Sample viewer

vx.netlux.org/Virus.DOS.GeldWash.1497

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:41:23.231430095Z 75 PC: 13026 | Execute program
2018-12-17T22:41:23.237657172Z 53 PC: 13035 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:23.23933759Z 72 PC: 13045 | Allocate memory
2018-12-17T22:41:23.241682589Z 37 PC: 13070 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:23.243594316Z 42 PC: 13077 | Get date 0x13077: cmp cx, 0x7c7
0x1307b: ja 0x13086
0x1307d: cmp dx, 0xb0f
0x13081: jae 0x13086
0x13083: jmp 0x13272
0x13086: xor ax, ax
0x13088: mov al, dh
0x1308a: mov cl, 2
0x1308c: div cl
0x1308e: cmp ah, 0
0x13091: je 0x13096
0x13093: jmp 0x13272
0x13096: cmp dl, 0x19
0x13099: je 0x1309e
0x1309b: jmp 0x13272
0x1309e: push cs
0x1309f: pop es
0x130a0: mov dh, 0xda
0x130a2: lea bx, word ptr [0x150]
0x130a6: mov cx, 0x97
2018-12-17T22:41:23.246239886Z 76 PC: 12f28 | Terminate with return code (Return code = '76')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":7195,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:01:05.391967144Z 75 PC: 13026 | Execute program
2018-12-25T12:01:05.393624238Z 53 PC: 13035 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:01:05.394838038Z 72 PC: 13045 | Allocate memory
2018-12-25T12:01:05.396603468Z 37 PC: 13070 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:01:05.398252223Z 42 PC: 13077 | Get date 0x13077: cmp cx, 0x7c7
0x1307b: ja 0x13086
0x1307d: cmp dx, 0xb0f
0x13081: jae 0x13086
0x13083: jmp 0x13272
0x13086: xor ax, ax
0x13088: mov al, dh
0x1308a: mov cl, 2
0x1308c: div cl
0x1308e: cmp ah, 0
0x13091: je 0x13096
0x13093: jmp 0x13272
0x13096: cmp dl, 0x19
0x13099: je 0x1309e
0x1309b: jmp 0x13272
0x1309e: push cs
0x1309f: pop es
0x130a0: mov dh, 0xda
0x130a2: lea bx, word ptr [0x150]
0x130a6: mov cx, 0x97
2018-12-25T12:01:05.400299994Z 76 PC: 12f28 | Terminate with return code (Return code = '76')

{"DateBased":true,"Day":16,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":7195,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:01:05.744945819Z 64 PC: 0 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T12:01:05.750357404Z 41 PC: 94fae | Parse filename
2018-12-25T12:01:05.755213181Z 41 PC: 9502f | Parse filename
2018-12-25T12:01:05.758205204Z 41 PC: 9504c | Parse filename
2018-12-25T12:01:05.760073003Z 26 PC: 984f7 | Set disk transfer address
2018-12-25T12:01:05.762137669Z 71 PC: 986f3 | Get current directory
2018-12-25T12:01:05.765504653Z 78 PC: 986fe | Find first file
2018-12-25T12:01:05.774305125Z 71 PC: 986f3 | Get current directory (See above)
2018-12-25T12:01:05.776863542Z 78 PC: 986fe | Find first file (See above)
2018-12-25T12:01:05.788754346Z 64 PC: 9a848 | Write file or device (Write 26 bytes on handle 2)
2018-12-25T12:01:05.794514416Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T12:01:05.796153711Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T12:01:05.798106433Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:01:05.799308893Z 62 PC: 122ab | Close file
2018-12-25T12:01:05.801262213Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:01:05.802995973Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:01:05.805247727Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:01:05.807457291Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:01:05.808903007Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:01:05.810270323Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:01:05.812183471Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:01:05.813755026Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:01:05.815768605Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:01:05.817326211Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:01:05.818724254Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:01:05.819847585Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:01:05.820864094Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:01:05.822487175Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:01:05.823663576Z 99 PC: 9a5d7 | Get DBCS lead byte table pointer
2018-12-25T12:01:05.824548168Z 56 PC: 94df9 | Get or set country info
2018-12-25T12:01:05.826446947Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T12:01:05.829054271Z 25 PC: 94e62 | Get default drive
2018-12-25T12:01:05.829989215Z 71 PC: 970dd | Get current directory
2018-12-25T12:01:05.83284767Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T12:01:05.834841007Z 2 PC: 970b2 | Character output (Char = '3e')
2018-12-25T12:01:05.836150734Z 93 PC: 94f20 | File sharing functions
2018-12-25T12:01:05.83749601Z 93 PC: 94f27 | File sharing functions
2018-12-25T12:01:05.838842361Z 10 PC: 94f39 | Buffered keyboard input
2018-12-25T12:01:20.791329203Z 0 PC: 0 | Program terminate (See above)
2018-12-25T12:01:22.144639625Z 0 PC: 0 | Program terminate (See above)
2018-12-25T12:01:22.247305883Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T12:01:22.253370629Z 41 PC: 94fae | Parse filename (See above)
2018-12-25T12:01:22.255496462Z 41 PC: 9502f | Parse filename (See above)
2018-12-25T12:01:22.25722966Z 41 PC: 9504c | Parse filename (See above)
2018-12-25T12:01:22.261288639Z 26 PC: 984f7 | Set disk transfer address (See above)
2018-12-25T12:01:22.263091276Z 71 PC: 986f3 | Get current directory (See above)
2018-12-25T12:01:22.270706954Z 78 PC: 986fe | Find first file (See above)
2018-12-25T12:01:22.280210142Z 71 PC: 9856c | Get current directory
2018-12-25T12:01:22.284599186Z 73 PC: 97c09 | Release memory
2018-12-25T12:01:22.286703456Z 75 PC: 11821 | Execute program
2018-12-25T12:01:22.301839562Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-25T12:01:22.30574882Z 76 PC: 12a4b | Terminate with return code (Return code = '36')

{"DateBased":true,"Day":1,"Month":1,"Year":1992,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":7195,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:01:06.195326171Z 75 PC: 13026 | Execute program
2018-12-25T12:01:06.197943982Z 53 PC: 13035 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:01:06.199316524Z 72 PC: 13045 | Allocate memory
2018-12-25T12:01:06.201449406Z 37 PC: 13070 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:01:06.202967891Z 42 PC: 13077 | Get date 0x13077: cmp cx, 0x7c7
0x1307b: ja 0x13086
0x1307d: cmp dx, 0xb0f
0x13081: jae 0x13086
0x13083: jmp 0x13272
0x13086: xor ax, ax
0x13088: mov al, dh
0x1308a: mov cl, 2
0x1308c: div cl
0x1308e: cmp ah, 0
0x13091: je 0x13096
0x13093: jmp 0x13272
0x13096: cmp dl, 0x19
0x13099: je 0x1309e
0x1309b: jmp 0x13272
0x1309e: push cs
0x1309f: pop es
0x130a0: mov dh, 0xda
0x130a2: lea bx, word ptr [0x150]
0x130a6: mov cx, 0x97
2018-12-25T12:01:06.206209351Z 76 PC: 12f28 | Terminate with return code (Return code = '76')