Sample viewer

vx.netlux.org/Virus.DOS.Altx.2675

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:41.987699042Z 11 PC: 1672e | Get input status
2018-12-17T22:46:41.990917497Z 42 PC: 1672e | Get date 0x1672e: ret
0x1672f: mov si, 0x30
0x16732: mov di, si
0x16734: mov cx, 0x51f
0x16737: lodsw ax, word ptr [si]
0x16738: nop
0x16739: xor ax, 0x315
0x1673c: stosw word ptr es:[di], ax
0x1673d: loop 0x16737
0x1673f: ret
0x16740: mov ax, 0x440b
0x16743: mov bx, 0x1998
0x16746: mov cx, 0x315
0x16749: call 0x2672a
0x1674c: cmp bx, 0x315
0x16750: jne 0x1676c
0x16752: cmp cx, 0x1998
0x16756: jne 0x1676c
0x16758: cmp byte ptr [0x16e], 1
0x1675d: jne 0x16762
2018-12-17T22:46:41.993286246Z 74 PC: 1672e | Reallocate memory
2018-12-17T22:46:41.995124322Z 74 PC: 1672e | Reallocate memory
2018-12-17T22:46:41.997274113Z 72 PC: 1672e | Allocate memory
2018-12-17T22:46:41.998803578Z 72 PC: 1672e | Allocate memory
2018-12-17T22:46:42.000422135Z 53 PC: 1672e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:42.001819002Z 37 PC: 1672e | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:42.003609521Z 53 PC: 1672e | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:46:42.015794918Z 37 PC: 1672e | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:46:42.017850823Z 53 PC: 1672e | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:46:42.022046755Z 37 PC: 1672e | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:46:42.040636054Z 53 PC: 1688a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:42.041912781Z 53 PC: 1688a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:46:42.047803619Z 53 PC: 1688a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:46:42.049548712Z 53 PC: 1688a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:42.051193673Z 53 PC: 1688a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:42.062029605Z 53 PC: 1688a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:42.064290746Z 53 PC: 1688a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:46:42.066478624Z 53 PC: 1688a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:46:42.069816047Z 53 PC: 1688a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:46:42.071237572Z 53 PC: 1688a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:46:42.072598663Z 53 PC: 1688a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:46:42.076675915Z 53 PC: 1688a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:46:42.078128092Z 53 PC: 1688a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:46:42.079514906Z 53 PC: 1688a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:46:42.081455762Z 53 PC: 1688a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:46:42.083126312Z 53 PC: 1688a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:46:42.08467692Z 53 PC: 1688a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:46:42.093988824Z 53 PC: 1688a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:46:42.095305538Z 53 PC: 1688a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:46:42.09656078Z 37 PC: 1689f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:42.098462092Z 37 PC: 168a7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:42.100056124Z 37 PC: 168af | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:42.101544826Z 37 PC: 168b7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:46:42.10416341Z 68 PC: 175e8 | I/O control for devices (Set for = '')
2018-12-17T22:46:42.295883101Z 64 PC: 16ca8 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:46:42.298086572Z 37 PC: 169e1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:42.30038919Z 37 PC: 169e1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:46:42.301968098Z 37 PC: 169e1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:46:42.303486069Z 37 PC: 169e1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:42.305554038Z 37 PC: 169e1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:46:42.30730433Z 37 PC: 169e1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:46:42.30879967Z 37 PC: 169e1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:46:42.310833156Z 37 PC: 169e1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:46:42.312300052Z 37 PC: 169e1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:46:42.313793748Z 37 PC: 169e1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:46:42.315940542Z 37 PC: 169e1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:46:42.317727264Z 37 PC: 169e1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:46:42.31919462Z 37 PC: 169e1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:46:42.320823051Z 37 PC: 169e1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:46:42.323008566Z 37 PC: 169e1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:46:42.324470171Z 37 PC: 169e1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:46:42.325925055Z 37 PC: 169e1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:46:42.328241376Z 37 PC: 169e1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:46:42.329686557Z 37 PC: 169e1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:46:42.331158619Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.33440104Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.336740588Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.339102189Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.342320012Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.344651706Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.346989342Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.350120777Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.35274109Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.355062812Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.358080392Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.360689818Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.363008841Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.366009344Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.368648493Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.370977298Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.373959094Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.376580693Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.378921253Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.382232186Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.385294788Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.387669211Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.389986231Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.393286579Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.39531263Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.397351644Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.400178419Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.402457759Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.404769162Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.407381951Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.409674211Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.411989902Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.414534273Z 6 PC: 16a68 | Direct console I/O
2018-12-17T22:46:42.418282256Z 76 PC: 16a20 | Terminate with return code (Return code = '200')