Sample viewer

vx.netlux.org/Virus.DOS.Disillu.1108

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:49.385597504Z 42 PC: 12a5a | Get date 0x12a5a: cmp dx, 0x405
0x12a5e: jb 0x12a69
0x12a60: cmp dx, 0x409
0x12a64: ja 0x12a69
0x12a66: call 0x12d63
0x12a69: mov ah, 0xff
0x12a6b: int 0x21
0x12a6d: cmp ax, 0xdead
0x12a70: jne 0x12a76
0x12a72: mov ah, 0xfe
0x12a74: int 0x21
0x12a76: mov ax, 0x3521
0x12a79: int 0x21
0x12a7b: mov word ptr cs:[0x281], bx
0x12a80: mov word ptr cs:[0x283], es
0x12a85: mov word ptr cs:[0x242], 0x530
0x12a8c: mov word ptr cs:[0x249], 0x532
0x12a93: mov word ptr cs:[0x213], 0x7203
0x12a9a: clc
0x12a9b: mov ax, 0x3501
2018-12-17T22:45:49.393065663Z 255 PC: 12a6d | UNKNOWN!
2018-12-17T22:45:49.394173175Z 53 PC: 12a7b | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:49.395594853Z 53 PC: 12aa0 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:45:49.397682651Z 37 PC: 12ab0 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:45:49.400095704Z 82 PC: 12ac2 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:45:49.405001725Z 37 PC: 12b00 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:45:49.407217118Z 37 PC: 12d62 | Set interrupt vector (Interrupt = '33' AKA 'Random read')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8672,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:40.575871141Z 42 PC: 12a5a | Get date 0x12a5a: cmp dx, 0x405
0x12a5e: jb 0x12a69
0x12a60: cmp dx, 0x409
0x12a64: ja 0x12a69
0x12a66: call 0x12d63
0x12a69: mov ah, 0xff
0x12a6b: int 0x21
0x12a6d: cmp ax, 0xdead
0x12a70: jne 0x12a76
0x12a72: mov ah, 0xfe
0x12a74: int 0x21
0x12a76: mov ax, 0x3521
0x12a79: int 0x21
0x12a7b: mov word ptr cs:[0x281], bx
0x12a80: mov word ptr cs:[0x283], es
0x12a85: mov word ptr cs:[0x242], 0x530
0x12a8c: mov word ptr cs:[0x249], 0x532
0x12a93: mov word ptr cs:[0x213], 0x7203
0x12a9a: clc
0x12a9b: mov ax, 0x3501
2018-12-25T12:21:40.578588668Z 255 PC: 12a6d | UNKNOWN!
2018-12-25T12:21:40.579718272Z 53 PC: 12a7b | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:21:40.580940539Z 53 PC: 12aa0 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T12:21:40.582360235Z 37 PC: 12ab0 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T12:21:40.584751169Z 82 PC: 12ac2 | Get DOS internal pointers (SYSVARS)
2018-12-25T12:21:40.58971128Z 37 PC: 12b00 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T12:21:40.592063248Z 37 PC: 12d62 | Set interrupt vector (Interrupt = '33' AKA 'Random read')

{"DateBased":true,"Day":5,"Month":4,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8672,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:40.715595218Z 42 PC: 12a5a | Get date 0x12a5a: cmp dx, 0x405
0x12a5e: jb 0x12a69
0x12a60: cmp dx, 0x409
0x12a64: ja 0x12a69
0x12a66: call 0x12d63
0x12a69: mov ah, 0xff
0x12a6b: int 0x21
0x12a6d: cmp ax, 0xdead
0x12a70: jne 0x12a76
0x12a72: mov ah, 0xfe
0x12a74: int 0x21
0x12a76: mov ax, 0x3521
0x12a79: int 0x21
0x12a7b: mov word ptr cs:[0x281], bx
0x12a80: mov word ptr cs:[0x283], es
0x12a85: mov word ptr cs:[0x242], 0x530
0x12a8c: mov word ptr cs:[0x249], 0x532
0x12a93: mov word ptr cs:[0x213], 0x7203
0x12a9a: clc
0x12a9b: mov ax, 0x3501
2018-12-25T12:21:40.718088136Z 9 PC: 12d6c | Display string (String= ' Your Computers Just A Microscopic Cog, In My Catastrophic Plan. Designed and Directed - By My Red Right Hand.... [D�SiLL�S��N�S�] by -=S�p�L�r�=- Dedicated To Kurt Cobain, 1967 - 1994. << PRESS A KEY >> ')

{"DateBased":true,"Day":10,"Month":4,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8672,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:41.131889779Z 42 PC: 12a5a | Get date 0x12a5a: cmp dx, 0x405
0x12a5e: jb 0x12a69
0x12a60: cmp dx, 0x409
0x12a64: ja 0x12a69
0x12a66: call 0x12d63
0x12a69: mov ah, 0xff
0x12a6b: int 0x21
0x12a6d: cmp ax, 0xdead
0x12a70: jne 0x12a76
0x12a72: mov ah, 0xfe
0x12a74: int 0x21
0x12a76: mov ax, 0x3521
0x12a79: int 0x21
0x12a7b: mov word ptr cs:[0x281], bx
0x12a80: mov word ptr cs:[0x283], es
0x12a85: mov word ptr cs:[0x242], 0x530
0x12a8c: mov word ptr cs:[0x249], 0x532
0x12a93: mov word ptr cs:[0x213], 0x7203
0x12a9a: clc
0x12a9b: mov ax, 0x3501
2018-12-25T12:21:41.134772033Z 255 PC: 12a6d | UNKNOWN!
2018-12-25T12:21:41.136132475Z 53 PC: 12a7b | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:21:41.137656738Z 53 PC: 12aa0 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T12:21:41.139312787Z 37 PC: 12ab0 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T12:21:41.14142743Z 82 PC: 12ac2 | Get DOS internal pointers (SYSVARS)
2018-12-25T12:21:41.146670624Z 37 PC: 12b00 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T12:21:41.149112534Z 37 PC: 12d62 | Set interrupt vector (Interrupt = '33' AKA 'Random read')