12-25T12:00:21.031221278Z 74 PC: 13278 | Reallocate memory
2018-12-25T12:00:21.032995834Z 74 PC: 13288 | Reallocate memory
2018-12-25T12:00:21.034502373Z 42 PC: 132b4 | Get date 0x132b4: cmp cx, 0x7c7
0x132b8: jne 0x132c4
0x132ba: cmp dh, 0xc
0x132bd: jne 0x132c4
0x132bf: cmp dl, 0x14
0x132c2: jb 0x132d0
0x132c4: cli
0x132c5: mov word ptr [0x24], 0x126
0x132cb: mov word ptr [0x26], es
0x132cf: sti
0x132d0: pop cx
0x132d1: pop dx
0x132d2: pop ax
0x132d3: pop si
0x132d4: pop es
0x132d5: cld
0x132d6: cmp word ptr cs:[si + 0x482], 0x5a4d
0x132dd: je 0x13300
0x132df: mov di, 0x100
0x132e2: push cs

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6842,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:00:21.447876289Z 131 PC: 13224 | UNKNOWN!
2018-12-25T12:00:21.449459406Z 73 PC: 1325e | Release memory
2018-12-25T12:00:21.450944001Z 72 PC: 13268 | Allocate memory
2018-12-25T12:00:21.453149798Z 74 PC: 13278 | Reallocate memory
2018-12-25T12:00:21.45466471Z 74 PC: 13288 | Reallocate memory
2018-12-25T12:00:21.456823255Z 42 PC: 132b4 | Get date 0x132b4: cmp cx, 0x7c7
0x132b8: jne 0x132c4
0x132ba: cmp dh, 0xc
0x132bd: jne 0x132c4
0x132bf: cmp dl, 0x14
0x132c2: jb 0x132d0
0x132c4: cli
0x132c5: mov word ptr [0x24], 0x126
0x132cb: mov word ptr [0x26], es
0x132cf: sti
0x132d0: pop cx
0x132d1: pop dx
0x132d2: pop ax
0x132d3: pop si
0x132d4: pop es
0x132d5: cld
0x132d6: cmp word ptr cs:[si + 0x482], 0x5a4d
0x132dd: je 0x13300
0x132df: mov di, 0x100
0x132e2: push cs

{"DateBased":true,"Day":1,"Month":1,"Year":1991,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6842,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:00:21.52354093Z 131 PC: 13224 | UNKNOWN!
2018-12-25T12:00:21.525352788Z 73 PC: 1325e | Release memory
2018-12-25T12:00:21.526518703Z 72 PC: 13268 | Allocate memory
2018-12-25T12:00:21.528175616Z 74 PC: 13278 | Reallocate memory
2018-12-25T12:00:21.52992128Z 74 PC: 13288 | Reallocate memory
2018-12-25T12:00:21.532254927Z 42 PC: 132b4 | Get date 0x132b4: cmp cx, 0x7c7
0x132b8: jne 0x132c4
0x132ba: cmp dh, 0xc
0x132bd: jne 0x132c4
0x132bf: cmp dl, 0x14
0x132c2: jb 0x132d0
0x132c4: cli
0x132c5: mov word ptr [0x24], 0x126
0x132cb: mov word ptr [0x26], es
0x132cf: sti
0x132d0: pop cx
0x132d1: pop dx
0x132d2: pop ax
0x132d3: pop si
0x132d4: pop es
0x132d5: cld
0x132d6: cmp word ptr cs:[si + 0x482], 0x5a4d
0x132dd: je 0x13300
0x132df: mov di, 0x100
0x132e2: push cs