Sample viewer

vx.netlux.org/Virus.DOS.Halka.1000.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:49.603147181Z 42 PC: 12c47 | Get date 0x12c47: cmp dh, 0xc
0x12c4a: jne 0x12c5f
0x12c4c: cmp dl, 0x1f
0x12c4f: jne 0x12c5f
0x12c51: mov ax, 0x900
0x12c54: lea dx, word ptr [bp + 0x166]
0x12c58: int 0x21
0x12c5a: mov ax, 0x4c00
0x12c5d: int 0x21
0x12c5f: cld
0x12c60: mov cx, 4
0x12c63: mov di, 0x100
0x12c66: lea si, word ptr [bp + 0x15c]
0x12c6a: rep movsb byte ptr es:[di], byte ptr [si]
0x12c6c: mov ax, 0x4e00
0x12c6f: mov cx, 0
0x12c72: lea dx, word ptr [bp + 0x160]
0x12c76: int 0x21
0x12c78: jae 0x12c8c
0x12c7a: mov cx, 0x2b
2018-12-17T22:46:49.605411485Z 78 PC: 12c78 | Find first file
2018-12-17T22:46:49.610175417Z 61 PC: 12c94 | Open file (Filename = '')
2018-12-17T22:46:49.611888956Z 63 PC: 12ca3 | Read file or device (Read 4 bytes on handle 2)

{"DateBased":true,"Day":1,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":9012,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:22:19.609207549Z 42 PC: 12c47 | Get date 0x12c47: cmp dh, 0xc
0x12c4a: jne 0x12c5f
0x12c4c: cmp dl, 0x1f
0x12c4f: jne 0x12c5f
0x12c51: mov ax, 0x900
0x12c54: lea dx, word ptr [bp + 0x166]
0x12c58: int 0x21
0x12c5a: mov ax, 0x4c00
0x12c5d: int 0x21
0x12c5f: cld
0x12c60: mov cx, 4
0x12c63: mov di, 0x100
0x12c66: lea si, word ptr [bp + 0x15c]
0x12c6a: rep movsb byte ptr es:[di], byte ptr [si]
0x12c6c: mov ax, 0x4e00
0x12c6f: mov cx, 0
0x12c72: lea dx, word ptr [bp + 0x160]
0x12c76: int 0x21
0x12c78: jae 0x12c8c
0x12c7a: mov cx, 0x2b
2018-12-25T12:22:19.613728521Z 78 PC: 12c78 | Find first file
2018-12-25T12:22:19.620793348Z 61 PC: 12c94 | Open file (Filename = '')
2018-12-25T12:22:19.623559136Z 63 PC: 12ca3 | Read file or device (Read 4 bytes on handle 2)

{"DateBased":true,"Day":31,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":9012,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:22:19.532870587Z 64 PC: 0 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T12:22:19.53975913Z 41 PC: 94fae | Parse filename
2018-12-25T12:22:19.544369371Z 41 PC: 9502f | Parse filename
2018-12-25T12:22:19.547106353Z 41 PC: 9504c | Parse filename
2018-12-25T12:22:19.550104716Z 26 PC: 984f7 | Set disk transfer address
2018-12-25T12:22:19.552117769Z 71 PC: 986f3 | Get current directory
2018-12-25T12:22:19.555189338Z 78 PC: 986fe | Find first file
2018-12-25T12:22:19.565081316Z 71 PC: 986f3 | Get current directory (See above)
2018-12-25T12:22:19.567839775Z 78 PC: 986fe | Find first file (See above)
2018-12-25T12:22:19.57833447Z 64 PC: 9a848 | Write file or device (Write 26 bytes on handle 2)
2018-12-25T12:22:19.584447272Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T12:22:19.587784441Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T12:22:19.58900707Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:22:19.590131331Z 62 PC: 122ab | Close file
2018-12-25T12:22:19.591581881Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:22:19.593225101Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:22:19.594745967Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:22:19.596189769Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:22:19.598184097Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:22:19.599617148Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:22:19.601022532Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:22:19.606815669Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:22:19.608239284Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:22:19.609613488Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:22:19.611341773Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:22:19.612664046Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:22:19.614087558Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:22:19.615899282Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:22:19.617757625Z 99 PC: 9a5d7 | Get DBCS lead byte table pointer
2018-12-25T12:22:19.618969178Z 56 PC: 94df9 | Get or set country info
2018-12-25T12:22:19.621154158Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T12:22:19.626038776Z 25 PC: 94e62 | Get default drive
2018-12-25T12:22:19.627735592Z 71 PC: 970dd | Get current directory
2018-12-25T12:22:19.634395418Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T12:22:19.6382328Z 2 PC: 970b2 | Character output (Char = '3e')
2018-12-25T12:22:19.640543701Z 93 PC: 94f20 | File sharing functions
2018-12-25T12:22:19.642430234Z 93 PC: 94f27 | File sharing functions
2018-12-25T12:22:19.644534979Z 10 PC: 94f39 | Buffered keyboard input
2018-12-25T12:22:34.579855924Z 0 PC: 0 | Program terminate (See above)
2018-12-25T12:22:35.934219105Z 0 PC: 0 | Program terminate (See above)
2018-12-25T12:22:36.036820703Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T12:22:36.043916123Z 41 PC: 94fae | Parse filename (See above)
2018-12-25T12:22:36.047283624Z 41 PC: 9502f | Parse filename (See above)
2018-12-25T12:22:36.05062805Z 41 PC: 9504c | Parse filename (See above)
2018-12-25T12:22:36.053275295Z 26 PC: 984f7 | Set disk transfer address (See above)
2018-12-25T12:22:36.067391216Z 71 PC: 986f3 | Get current directory (See above)
2018-12-25T12:22:36.094610041Z 78 PC: 986fe | Find first file (See above)
2018-12-25T12:22:36.10556346Z 71 PC: 9856c | Get current directory
2018-12-25T12:22:36.110148309Z 73 PC: 97c09 | Release memory
2018-12-25T12:22:36.112629165Z 75 PC: 11821 | Execute program
2018-12-25T12:22:36.127999568Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-25T12:22:36.133213887Z 76 PC: 12a4b | Terminate with return code (Return code = '36')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":9012,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:22:19.672731253Z 42 PC: 12c47 | Get date 0x12c47: cmp dh, 0xc
0x12c4a: jne 0x12c5f
0x12c4c: cmp dl, 0x1f
0x12c4f: jne 0x12c5f
0x12c51: mov ax, 0x900
0x12c54: lea dx, word ptr [bp + 0x166]
0x12c58: int 0x21
0x12c5a: mov ax, 0x4c00
0x12c5d: int 0x21
0x12c5f: cld
0x12c60: mov cx, 4
0x12c63: mov di, 0x100
0x12c66: lea si, word ptr [bp + 0x15c]
0x12c6a: rep movsb byte ptr es:[di], byte ptr [si]
0x12c6c: mov ax, 0x4e00
0x12c6f: mov cx, 0
0x12c72: lea dx, word ptr [bp + 0x160]
0x12c76: int 0x21
0x12c78: jae 0x12c8c
0x12c7a: mov cx, 0x2b
2018-12-25T12:22:19.675806348Z 78 PC: 12c78 | Find first file
2018-12-25T12:22:19.681852169Z 61 PC: 12c94 | Open file (Filename = '')
2018-12-25T12:22:19.683903841Z 63 PC: 12ca3 | Read file or device (Read 4 bytes on handle 2)