Sample viewer

vx.netlux.org/Virus.DOS.Espacio.8458

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:07.106823662Z 200 PC: 12c6c | UNKNOWN!
2018-12-17T22:43:07.110087549Z 80 PC: 2a91d | Set current PSP
2018-12-17T22:43:07.111315908Z 74 PC: 2a925 | Reallocate memory
2018-12-17T22:43:07.112890382Z 80 PC: 2a92a | Set current PSP
2018-12-17T22:43:07.125916007Z 38 PC: 12b6d | Create PSP
2018-12-17T22:43:07.127229471Z 53 PC: 12b74 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:07.128414647Z 37 PC: 12b83 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:43:07.129898187Z 42 PC: 12b87 | Get date 0x12b87: cmp cx, 0x7c9
0x12b8b: ja 0x12b93
0x12b8d: cmp dx, 0x614
0x12b91: jb 0x12ba7
0x12b93: mov ax, 0x351c
0x12b96: int 0x21
0x12b98: mov si, 0x6a4
0x12b9b: mov word ptr [si], bx
0x12b9d: mov word ptr [si + 2], es
0x12ba0: mov dx, 0x69c
0x12ba3: mov ah, 0x25
0x12ba5: int 0x21
0x12ba7: mov es, bp
0x12ba9: push es
0x12baa: cmp byte ptr cs:[0x123], 0
0x12bb0: je 0x12c02
0x12bb2: mov es, word ptr es:[0x2c]
0x12bb7: mov cx, 0xffff
0x12bba: xor ax, ax
0x12bbc: xor di, di
2018-12-17T22:43:07.132583239Z 53 PC: 12b98 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:43:07.133765659Z 37 PC: 12ba7 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:43:07.135374246Z 61 PC: 12bce | Open file (Filename = '')
2018-12-17T22:43:07.141673184Z 66 PC: 12bdc | Move file pointer
2018-12-17T22:43:07.143215987Z 62 PC: 12c02 | Close file
2018-12-17T22:43:07.145576059Z 9 PC: 1a832 | Display string (Could not find end pointer)
2018-12-17T22:43:07.150908412Z 76 PC: 1a838 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":20,"Month":6,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":7777,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:02:35.399744645Z 200 PC: 12c6c | UNKNOWN!
2018-12-25T12:02:35.402957734Z 80 PC: 2a91d | Set current PSP
2018-12-25T12:02:35.404374891Z 74 PC: 2a925 | Reallocate memory
2018-12-25T12:02:35.406050427Z 80 PC: 2a92a | Set current PSP
2018-12-25T12:02:35.410970373Z 38 PC: 12b6d | Create PSP
2018-12-25T12:02:35.413006106Z 53 PC: 12b74 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:02:35.414502245Z 37 PC: 12b83 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:02:35.417984063Z 42 PC: 12b87 | Get date 0x12b87: cmp cx, 0x7c9
0x12b8b: ja 0x12b93
0x12b8d: cmp dx, 0x614
0x12b91: jb 0x12ba7
0x12b93: mov ax, 0x351c
0x12b96: int 0x21
0x12b98: mov si, 0x6a4
0x12b9b: mov word ptr [si], bx
0x12b9d: mov word ptr [si + 2], es
0x12ba0: mov dx, 0x69c
0x12ba3: mov ah, 0x25
0x12ba5: nop
0x12ba6: nop
0x12ba7: mov es, bp
0x12ba9: push es
0x12baa: cmp byte ptr cs:[0x123], 0
0x12bb0: je 0x12c02
0x12bb2: mov es, word ptr es:[0x2c]
0x12bb7: mov cx, 0xffff
0x12bba: xor ax, ax
2018-12-25T12:02:35.421366638Z 53 PC: 12b98 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:02:35.423319512Z 61 PC: 12bce | Open file (Filename = '')
2018-12-25T12:02:35.431259733Z 66 PC: 12bdc | Move file pointer
2018-12-25T12:02:35.434277845Z 62 PC: 12c02 | Close file
2018-12-25T12:02:35.436908795Z 9 PC: 1a832 | Display string (Could not find end pointer)
2018-12-25T12:02:35.443862893Z 76 PC: 1a838 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1994,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":7777,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:02:35.919436214Z 200 PC: 12c6c | UNKNOWN!
2018-12-25T12:02:35.921389431Z 80 PC: 2a91d | Set current PSP
2018-12-25T12:02:35.922076654Z 74 PC: 2a925 | Reallocate memory
2018-12-25T12:02:35.923148949Z 80 PC: 2a92a | Set current PSP
2018-12-25T12:02:35.926253994Z 38 PC: 12b6d | Create PSP
2018-12-25T12:02:35.927151594Z 53 PC: 12b74 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:02:35.927947977Z 37 PC: 12b83 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:02:35.929510732Z 42 PC: 12b87 | Get date 0x12b87: cmp cx, 0x7c9
0x12b8b: ja 0x12b93
0x12b8d: cmp dx, 0x614
0x12b91: jb 0x12ba7
0x12b93: mov ax, 0x351c
0x12b96: int 0x21
0x12b98: mov si, 0x6a4
0x12b9b: mov word ptr [si], bx
0x12b9d: mov word ptr [si + 2], es
0x12ba0: mov dx, 0x69c
0x12ba3: mov ah, 0x25
0x12ba5: nop
0x12ba6: nop
0x12ba7: mov es, bp
0x12ba9: push es
0x12baa: cmp byte ptr cs:[0x123], 0
0x12bb0: je 0x12c02
0x12bb2: mov es, word ptr es:[0x2c]
0x12bb7: mov cx, 0xffff
0x12bba: xor ax, ax
2018-12-25T12:02:35.931107276Z 53 PC: 12b98 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:02:35.932070524Z 61 PC: 12bce | Open file (Filename = '')
2018-12-25T12:02:35.948817675Z 66 PC: 12bdc | Move file pointer
2018-12-25T12:02:35.949808201Z 62 PC: 12c02 | Close file
2018-12-25T12:02:35.951061242Z 9 PC: 1a832 | Display string (Could not find end pointer)
2018-12-25T12:02:35.9550074Z 76 PC: 1a838 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":7777,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:02:36.0370767Z 200 PC: 12c6c | UNKNOWN!
2018-12-25T12:02:36.040990207Z 80 PC: 2a91d | Set current PSP
2018-12-25T12:02:36.042965019Z 74 PC: 2a925 | Reallocate memory
2018-12-25T12:02:36.044928615Z 80 PC: 2a92a | Set current PSP
2018-12-25T12:02:36.049805145Z 38 PC: 12b6d | Create PSP
2018-12-25T12:02:36.051674254Z 53 PC: 12b74 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:02:36.053452801Z 37 PC: 12b83 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:02:36.056853302Z 42 PC: 12b87 | Get date 0x12b87: cmp cx, 0x7c9
0x12b8b: ja 0x12b93
0x12b8d: cmp dx, 0x614
0x12b91: jb 0x12ba7
0x12b93: mov ax, 0x351c
0x12b96: int 0x21
0x12b98: mov si, 0x6a4
0x12b9b: mov word ptr [si], bx
0x12b9d: mov word ptr [si + 2], es
0x12ba0: mov dx, 0x69c
0x12ba3: mov ah, 0x25
0x12ba5: int 0x21
0x12ba7: mov es, bp
0x12ba9: push es
0x12baa: cmp byte ptr cs:[0x123], 0
0x12bb0: je 0x12c02
0x12bb2: mov es, word ptr es:[0x2c]
0x12bb7: mov cx, 0xffff
0x12bba: xor ax, ax
0x12bbc: xor di, di
2018-12-25T12:02:36.059639063Z 61 PC: 12bce | Open file (Filename = '')
2018-12-25T12:02:36.068172978Z 66 PC: 12bdc | Move file pointer
2018-12-25T12:02:36.069885075Z 62 PC: 12c02 | Close file
2018-12-25T12:02:36.074549112Z 9 PC: 1a832 | Display string (Could not find end pointer)
2018-12-25T12:02:36.082191254Z 76 PC: 1a838 | Terminate with return code (Return code = '0')