Sample viewer

vx.netlux.org/Virus.DOS.CivilWar.Dad.503

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:59.842558443Z 250 PC: 12a5d | UNKNOWN!
2018-12-17T22:45:59.844023233Z 42 PC: 12a61 | Get date 0x12a61: cmp dl, 0x10
0x12a64: jne 0x12a6c
0x12a66: call 0x12b4c
0x12a69: jmp 0x12b16
0x12a6c: lea dx, word ptr [bp + 0x2f7]
0x12a70: mov ah, 0x1a
0x12a72: int 0x21
0x12a74: mov ah, 0x4e
0x12a76: mov cx, 0x3f
0x12a79: lea dx, word ptr [bp + 0x1d7]
0x12a7d: int 0x21
0x12a7f: jb 0x12a88
0x12a81: lea dx, word ptr [bp + 0x315]
0x12a85: jmp 0x12a8e
0x12a87: nop
0x12a88: jmp 0x12b0f
0x12a8b: jmp 0x12b0a
0x12a8d: nop
0x12a8e: mov cx, 0
0x12a91: mov ax, 0x4301
2018-12-17T22:45:59.846250109Z 26 PC: 12a74 | Set disk transfer address
2018-12-17T22:45:59.84735902Z 78 PC: 12a7f | Find first file
2018-12-17T22:45:59.85388792Z 67 PC: 12a96 | Get or set file attributes
2018-12-17T22:45:59.881736579Z 61 PC: 12a9d | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:45:59.893814165Z 63 PC: 12aab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:45:59.90025286Z 66 PC: 12acb | Move file pointer
2018-12-17T22:45:59.90165682Z 64 PC: 12add | Write file or device (Write 503 bytes on handle 5)
2018-12-17T22:45:59.909288661Z 66 PC: 12ae6 | Move file pointer
2018-12-17T22:45:59.910501252Z 64 PC: 12af6 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:45:59.917780328Z 87 PC: 12b3a | Get or set file date and time
2018-12-17T22:45:59.919160219Z 62 PC: 12afd | Close file
2018-12-17T22:45:59.926764279Z 67 PC: 12b4b | Get or set file attributes
2018-12-17T22:45:59.93697408Z 26 PC: 12b16 | Set disk transfer address

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8734,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:48.259727123Z 250 PC: 12a5d | UNKNOWN!
2018-12-25T12:21:48.260576006Z 42 PC: 12a61 | Get date 0x12a61: cmp dl, 0x10
0x12a64: jne 0x12a6c
0x12a66: call 0x12b4c
0x12a69: jmp 0x12b16
0x12a6c: lea dx, word ptr [bp + 0x2f7]
0x12a70: mov ah, 0x1a
0x12a72: int 0x21
0x12a74: mov ah, 0x4e
0x12a76: mov cx, 0x3f
0x12a79: lea dx, word ptr [bp + 0x1d7]
0x12a7d: int 0x21
0x12a7f: jb 0x12a88
0x12a81: lea dx, word ptr [bp + 0x315]
0x12a85: jmp 0x12a8e
0x12a87: nop
0x12a88: jmp 0x12b0f
0x12a8b: jmp 0x12b0a
0x12a8d: nop
0x12a8e: mov cx, 0
0x12a91: mov ax, 0x4301
2018-12-25T12:21:48.264034942Z 26 PC: 12a74 | Set disk transfer address
2018-12-25T12:21:48.26518087Z 78 PC: 12a7f | Find first file
2018-12-25T12:21:48.271875571Z 67 PC: 12a96 | Get or set file attributes
2018-12-25T12:21:48.289027921Z 61 PC: 12a9d | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:21:48.294591445Z 63 PC: 12aab | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:21:48.303409319Z 66 PC: 12acb | Move file pointer
2018-12-25T12:21:48.308353608Z 64 PC: 12add | Write file or device (Write 503 bytes on handle 5)
2018-12-25T12:21:48.318176286Z 66 PC: 12ae6 | Move file pointer
2018-12-25T12:21:48.320072336Z 64 PC: 12af6 | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:21:48.329340139Z 87 PC: 12b3a | Get or set file date and time
2018-12-25T12:21:48.331163454Z 62 PC: 12afd | Close file
2018-12-25T12:21:48.340919395Z 67 PC: 12b4b | Get or set file attributes
2018-12-25T12:21:48.352440506Z 26 PC: 12b16 | Set disk transfer address

{"DateBased":true,"Day":16,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":8734,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:48.254878867Z 250 PC: 12a5d | UNKNOWN!
2018-12-25T12:21:48.255989067Z 42 PC: 12a61 | Get date 0x12a61: cmp dl, 0x10
0x12a64: jne 0x12a6c
0x12a66: call 0x12b4c
0x12a69: jmp 0x12b16
0x12a6c: lea dx, word ptr [bp + 0x2f7]
0x12a70: mov ah, 0x1a
0x12a72: int 0x21
0x12a74: mov ah, 0x4e
0x12a76: mov cx, 0x3f
0x12a79: lea dx, word ptr [bp + 0x1d7]
0x12a7d: int 0x21
0x12a7f: jb 0x12a88
0x12a81: lea dx, word ptr [bp + 0x315]
0x12a85: jmp 0x12a8e
0x12a87: nop
0x12a88: jmp 0x12b0f
0x12a8b: jmp 0x12b0a
0x12a8d: nop
0x12a8e: mov cx, 0
0x12a91: mov ax, 0x4301
2018-12-25T12:21:48.257752497Z 2 PC: 12b63 | Character output (Char = '20')
2018-12-25T12:21:48.262159924Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.264106549Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.266139488Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.267594051Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.269302622Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.271449795Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.273129785Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.274608173Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.276658238Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.278105073Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.279399787Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.281566727Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.283280858Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.284723817Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.286856853Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.288711179Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.290507274Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.292767869Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.294855446Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.297033914Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.299853857Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.301789019Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.303664562Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.305514244Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.309837252Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.312456058Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.315148432Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.323657051Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.326016721Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.328764432Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.332357037Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.335021185Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.337771553Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.342009756Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.344536873Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.348571453Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.352323352Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.354882801Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.35673909Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.358753821Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.361104387Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.36274774Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.364485261Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.366746474Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.368489494Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.370260915Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.372791494Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.374647458Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.376549006Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.37986326Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.384306715Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.386603497Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.392099237Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.394811199Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.397562966Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.401060014Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.404204106Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.406967203Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.409793756Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.4138314Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.416257351Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.419352853Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.422046161Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.424889013Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.427750885Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.431044484Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.433411455Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.43568767Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.438711321Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.441492281Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.44404021Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.447120013Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.44961446Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.453392846Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.457615819Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.460000218Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.462340455Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.465756817Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.467488985Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.468964593Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.470445782Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.472658316Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.474252225Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.4757289Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.477843301Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.479402524Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.481013504Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.482773386Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.484199426Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.485535333Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.487360066Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.488796054Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.490071882Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.491950375Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.494170992Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.49648835Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.504273433Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.508933643Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.511213162Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.515840206Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.518189031Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.520452282Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.523058255Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.525269771Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.527236685Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.529614801Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.531428129Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.534015298Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.536529033Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.538339824Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.539899518Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.541605333Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.543305942Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.544960656Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.546619567Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.54911342Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.551306674Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.553884825Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.556910706Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.559195344Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.561722166Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.574210842Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.575891353Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.577682862Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.580021506Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.581644866Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.58325912Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.585306641Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.586933605Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.588554537Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.590470677Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.592090785Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.593810358Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.59611847Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.597744783Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.600006242Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.604433376Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.607083741Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.609799905Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.614908371Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.618484895Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.621131527Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.623658303Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.626330084Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.628477969Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.631219347Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.633625502Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.636542462Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.639321933Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.642041661Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.64509903Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.647974586Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.650694969Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.653151284Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.655836411Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.658102407Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.661037132Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.664737749Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.667544516Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.670336828Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.674171177Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.676622461Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.679124137Z 2 PC: 12b63 | Character output (See above)
2018-12-25T12:21:48.683648795Z 2 PC: 12b63 | Character output (See above)