Sample viewer

vx.netlux.org/Virus.DOS.Flavour.911

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:41:54.684482858Z 42 PC: 12e34 | Get date 0x12e34: cmp dx, 0x909
0x12e38: jne 0x12e45
0x12e3a: mov ah, 9
0x12e3c: lea dx, word ptr [si + 0x13b]
0x12e40: int 0x21
0x12e42: cli
0x12e43: jmp 0x12e42
0x12e45: mov ax, 0x8f00
0x12e48: int 0x21
0x12e4a: cmp ax, 0x8f
0x12e4d: jne 0x12e5e
0x12e4f: add si, 0x126
0x12e53: mov di, 0x100
0x12e56: push ss
0x12e57: push di
0x12e58: cld
0x12e59: movsw word ptr es:[di], word ptr [si]
0x12e5a: movsw word ptr es:[di], word ptr [si]
0x12e5b: push ss
0x12e5c: pop ds
2018-12-17T22:41:54.68716729Z 143 PC: 12e4a | UNKNOWN!
2018-12-17T22:41:54.690998616Z 82 PC: 12e64 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:41:54.693078673Z 82 PC: 9f92d | Get DOS internal pointers (SYSVARS)

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":7366,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:01:25.034095137Z 42 PC: 12e34 | Get date 0x12e34: cmp dx, 0x909
0x12e38: jne 0x12e45
0x12e3a: mov ah, 9
0x12e3c: lea dx, word ptr [si + 0x13b]
0x12e40: int 0x21
0x12e42: cli
0x12e43: jmp 0x12e42
0x12e45: mov ax, 0x8f00
0x12e48: int 0x21
0x12e4a: cmp ax, 0x8f
0x12e4d: jne 0x12e5e
0x12e4f: add si, 0x126
0x12e53: mov di, 0x100
0x12e56: push ss
0x12e57: push di
0x12e58: cld
0x12e59: movsw word ptr es:[di], word ptr [si]
0x12e5a: movsw word ptr es:[di], word ptr [si]
0x12e5b: push ss
0x12e5c: pop ds
2018-12-25T12:01:25.036778729Z 143 PC: 12e4a | UNKNOWN!
2018-12-25T12:01:25.03828378Z 82 PC: 12e64 | Get DOS internal pointers (SYSVARS)
2018-12-25T12:01:25.040252271Z 82 PC: 9f92d | Get DOS internal pointers (SYSVARS)

{"DateBased":true,"Day":9,"Month":9,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":7366,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:01:25.639615789Z 42 PC: 12e34 | Get date 0x12e34: cmp dx, 0x909
0x12e38: jne 0x12e45
0x12e3a: mov ah, 9
0x12e3c: lea dx, word ptr [si + 0x13b]
0x12e40: int 0x21
0x12e42: cli
0x12e43: jmp 0x12e42
0x12e45: mov ax, 0x8f00
0x12e48: int 0x21
0x12e4a: cmp ax, 0x8f
0x12e4d: jne 0x12e5e
0x12e4f: add si, 0x126
0x12e53: mov di, 0x100
0x12e56: push ss
0x12e57: push di
0x12e58: cld
0x12e59: movsw word ptr es:[di], word ptr [si]
0x12e5a: movsw word ptr es:[di], word ptr [si]
0x12e5b: push ss
0x12e5c: pop ds
2018-12-25T12:01:25.642344935Z 9 PC: 12e42 | Display string (String= 'Hello !! I am [Flavour V1.3�] By Dark Killer ... at Taiwan Power Virus Organization !! 1995/07/06 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":7366,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:01:25.706947539Z 42 PC: 12e34 | Get date 0x12e34: cmp dx, 0x909
0x12e38: jne 0x12e45
0x12e3a: mov ah, 9
0x12e3c: lea dx, word ptr [si + 0x13b]
0x12e40: int 0x21
0x12e42: cli
0x12e43: jmp 0x12e42
0x12e45: mov ax, 0x8f00
0x12e48: int 0x21
0x12e4a: cmp ax, 0x8f
0x12e4d: jne 0x12e5e
0x12e4f: add si, 0x126
0x12e53: mov di, 0x100
0x12e56: push ss
0x12e57: push di
0x12e58: cld
0x12e59: movsw word ptr es:[di], word ptr [si]
0x12e5a: movsw word ptr es:[di], word ptr [si]
0x12e5b: push ss
0x12e5c: pop ds
2018-12-25T12:01:25.710275683Z 143 PC: 12e4a | UNKNOWN!
2018-12-25T12:01:25.711107917Z 82 PC: 12e64 | Get DOS internal pointers (SYSVARS)
2018-12-25T12:01:25.712484264Z 82 PC: 9f92d | Get DOS internal pointers (SYSVARS)

{"DateBased":true,"Day":9,"Month":9,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":7366,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:01:26.880175445Z 42 PC: 12e34 | Get date 0x12e34: cmp dx, 0x909
0x12e38: jne 0x12e45
0x12e3a: mov ah, 9
0x12e3c: lea dx, word ptr [si + 0x13b]
0x12e40: int 0x21
0x12e42: cli
0x12e43: jmp 0x12e42
0x12e45: mov ax, 0x8f00
0x12e48: int 0x21
0x12e4a: cmp ax, 0x8f
0x12e4d: jne 0x12e5e
0x12e4f: add si, 0x126
0x12e53: mov di, 0x100
0x12e56: push ss
0x12e57: push di
0x12e58: cld
0x12e59: movsw word ptr es:[di], word ptr [si]
0x12e5a: movsw word ptr es:[di], word ptr [si]
0x12e5b: push ss
0x12e5c: pop ds
2018-12-25T12:01:26.883268151Z 9 PC: 12e42 | Display string (String= 'Hello !! I am [Flavour V1.3�] By Dark Killer ... at Taiwan Power Virus Organization !! 1995/07/06 ')