Sample viewer

vx.netlux.org/Virus.DOS.China.882.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:42:24.339643395Z 127 PC: 12ac7 | UNKNOWN!
2018-12-17T22:42:24.341040453Z 53 PC: 12aea | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:42:24.344571387Z 37 PC: 12afe | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:42:24.350688086Z 37 PC: 12b06 | Set interrupt vector (Interrupt = '247' AKA 'UNKNOWN!')
2018-12-17T22:42:24.352545283Z 42 PC: 12b0a | Get date 0x12b0a: cmp dx, 0xa01
0x12b0e: jne 0x12b29
0x12b10: mov ax, 0x3508
0x12b13: int 0x21
0x12b15: mov word ptr cs:[0x39], bx
0x12b1a: mov word ptr cs:[0x3b], es
0x12b1f: mov ax, 0x2508
0x12b22: push cs
0x12b23: pop ds
0x12b24: mov dx, 0x2c2
0x12b27: int 0x21
0x12b29: mov es, word ptr cs:[0x11]
0x12b2e: mov bx, 0x600
0x12b31: mov cl, 4
0x12b33: shr bx, cl
0x12b35: add bx, 0x10
0x12b38: mov ah, 0x4a
0x12b3a: int 0x21
0x12b3c: mov es, word ptr cs:[0x11]
0x12b41: mov es, word ptr es:[0x2c]
2018-12-17T22:42:24.356990334Z 74 PC: 12b3c | Reallocate memory
2018-12-17T22:42:24.358794109Z 73 PC: 12b85 | Release memory
2018-12-17T22:42:24.360429142Z 77 PC: 12b89 | Get program return code
2018-12-17T22:42:24.369959074Z 49 PC: 12b97 | Terminate and stay resident (Return code = '0' | Memory size = '112')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":7531,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:01:48.958836561Z 127 PC: 12ac7 | UNKNOWN!
2018-12-25T12:01:48.960109629Z 53 PC: 12aea | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:01:48.961695119Z 37 PC: 12afe | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:01:48.963009526Z 37 PC: 12b06 | Set interrupt vector (Interrupt = '247' AKA 'UNKNOWN!')
2018-12-25T12:01:48.964309287Z 42 PC: 12b0a | Get date 0x12b0a: cmp dx, 0xa01
0x12b0e: jne 0x12b29
0x12b10: mov ax, 0x3508
0x12b13: int 0x21
0x12b15: mov word ptr cs:[0x39], bx
0x12b1a: mov word ptr cs:[0x3b], es
0x12b1f: mov ax, 0x2508
0x12b22: push cs
0x12b23: pop ds
0x12b24: mov dx, 0x2c2
0x12b27: int 0x21
0x12b29: mov es, word ptr cs:[0x11]
0x12b2e: mov bx, 0x600
0x12b31: mov cl, 4
0x12b33: shr bx, cl
0x12b35: add bx, 0x10
0x12b38: mov ah, 0x4a
0x12b3a: int 0x21
0x12b3c: mov es, word ptr cs:[0x11]
0x12b41: mov es, word ptr es:[0x2c]
2018-12-25T12:01:48.967837823Z 74 PC: 12b3c | Reallocate memory
2018-12-25T12:01:48.969738455Z 73 PC: 12b85 | Release memory
2018-12-25T12:01:48.971455596Z 77 PC: 12b89 | Get program return code
2018-12-25T12:01:48.973422702Z 49 PC: 12b97 | Terminate and stay resident (Return code = '0' | Memory size = '112')

{"DateBased":true,"Day":1,"Month":10,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":7531,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:01:49.061118644Z 127 PC: 12ac7 | UNKNOWN!
2018-12-25T12:01:49.062758677Z 53 PC: 12aea | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:01:49.064118647Z 37 PC: 12afe | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:01:49.065470856Z 37 PC: 12b06 | Set interrupt vector (Interrupt = '247' AKA 'UNKNOWN!')
2018-12-25T12:01:49.067078006Z 42 PC: 12b0a | Get date 0x12b0a: cmp dx, 0xa01
0x12b0e: jne 0x12b29
0x12b10: mov ax, 0x3508
0x12b13: int 0x21
0x12b15: mov word ptr cs:[0x39], bx
0x12b1a: mov word ptr cs:[0x3b], es
0x12b1f: mov ax, 0x2508
0x12b22: push cs
0x12b23: pop ds
0x12b24: mov dx, 0x2c2
0x12b27: int 0x21
0x12b29: mov es, word ptr cs:[0x11]
0x12b2e: mov bx, 0x600
0x12b31: mov cl, 4
0x12b33: shr bx, cl
0x12b35: add bx, 0x10
0x12b38: mov ah, 0x4a
0x12b3a: int 0x21
0x12b3c: mov es, word ptr cs:[0x11]
0x12b41: mov es, word ptr es:[0x2c]
2018-12-25T12:01:49.071391986Z 53 PC: 12b15 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T12:01:49.07313988Z 37 PC: 12b29 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-25T12:01:49.074486358Z 74 PC: 12b3c | Reallocate memory
2018-12-25T12:01:49.076978754Z 73 PC: 12b85 | Release memory
2018-12-25T12:01:49.078342151Z 77 PC: 12b89 | Get program return code
2018-12-25T12:01:49.079831784Z 49 PC: 12b97 | Terminate and stay resident (Return code = '0' | Memory size = '112')