Sample viewer

vx.netlux.org/Virus.DOS.Usa.1339

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:20.275850085Z 26 PC: 12aa0 | Set disk transfer address
2018-12-17T22:45:20.289495722Z 42 PC: 12aa7 | Get date 0x12aa7: cmp dl, 1
0x12aaa: je 0x12ab6
0x12aac: cmp dl, 0x15
0x12aaf: je 0x12ab6
0x12ab1: cmp dl, 0x18
0x12ab4: jne 0x12ab9
0x12ab6: call 0x12c07
0x12ab9: push ds
0x12aba: mov ds, word ptr cs:[0x2c]
0x12abf: xor si, si
0x12ac1: lodsb al, byte ptr [si]
0x12ac2: cmp al, 0x50
0x12ac4: jne 0x12ac1
0x12ac6: cmp word ptr [si], 0x5441
0x12aca: jne 0x12ac1
0x12acc: add si, 4
0x12acf: mov cx, 1
0x12ad2: mov bx, word ptr cs:[0x631]
0x12ad7: lodsb al, byte ptr [si]
0x12ad8: cmp al, 0x3b
2018-12-17T22:45:20.291863186Z 26 PC: 12b96 | Set disk transfer address

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8511,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:01.906897527Z 26 PC: 12aa0 | Set disk transfer address
2018-12-25T12:05:01.908325496Z 42 PC: 12aa7 | Get date 0x12aa7: cmp dl, 1
0x12aaa: je 0x12ab6
0x12aac: cmp dl, 0x15
0x12aaf: je 0x12ab6
0x12ab1: cmp dl, 0x18
0x12ab4: jne 0x12ab9
0x12ab6: call 0x12c07
0x12ab9: push ds
0x12aba: mov ds, word ptr cs:[0x2c]
0x12abf: xor si, si
0x12ac1: lodsb al, byte ptr [si]
0x12ac2: cmp al, 0x50
0x12ac4: jne 0x12ac1
0x12ac6: cmp word ptr [si], 0x5441
0x12aca: jne 0x12ac1
0x12acc: add si, 4
0x12acf: mov cx, 1
0x12ad2: mov bx, word ptr cs:[0x631]
0x12ad7: lodsb al, byte ptr [si]
0x12ad8: cmp al, 0x3b
2018-12-25T12:05:03.001769275Z 26 PC: 12b96 | Set disk transfer address

{"DateBased":true,"Day":2,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8511,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:02.417903286Z 26 PC: 12aa0 | Set disk transfer address
2018-12-25T12:05:02.419510542Z 42 PC: 12aa7 | Get date 0x12aa7: cmp dl, 1
0x12aaa: je 0x12ab6
0x12aac: cmp dl, 0x15
0x12aaf: je 0x12ab6
0x12ab1: cmp dl, 0x18
0x12ab4: jne 0x12ab9
0x12ab6: call 0x12c07
0x12ab9: push ds
0x12aba: mov ds, word ptr cs:[0x2c]
0x12abf: xor si, si
0x12ac1: lodsb al, byte ptr [si]
0x12ac2: cmp al, 0x50
0x12ac4: jne 0x12ac1
0x12ac6: cmp word ptr [si], 0x5441
0x12aca: jne 0x12ac1
0x12acc: add si, 4
0x12acf: mov cx, 1
0x12ad2: mov bx, word ptr cs:[0x631]
0x12ad7: lodsb al, byte ptr [si]
0x12ad8: cmp al, 0x3b
2018-12-25T12:05:02.42158973Z 26 PC: 12b96 | Set disk transfer address

{"DateBased":true,"Day":21,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8511,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:02.743106313Z 26 PC: 12aa0 | Set disk transfer address
2018-12-25T12:05:02.744725337Z 42 PC: 12aa7 | Get date 0x12aa7: cmp dl, 1
0x12aaa: je 0x12ab6
0x12aac: cmp dl, 0x15
0x12aaf: je 0x12ab6
0x12ab1: cmp dl, 0x18
0x12ab4: jne 0x12ab9
0x12ab6: call 0x12c07
0x12ab9: push ds
0x12aba: mov ds, word ptr cs:[0x2c]
0x12abf: xor si, si
0x12ac1: lodsb al, byte ptr [si]
0x12ac2: cmp al, 0x50
0x12ac4: jne 0x12ac1
0x12ac6: cmp word ptr [si], 0x5441
0x12aca: jne 0x12ac1
0x12acc: add si, 4
0x12acf: mov cx, 1
0x12ad2: mov bx, word ptr cs:[0x631]
0x12ad7: lodsb al, byte ptr [si]
0x12ad8: cmp al, 0x3b
2018-12-25T12:05:03.971659522Z 26 PC: 12b96 | Set disk transfer address

{"DateBased":true,"Day":24,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8511,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:04.124919567Z 26 PC: 12aa0 | Set disk transfer address
2018-12-25T12:05:04.126549203Z 42 PC: 12aa7 | Get date 0x12aa7: cmp dl, 1
0x12aaa: je 0x12ab6
0x12aac: cmp dl, 0x15
0x12aaf: je 0x12ab6
0x12ab1: cmp dl, 0x18
0x12ab4: jne 0x12ab9
0x12ab6: call 0x12c07
0x12ab9: push ds
0x12aba: mov ds, word ptr cs:[0x2c]
0x12abf: xor si, si
0x12ac1: lodsb al, byte ptr [si]
0x12ac2: cmp al, 0x50
0x12ac4: jne 0x12ac1
0x12ac6: cmp word ptr [si], 0x5441
0x12aca: jne 0x12ac1
0x12acc: add si, 4
0x12acf: mov cx, 1
0x12ad2: mov bx, word ptr cs:[0x631]
0x12ad7: lodsb al, byte ptr [si]
0x12ad8: cmp al, 0x3b
2018-12-25T12:05:05.688972924Z 26 PC: 12b96 | Set disk transfer address