Sample viewer

vx.netlux.org/Virus.DOS.November17.690

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:42:48.297099195Z 9 PC: 12a4e | Display string (String= ' TEST CPU ')
2018-12-17T22:42:48.300620803Z 9 PC: 12a55 | Display string (String= ' BENCHMARK sulla velocita'. ')
2018-12-17T22:42:48.304373835Z 9 PC: 12a65 | Display string (String= 'Calcolo CPU relativo ad un IBM PC-XT: (00.00X) ')
2018-12-17T22:42:48.308016568Z 9 PC: 12a6a | Display string (String= 'XT:1X 2X 3X 4X 5X 7X 9X 11X 13X 15X 17X 19X ')
2018-12-17T22:42:48.312051311Z 9 PC: 12a71 | Display string (String= ' � � � � �')
2018-12-17T22:42:48.315540222Z 9 PC: 12a73 | Display string (String= ' � � � � �')
2018-12-17T22:42:48.317573122Z 9 PC: 12a75 | Display string (String= ' � � � � �')
2018-12-17T22:42:48.320577585Z 9 PC: 12a77 | Display string (String= ' � � � � �')
2018-12-17T22:42:48.323856506Z 9 PC: 12a89 | Display string (String= ' ')
2018-12-17T22:42:48.327202039Z 9 PC: 12a8b | Display string (String= ' ')
2018-12-17T22:42:48.329488437Z 9 PC: 12a9d | Display string (String= ' ')
2018-12-17T22:42:48.331693493Z 9 PC: 12aa4 | Display string (String= ' � � � � ')
2018-12-17T22:42:48.334195796Z 9 PC: 12aab | Display string (String= 'AT: 6MHZ 8MHZ 10MHZ 12MHZ')
2018-12-17T22:42:48.338172345Z 9 PC: 12ac7 | Display string (String= 'Questo sistema e' equivalente ad un PC-AT con 00.00 MHZ')
2018-12-17T22:42:48.492993903Z 76 PC: 0 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":7666,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:02:19.966935387Z 9 PC: 12a4e | Display string (String= ' TEST CPU ')
2018-12-25T12:02:19.984112047Z 9 PC: 12a55 | Display string (String= ' BENCHMARK sulla velocita'. ')
2018-12-25T12:02:19.988731539Z 9 PC: 12a65 | Display string (String= 'Calcolo CPU relativo ad un IBM PC-XT: (00.00X) ')
2018-12-25T12:02:19.991575365Z 9 PC: 12a6a | Display string (String= 'XT:1X 2X 3X 4X 5X 7X 9X 11X 13X 15X 17X 19X ')
2018-12-25T12:02:19.996351064Z 9 PC: 12a71 | Display string (String= ' � � � � �')
2018-12-25T12:02:19.999640192Z 9 PC: 12a73 | Display string (String= ' � � � � �')
2018-12-25T12:02:20.002609427Z 9 PC: 12a75 | Display string (String= ' � � � � �')
2018-12-25T12:02:20.006663413Z 9 PC: 12a77 | Display string (String= ' � � � � �')
2018-12-25T12:02:20.010494677Z 9 PC: 12a89 | Display string (String= ' ')
2018-12-25T12:02:20.012990038Z 9 PC: 12a8b | Display string (String= ' ')
2018-12-25T12:02:20.015694206Z 9 PC: 12a9d | Display string (String= ' ')
2018-12-25T12:02:20.018849096Z 9 PC: 12aa4 | Display string (String= ' � � � � ')
2018-12-25T12:02:20.023236853Z 9 PC: 12aab | Display string (String= 'AT: 6MHZ 8MHZ 10MHZ 12MHZ')
2018-12-25T12:02:20.0260276Z 9 PC: 12ac7 | Display string (String= 'Questo sistema e' equivalente ad un PC-AT con 00.00 MHZ')
2018-12-25T12:02:20.194468421Z 76 PC: 0 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":8,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":7666,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:02:20.168089765Z 9 PC: 12a4e | Display string (String= ' TEST CPU ')
2018-12-25T12:02:20.173128421Z 9 PC: 12a55 | Display string (String= ' BENCHMARK sulla velocita'. ')
2018-12-25T12:02:20.178078676Z 9 PC: 12a65 | Display string (String= 'Calcolo CPU relativo ad un IBM PC-XT: (00.00X) ')
2018-12-25T12:02:20.180405163Z 9 PC: 12a6a | Display string (String= 'XT:1X 2X 3X 4X 5X 7X 9X 11X 13X 15X 17X 19X ')
2018-12-25T12:02:20.184919388Z 9 PC: 12a71 | Display string (String= ' � � � � �')
2018-12-25T12:02:20.187219126Z 9 PC: 12a73 | Display string (String= ' � � � � �')
2018-12-25T12:02:20.189313597Z 9 PC: 12a75 | Display string (String= ' � � � � �')
2018-12-25T12:02:20.19324489Z 9 PC: 12a77 | Display string (String= ' � � � � �')
2018-12-25T12:02:20.196197217Z 9 PC: 12a89 | Display string (String= ' ')
2018-12-25T12:02:20.198117117Z 9 PC: 12a8b | Display string (String= ' ')
2018-12-25T12:02:20.200567361Z 9 PC: 12a9d | Display string (String= ' ')
2018-12-25T12:02:20.203336338Z 9 PC: 12aa4 | Display string (String= ' � � � � ')
2018-12-25T12:02:20.214616609Z 9 PC: 12aab | Display string (String= 'AT: 6MHZ 8MHZ 10MHZ 12MHZ')
2018-12-25T12:02:20.216436888Z 9 PC: 12ac7 | Display string (String= 'Questo sistema e' equivalente ad un PC-AT con 00.00 MHZ')
2018-12-25T12:02:20.353930038Z 76 PC: 0 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":8,"Month":7,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":7666,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:02:20.177128145Z 9 PC: 12a4e | Display string (String= ' TEST CPU ')
2018-12-25T12:02:20.182093933Z 9 PC: 12a55 | Display string (String= ' BENCHMARK sulla velocita'. ')
2018-12-25T12:02:20.187106792Z 9 PC: 12a65 | Display string (String= 'Calcolo CPU relativo ad un IBM PC-XT: (00.00X) ')
2018-12-25T12:02:20.189739991Z 9 PC: 12a6a | Display string (String= 'XT:1X 2X 3X 4X 5X 7X 9X 11X 13X 15X 17X 19X ')
2018-12-25T12:02:20.193990998Z 9 PC: 12a71 | Display string (String= ' � � � � �')
2018-12-25T12:02:20.197212554Z 9 PC: 12a73 | Display string (String= ' � � � � �')
2018-12-25T12:02:20.199557244Z 9 PC: 12a75 | Display string (String= ' � � � � �')
2018-12-25T12:02:20.203258054Z 9 PC: 12a77 | Display string (String= ' � � � � �')
2018-12-25T12:02:20.206829908Z 9 PC: 12a89 | Display string (String= ' ')
2018-12-25T12:02:20.209228209Z 9 PC: 12a8b | Display string (String= ' ')
2018-12-25T12:02:20.211959236Z 9 PC: 12a9d | Display string (String= ' ')
2018-12-25T12:02:20.214773248Z 9 PC: 12aa4 | Display string (String= ' � � � � ')
2018-12-25T12:02:20.21946869Z 9 PC: 12aab | Display string (String= 'AT: 6MHZ 8MHZ 10MHZ 12MHZ')
2018-12-25T12:02:20.223047656Z 9 PC: 12ac7 | Display string (String= 'Questo sistema e' equivalente ad un PC-AT con 00.00 MHZ')
2018-12-25T12:02:20.470423473Z 9 PC: 12ce9 | Display string (String= 'I6.00')
2018-12-25T12:02:20.47327107Z 9 PC: 12ce9 | Display string (See above)
2018-12-25T12:02:20.47642367Z 9 PC: 12c61 | Display string (String= 'Premi per uscire. ')
2018-12-25T12:02:20.481107597Z 9 PC: 12c66 | Display string (String= ' (C) 1988 LABORATORI JACKSON ')
2018-12-25T12:02:20.806118539Z 76 PC: 0 | Terminate with return code (Return code = '0')