Sample viewer

vx.netlux.org/Virus.DOS.Cascade.1621

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:15:37.170592961Z 48 PC: 12bcf | Get DOS version
2018-12-17T23:15:37.172298504Z 75 PC: 12bdd | Execute program
2018-12-17T23:15:37.173615757Z 53 PC: 12c0f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:15:37.17484276Z 80 PC: 12c41 | Set current PSP
2018-12-17T23:15:37.177359883Z 37 PC: 12ba8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:15:37.178375431Z 26 PC: 12bb0 | Set disk transfer address
2018-12-17T23:15:37.179652514Z 42 PC: 12bb7 | Get date 0x12bb7: cmp dl, 0x19
0x12bba: jne 0x12c11
0x12bbc: push ds
0x12bbd: mov ax, 0x3528
0x12bc0: int 0x21
0x12bc2: mov word ptr cs:[0x136], bx
0x12bc7: mov word ptr cs:[0x138], es
0x12bcc: mov ax, 0x2528
0x12bcf: mov dx, 0x6d0
0x12bd2: push cs
0x12bd3: pop ds
0x12bd4: int 0x21
0x12bd6: pop ds
0x12bd7: or byte ptr cs:[0x152], 8
0x12bdd: call 0x12e50
0x12be0: mov ax, 0x1518
0x12be3: call 0x12d5d
0x12be6: inc ax
0x12be7: mov word ptr cs:[0x159], ax
0x12beb: mov word ptr cs:[0x15b], ax
2018-12-17T23:15:37.182509105Z 76 PC: 131cb | Terminate with return code (Return code = '1')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":7108,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:00:51.73744002Z 48 PC: 12bcf | Get DOS version
2018-12-25T12:00:51.738879747Z 75 PC: 12bdd | Execute program
2018-12-25T12:00:51.741639301Z 53 PC: 12c0f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:00:51.743504859Z 80 PC: 12c41 | Set current PSP
2018-12-25T12:00:51.745600047Z 37 PC: 12ba8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:00:51.748194274Z 26 PC: 12bb0 | Set disk transfer address
2018-12-25T12:00:51.749608085Z 42 PC: 12bb7 | Get date 0x12bb7: cmp dl, 0x19
0x12bba: jne 0x12c11
0x12bbc: push ds
0x12bbd: mov ax, 0x3528
0x12bc0: int 0x21
0x12bc2: mov word ptr cs:[0x136], bx
0x12bc7: mov word ptr cs:[0x138], es
0x12bcc: mov ax, 0x2528
0x12bcf: mov dx, 0x6d0
0x12bd2: push cs
0x12bd3: pop ds
0x12bd4: int 0x21
0x12bd6: pop ds
0x12bd7: or byte ptr cs:[0x152], 8
0x12bdd: call 0x12e50
0x12be0: mov ax, 0x1518
0x12be3: call 0x12d5d
0x12be6: inc ax
0x12be7: mov word ptr cs:[0x159], ax
0x12beb: mov word ptr cs:[0x15b], ax
2018-12-25T12:00:51.752136145Z 76 PC: 131cb | Terminate with return code (Return code = '1')

{"DateBased":true,"Day":25,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":7108,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:00:51.869693087Z 48 PC: 12bcf | Get DOS version
2018-12-25T12:00:51.871743817Z 75 PC: 12bdd | Execute program
2018-12-25T12:00:51.873303807Z 53 PC: 12c0f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:00:51.874640691Z 80 PC: 12c41 | Set current PSP
2018-12-25T12:00:51.876230812Z 37 PC: 12ba8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:00:51.878568062Z 26 PC: 12bb0 | Set disk transfer address
2018-12-25T12:00:51.879810618Z 42 PC: 12bb7 | Get date 0x12bb7: cmp dl, 0x19
0x12bba: jne 0x12c11
0x12bbc: push ds
0x12bbd: mov ax, 0x3528
0x12bc0: int 0x21
0x12bc2: mov word ptr cs:[0x136], bx
0x12bc7: mov word ptr cs:[0x138], es
0x12bcc: mov ax, 0x2528
0x12bcf: mov dx, 0x6d0
0x12bd2: push cs
0x12bd3: pop ds
0x12bd4: int 0x21
0x12bd6: pop ds
0x12bd7: or byte ptr cs:[0x152], 8
0x12bdd: call 0x12e50
0x12be0: mov ax, 0x1518
0x12be3: call 0x12d5d
0x12be6: inc ax
0x12be7: mov word ptr cs:[0x159], ax
0x12beb: mov word ptr cs:[0x15b], ax
2018-12-25T12:00:51.882099348Z 53 PC: 12bc2 | Get interrupt vector (Interrupt = '40' AKA 'Random block write')
2018-12-25T12:00:51.883949844Z 37 PC: 12bd6 | Set interrupt vector (Interrupt = '40' AKA 'Random block write')
2018-12-25T12:00:51.956636214Z 53 PC: 12bfb | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:00:51.957969635Z 37 PC: 12c10 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:00:51.960332307Z 76 PC: 131cb | Terminate with return code (Return code = '1')