Sample viewer

vx.netlux.org/Virus.DOS.Dieg.1586

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:44:54.664550113Z 53 PC: 2072d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:44:54.666196077Z 53 PC: 12d40 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:44:54.667114149Z 37 PC: 12d53 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:44:54.667882803Z 42 PC: 12d57 | Get date 0x12d57: cmp dh, 8
0x12d5a: jne 0x12d72
0x12d5c: cli
0x12d5d: mov dx, 0x594
0x12d60: nop
0x12d61: mov al, 0x1c
0x12d63: mov ah, 0x25
0x12d65: sti
0x12d66: int 0x21
0x12d68: cli
0x12d69: mov dx, 0x5b0
0x12d6c: nop
0x12d6d: mov al, 0x28
0x12d6f: sti
0x12d70: int 0x21
0x12d72: mov di, 0x2c
0x12d75: mov ax, word ptr [di]
0x12d77: mov es, ax
0x12d79: xor ax, ax
0x12d7b: xor di, di
2018-12-17T22:44:54.669982511Z 74 PC: 12eb0 | Reallocate memory
2018-12-17T22:44:54.671025837Z 75 PC: 12ec4 | Execute program
2018-12-17T22:44:54.682236993Z 53 PC: 20ecd | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:44:54.684101069Z 80 PC: 14959 | Set current PSP
2018-12-17T22:44:54.684972404Z 48 PC: 1495e | Get DOS version
2018-12-17T22:44:54.686066169Z 2 PC: 1480c | Character output (Char = '56')
2018-12-17T22:44:54.68864441Z 2 PC: 1480c | Character output (Char = '65')
2018-12-17T22:44:54.690941727Z 2 PC: 1480c | Character output (Char = '72')
2018-12-17T22:44:54.693235042Z 2 PC: 1480c | Character output (Char = '73')
2018-12-17T22:44:54.696096067Z 2 PC: 1480c | Character output (Char = '69')
2018-12-17T22:44:54.698512111Z 2 PC: 1480c | Character output (Char = 'a2')
2018-12-17T22:44:54.700843596Z 2 PC: 1480c | Character output (Char = '6e')
2018-12-17T22:44:54.703382243Z 2 PC: 1480c | Character output (Char = '20')
2018-12-17T22:44:54.70596359Z 2 PC: 1480c | Character output (Char = '69')
2018-12-17T22:44:54.708230362Z 2 PC: 1480c | Character output (Char = '6e')
2018-12-17T22:44:54.710449914Z 2 PC: 1480c | Character output (Char = '63')
2018-12-17T22:44:54.71277588Z 2 PC: 1480c | Character output (Char = '6f')
2018-12-17T22:44:54.715204998Z 2 PC: 1480c | Character output (Char = '72')
2018-12-17T22:44:54.71757039Z 2 PC: 1480c | Character output (Char = '72')
2018-12-17T22:44:54.720592241Z 2 PC: 1480c | Character output (Char = '65')
2018-12-17T22:44:54.722963094Z 2 PC: 1480c | Character output (Char = '63')
2018-12-17T22:44:54.725238616Z 2 PC: 1480c | Character output (Char = '74')
2018-12-17T22:44:54.727892115Z 2 PC: 1480c | Character output (Char = '61')
2018-12-17T22:44:54.730163277Z 2 PC: 1480c | Character output (Char = '20')
2018-12-17T22:44:54.732377375Z 2 PC: 1480c | Character output (Char = '64')
2018-12-17T22:44:54.735371419Z 2 PC: 1480c | Character output (Char = '65')
2018-12-17T22:44:54.737695917Z 2 PC: 1480c | Character output (Char = '20')
2018-12-17T22:44:54.73995524Z 2 PC: 1480c | Character output (Char = '44')
2018-12-17T22:44:54.742611137Z 2 PC: 1480c | Character output (Char = '4f')
2018-12-17T22:44:54.74491614Z 2 PC: 1480c | Character output (Char = '53')
2018-12-17T22:44:54.748774824Z 2 PC: 1480c | Character output (Char = '0d')
2018-12-17T22:44:54.752095553Z 2 PC: 1480c | Character output (Char = '0a')
2018-12-17T22:44:54.759054185Z 49 PC: 12eca | Terminate and stay resident (Return code = '0' | Memory size = '116')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8369,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:04:31.489990935Z 53 PC: 2072d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:04:31.491268313Z 53 PC: 12d40 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:04:31.49241361Z 37 PC: 12d53 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:04:31.494710072Z 42 PC: 12d57 | Get date 0x12d57: cmp dh, 8
0x12d5a: jne 0x12d72
0x12d5c: cli
0x12d5d: mov dx, 0x594
0x12d60: nop
0x12d61: mov al, 0x1c
0x12d63: mov ah, 0x25
0x12d65: sti
0x12d66: int 0x21
0x12d68: cli
0x12d69: mov dx, 0x5b0
0x12d6c: nop
0x12d6d: mov al, 0x28
0x12d6f: sti
0x12d70: int 0x21
0x12d72: mov di, 0x2c
0x12d75: mov ax, word ptr [di]
0x12d77: mov es, ax
0x12d79: xor ax, ax
0x12d7b: xor di, di
2018-12-25T12:04:31.496944151Z 74 PC: 12eb0 | Reallocate memory
2018-12-25T12:04:31.498211047Z 75 PC: 12ec4 | Execute program
2018-12-25T12:04:31.514737017Z 53 PC: 20ecd | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:04:31.516036739Z 80 PC: 14959 | Set current PSP
2018-12-25T12:04:31.51676717Z 48 PC: 1495e | Get DOS version
2018-12-25T12:04:31.518409905Z 2 PC: 1480c | Character output (Char = '56')
2018-12-25T12:04:31.520573131Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.5225337Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.525070139Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.527273625Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.529254172Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.531972268Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.534014208Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.535926553Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.538536954Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.540534353Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.542508876Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.544611427Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.547074989Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.54904923Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.551907257Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.553704363Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.555144831Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.5566951Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.559072006Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.561035523Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.563071899Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.565036282Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.566939083Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.569001379Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.571236001Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.573208037Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:31.578657163Z 49 PC: 12eca | Terminate and stay resident (Return code = '0' | Memory size = '116')

{"DateBased":true,"Day":1,"Month":8,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8369,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:04:32.081385376Z 53 PC: 2072d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:04:32.082249932Z 53 PC: 12d40 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:04:32.083005661Z 37 PC: 12d53 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:04:32.084812456Z 42 PC: 12d57 | Get date 0x12d57: cmp dh, 8
0x12d5a: jne 0x12d72
0x12d5c: cli
0x12d5d: mov dx, 0x594
0x12d60: nop
0x12d61: mov al, 0x1c
0x12d63: mov ah, 0x25
0x12d65: sti
0x12d66: int 0x21
0x12d68: cli
0x12d69: mov dx, 0x5b0
0x12d6c: nop
0x12d6d: mov al, 0x28
0x12d6f: sti
0x12d70: int 0x21
0x12d72: mov di, 0x2c
0x12d75: mov ax, word ptr [di]
0x12d77: mov es, ax
0x12d79: xor ax, ax
0x12d7b: xor di, di
2018-12-25T12:04:32.08753736Z 37 PC: 12d68 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:04:32.088463468Z 37 PC: 12d72 | Set interrupt vector (Interrupt = '40' AKA 'Random block write')
2018-12-25T12:04:32.089895334Z 74 PC: 12eb0 | Reallocate memory
2018-12-25T12:04:32.091097658Z 75 PC: 12ec4 | Execute program
2018-12-25T12:04:32.107499269Z 53 PC: 20ecd | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:04:32.118452616Z 80 PC: 14959 | Set current PSP
2018-12-25T12:04:32.119160332Z 48 PC: 1495e | Get DOS version
2018-12-25T12:04:32.120147383Z 2 PC: 1480c | Character output (Char = '56')
2018-12-25T12:04:32.122473763Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.124409416Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.126312526Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.128541959Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.130459483Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.132348065Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.134664597Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.13607711Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.137354461Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.139097111Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.140428247Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.141715795Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.143411269Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.144776785Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.146072007Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.14830089Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.149674187Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.151002593Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.153029146Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.155260213Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.157306853Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.159528474Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.16142756Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.16330148Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.166349417Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.168107013Z 2 PC: 1480c | Character output (See above)
2018-12-25T12:04:32.173200138Z 49 PC: 12eca | Terminate and stay resident (Return code = '0' | Memory size = '116')