Sample viewer

vx.netlux.org/Virus.DOS.LazyToday.1203

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:47:35.604192873Z 253 PC: 9f795 | UNKNOWN!
2018-12-17T22:47:35.606306959Z 48 PC: 9f79e | Get DOS version
2018-12-17T22:47:35.607516122Z 42 PC: 9f801 | Get date 0x9f801: cmp cx, 0x7cb
0x9f805: jne 0x9f833
0x9f807: cmp dh, 1
0x9f80a: jne 0x9f833
0x9f80c: inc word ptr [0xc3]
0x9f810: mov bx, 0x3ca
0x9f813: push bx
0x9f814: sub byte ptr [bx], 0x23
0x9f817: inc bx
0x9f818: cmp byte ptr [bx], 0x24
0x9f81b: jne 0x9f814
0x9f81d: mov ah, 9
0x9f81f: mov dx, 0x3ca
0x9f822: int 0x21
0x9f824: pop bx
0x9f825: add byte ptr [bx], 0x23
0x9f828: inc bx
0x9f829: cmp byte ptr [bx], 0x24
0x9f82c: jne 0x9f825
0x9f82e: mov byte ptr [0x41c], 1
2018-12-17T22:47:35.609640838Z 53 PC: 9f838 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:35.611443809Z 37 PC: 9f848 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:35.612732105Z 9 PC: 133f2 | Display string (Could not find end pointer)
2018-12-17T22:47:35.618583547Z 76 PC: 133f8 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":9269,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:22:45.649985631Z 253 PC: 9f795 | UNKNOWN!
2018-12-25T12:22:45.651635171Z 48 PC: 9f79e | Get DOS version
2018-12-25T12:22:45.653007081Z 42 PC: 9f801 | Get date 0x9f801: cmp cx, 0x7cb
0x9f805: jne 0x9f833
0x9f807: cmp dh, 1
0x9f80a: jne 0x9f833
0x9f80c: inc word ptr [0xc3]
0x9f810: mov bx, 0x3ca
0x9f813: push bx
0x9f814: sub byte ptr [bx], 0x23
0x9f817: inc bx
0x9f818: cmp byte ptr [bx], 0x24
0x9f81b: jne 0x9f814
0x9f81d: mov ah, 9
0x9f81f: mov dx, 0x3ca
0x9f822: int 0x21
0x9f824: pop bx
0x9f825: add byte ptr [bx], 0x23
0x9f828: inc bx
0x9f829: cmp byte ptr [bx], 0x24
0x9f82c: jne 0x9f825
0x9f82e: mov byte ptr [0x41c], 1
2018-12-25T12:22:45.655447969Z 53 PC: 9f838 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:45.664415672Z 37 PC: 9f848 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:45.666284606Z 9 PC: 133f2 | Display string (Could not find end pointer)
2018-12-25T12:22:45.67284176Z 76 PC: 133f8 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1995,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":9269,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:22:46.58212326Z 253 PC: 9f795 | UNKNOWN!
2018-12-25T12:22:46.583860226Z 48 PC: 9f79e | Get DOS version
2018-12-25T12:22:46.585323548Z 42 PC: 9f801 | Get date 0x9f801: cmp cx, 0x7cb
0x9f805: jne 0x9f833
0x9f807: cmp dh, 1
0x9f80a: jne 0x9f833
0x9f80c: inc word ptr [0xc3]
0x9f810: mov bx, 0x3ca
0x9f813: push bx
0x9f814: sub byte ptr [bx], 0x23
0x9f817: inc bx
0x9f818: cmp byte ptr [bx], 0x24
0x9f81b: jne 0x9f814
0x9f81d: mov ah, 9
0x9f81f: mov dx, 0x3ca
0x9f822: int 0x21
0x9f824: pop bx
0x9f825: add byte ptr [bx], 0x23
0x9f828: inc bx
0x9f829: cmp byte ptr [bx], 0x24
0x9f82c: jne 0x9f825
0x9f82e: mov byte ptr [0x41c], 1
2018-12-25T12:22:46.587887009Z 9 PC: 9f824 | Display string (String= 'Forget it, I'm lazy today!')
2018-12-25T12:22:46.591359442Z 53 PC: 9f838 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:46.592637034Z 37 PC: 9f848 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:46.593820296Z 76 PC: 9f85b | Terminate with return code (Return code = '33')

{"DateBased":true,"Day":1,"Month":2,"Year":1995,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":9269,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:22:46.974886639Z 253 PC: 9f795 | UNKNOWN!
2018-12-25T12:22:46.976046164Z 48 PC: 9f79e | Get DOS version
2018-12-25T12:22:46.977379984Z 42 PC: 9f801 | Get date 0x9f801: cmp cx, 0x7cb
0x9f805: jne 0x9f833
0x9f807: cmp dh, 1
0x9f80a: jne 0x9f833
0x9f80c: inc word ptr [0xc3]
0x9f810: mov bx, 0x3ca
0x9f813: push bx
0x9f814: sub byte ptr [bx], 0x23
0x9f817: inc bx
0x9f818: cmp byte ptr [bx], 0x24
0x9f81b: jne 0x9f814
0x9f81d: mov ah, 9
0x9f81f: mov dx, 0x3ca
0x9f822: int 0x21
0x9f824: pop bx
0x9f825: add byte ptr [bx], 0x23
0x9f828: inc bx
0x9f829: cmp byte ptr [bx], 0x24
0x9f82c: jne 0x9f825
0x9f82e: mov byte ptr [0x41c], 1
2018-12-25T12:22:46.979616566Z 53 PC: 9f838 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:46.980878569Z 37 PC: 9f848 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:22:46.982923892Z 9 PC: 133f2 | Display string (Could not find end pointer)
2018-12-25T12:22:46.98965764Z 76 PC: 133f8 | Terminate with return code (Return code = '0')