Sample viewer

vx.netlux.org/Virus.DOS.Andromeda.749

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:44:26.518597545Z 42 PC: 1515c | Get date 0x1515c: cmp al, 6
0x1515e: je 0x15171
0x15160: cmp al, 0
0x15162: je 0x15171
0x15164: mov si, 0xcdfe
0x15167: mov ah, 0x30
0x15169: int 0x21
0x1516b: cmp di, 0x1b3d
0x1516f: jne 0x15188
0x15171: mov si, 0x3db
0x15174: pop bx
0x15175: sub bx, 0x100
0x15179: add si, bx
0x1517b: mov di, 0x100
0x1517e: mov cx, 5
0x15181: rep movsb byte ptr es:[di], byte ptr [si]
0x15183: mov ax, 0x100
0x15186: jmp ax
0x15188: push es
0x15189: mov ax, cs
2018-12-17T22:44:26.522271215Z 48 PC: 1516b | Get DOS version
2018-12-17T22:44:26.52402017Z 38 PC: 151ab | Create PSP
2018-12-17T22:44:26.526233707Z 53 PC: 151db | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:44:26.534723502Z 53 PC: 151f2 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:44:26.536637828Z 37 PC: 1520d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:44:26.538470079Z 37 PC: 15215 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:44:26.542025086Z 9 PC: 1514e | Display string (String= 'DDFGH - A 10000 byte COM test file 1994. ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8213,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:03:52.218899737Z 42 PC: 1515c | Get date 0x1515c: cmp al, 6
0x1515e: je 0x15171
0x15160: cmp al, 0
0x15162: je 0x15171
0x15164: mov si, 0xcdfe
0x15167: mov ah, 0x30
0x15169: int 0x21
0x1516b: cmp di, 0x1b3d
0x1516f: jne 0x15188
0x15171: mov si, 0x3db
0x15174: pop bx
0x15175: sub bx, 0x100
0x15179: add si, bx
0x1517b: mov di, 0x100
0x1517e: mov cx, 5
0x15181: rep movsb byte ptr es:[di], byte ptr [si]
0x15183: mov ax, 0x100
0x15186: jmp ax
0x15188: push es
0x15189: mov ax, cs
2018-12-25T12:03:52.223226173Z 48 PC: 1516b | Get DOS version
2018-12-25T12:03:52.224623245Z 38 PC: 151ab | Create PSP
2018-12-25T12:03:52.226177375Z 53 PC: 151db | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:03:52.228049612Z 53 PC: 151f2 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:03:52.22949677Z 37 PC: 1520d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:03:52.231062431Z 37 PC: 15215 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:03:52.233494498Z 9 PC: 1514e | Display string (String= 'DDFGH - A 10000 byte COM test file 1994. ')

{"DateBased":true,"Day":5,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8213,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:03:52.389236947Z 42 PC: 1515c | Get date 0x1515c: cmp al, 6
0x1515e: je 0x15171
0x15160: cmp al, 0
0x15162: je 0x15171
0x15164: mov si, 0xcdfe
0x15167: mov ah, 0x30
0x15169: int 0x21
0x1516b: cmp di, 0x1b3d
0x1516f: jne 0x15188
0x15171: mov si, 0x3db
0x15174: pop bx
0x15175: sub bx, 0x100
0x15179: add si, bx
0x1517b: mov di, 0x100
0x1517e: mov cx, 5
0x15181: rep movsb byte ptr es:[di], byte ptr [si]
0x15183: mov ax, 0x100
0x15186: jmp ax
0x15188: push es
0x15189: mov ax, cs
2018-12-25T12:03:52.391877444Z 9 PC: 1514e | Display string (String= 'DEFGH - A 10000 byte COM test file 1994. ')

{"DateBased":true,"Day":6,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8213,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:03:52.606535268Z 42 PC: 1515c | Get date 0x1515c: cmp al, 6
0x1515e: je 0x15171
0x15160: cmp al, 0
0x15162: je 0x15171
0x15164: mov si, 0xcdfe
0x15167: mov ah, 0x30
0x15169: int 0x21
0x1516b: cmp di, 0x1b3d
0x1516f: jne 0x15188
0x15171: mov si, 0x3db
0x15174: pop bx
0x15175: sub bx, 0x100
0x15179: add si, bx
0x1517b: mov di, 0x100
0x1517e: mov cx, 5
0x15181: rep movsb byte ptr es:[di], byte ptr [si]
0x15183: mov ax, 0x100
0x15186: jmp ax
0x15188: push es
0x15189: mov ax, cs
2018-12-25T12:03:52.609191003Z 9 PC: 1514e | Display string (String= 'DEFGH - A 10000 byte COM test file 1994. ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8213,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:03:52.618920016Z 42 PC: 1515c | Get date 0x1515c: cmp al, 6
0x1515e: je 0x15171
0x15160: cmp al, 0
0x15162: je 0x15171
0x15164: mov si, 0xcdfe
0x15167: mov ah, 0x30
0x15169: int 0x21
0x1516b: cmp di, 0x1b3d
0x1516f: jne 0x15188
0x15171: mov si, 0x3db
0x15174: pop bx
0x15175: sub bx, 0x100
0x15179: add si, bx
0x1517b: mov di, 0x100
0x1517e: mov cx, 5
0x15181: rep movsb byte ptr es:[di], byte ptr [si]
0x15183: mov ax, 0x100
0x15186: jmp ax
0x15188: push es
0x15189: mov ax, cs
2018-12-25T12:03:52.622173195Z 48 PC: 1516b | Get DOS version
2018-12-25T12:03:52.624803517Z 38 PC: 151ab | Create PSP
2018-12-25T12:03:52.627000359Z 53 PC: 151db | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:03:52.629278054Z 53 PC: 151f2 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:03:52.630685489Z 37 PC: 1520d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:03:52.631930249Z 37 PC: 15215 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:03:52.633139394Z 9 PC: 1514e | Display string (String= 'DDFGH - A 10000 byte COM test file 1994. ')

{"DateBased":true,"Day":5,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8213,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:03:52.589782766Z 42 PC: 1515c | Get date 0x1515c: cmp al, 6
0x1515e: je 0x15171
0x15160: cmp al, 0
0x15162: je 0x15171
0x15164: mov si, 0xcdfe
0x15167: mov ah, 0x30
0x15169: int 0x21
0x1516b: cmp di, 0x1b3d
0x1516f: jne 0x15188
0x15171: mov si, 0x3db
0x15174: pop bx
0x15175: sub bx, 0x100
0x15179: add si, bx
0x1517b: mov di, 0x100
0x1517e: mov cx, 5
0x15181: rep movsb byte ptr es:[di], byte ptr [si]
0x15183: mov ax, 0x100
0x15186: jmp ax
0x15188: push es
0x15189: mov ax, cs
2018-12-25T12:03:52.592592867Z 9 PC: 1514e | Display string (String= 'DEFGH - A 10000 byte COM test file 1994. ')

{"DateBased":true,"Day":6,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8213,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:03:53.051358234Z 42 PC: 1515c | Get date 0x1515c: cmp al, 6
0x1515e: je 0x15171
0x15160: cmp al, 0
0x15162: je 0x15171
0x15164: mov si, 0xcdfe
0x15167: mov ah, 0x30
0x15169: int 0x21
0x1516b: cmp di, 0x1b3d
0x1516f: jne 0x15188
0x15171: mov si, 0x3db
0x15174: pop bx
0x15175: sub bx, 0x100
0x15179: add si, bx
0x1517b: mov di, 0x100
0x1517e: mov cx, 5
0x15181: rep movsb byte ptr es:[di], byte ptr [si]
0x15183: mov ax, 0x100
0x15186: jmp ax
0x15188: push es
0x15189: mov ax, cs
2018-12-25T12:03:53.053570328Z 9 PC: 1514e | Display string (String= 'DEFGH - A 10000 byte COM test file 1994. ')