Sample viewer

vx.netlux.org/Virus.DOS.Steel.407

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:56:38.470789352Z 42 PC: 12a69 | Get date 0x12a69: cmp al, 1
0x12a6b: jne 0x12a7a
0x12a6d: mov ah, 9
0x12a6f: mov dx, 0x27e
0x12a72: int 0x21
0x12a74: mov ah, 1
0x12a76: int 0x21
0x12a78: int 0x20
0x12a7a: jne 0x12a7f
0x12a7c: jmp 0x12ace
0x12a7e: nop
0x12a7f: pop es
0x12a80: push es
0x12a81: mov ax, es
0x12a83: dec ax
0x12a84: mov es, ax
0x12a86: mov ax, word ptr es:[3]
0x12a8a: sub ax, 0x1b
0x12a8d: mov word ptr es:[3], ax
0x12a91: mov bx, word ptr es:[1]
2018-12-17T21:56:38.473202991Z 9 PC: 12a74 | Display string (String= 'I Love your computer!')
2018-12-17T21:56:38.475380982Z 1 PC: 12a78 | Character input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":721,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:41:35.203324489Z 42 PC: 12a69 | Get date 0x12a69: cmp al, 1
0x12a6b: jne 0x12a7a
0x12a6d: mov ah, 9
0x12a6f: mov dx, 0x27e
0x12a72: int 0x21
0x12a74: mov ah, 1
0x12a76: int 0x21
0x12a78: int 0x20
0x12a7a: jne 0x12a7f
0x12a7c: jmp 0x12ace
0x12a7e: nop
0x12a7f: pop es
0x12a80: push es
0x12a81: mov ax, es
0x12a83: dec ax
0x12a84: mov es, ax
0x12a86: mov ax, word ptr es:[3]
0x12a8a: sub ax, 0x1b
0x12a8d: mov word ptr es:[3], ax
0x12a91: mov bx, word ptr es:[1]
2018-12-25T11:41:35.20616565Z 9 PC: 12a47 | Display string (String= 'I Love your computer!')

{"DateBased":true,"Day":7,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":721,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:41:35.341066778Z 42 PC: 12a69 | Get date 0x12a69: cmp al, 1
0x12a6b: jne 0x12a7a
0x12a6d: mov ah, 9
0x12a6f: mov dx, 0x27e
0x12a72: int 0x21
0x12a74: mov ah, 1
0x12a76: int 0x21
0x12a78: int 0x20
0x12a7a: jne 0x12a7f
0x12a7c: jmp 0x12ace
0x12a7e: nop
0x12a7f: pop es
0x12a80: push es
0x12a81: mov ax, es
0x12a83: dec ax
0x12a84: mov es, ax
0x12a86: mov ax, word ptr es:[3]
0x12a8a: sub ax, 0x1b
0x12a8d: mov word ptr es:[3], ax
0x12a91: mov bx, word ptr es:[1]
2018-12-25T11:41:35.34461397Z 9 PC: 12a74 | Display string (String= 'I Love your computer!')
2018-12-25T11:41:35.346709815Z 1 PC: 12a78 | Character input