Sample viewer

vx.netlux.org/Virus.DOS.Avalon.814

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:48:26.478289181Z 255 PC: 12e6f | UNKNOWN!
2018-12-17T22:48:26.480082052Z 53 PC: 12ec1 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:48:26.482450052Z 37 PC: 12ed0 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:48:26.484746594Z 42 PC: 130fd | Get date 0x130fd: cmp cx, 0x7c9
0x13101: jb 0x13127
0x13103: cmp dl, 0x1f
0x13106: jne 0x13127
0x13108: mov ax, 0x301
0x1310b: mov cx, 1
0x1310e: mov dx, 0x80
0x13111: int 0x13
0x13113: mov ax, 0x351c
0x13116: int 0x21
0x13118: mov word ptr [0x121], bx
0x1311c: mov word ptr [0x123], es
0x13120: mov dx, 0x400
0x13123: mov ah, 0x25
0x13125: int 0x21
0x13127: ret
0x13128: push ax
0x13129: push es
0x1312a: push di
0x1312b: push si
2018-12-17T22:48:26.488227082Z 9 PC: 12e26 | Display string (String= 'BCDEF- This is a 1000 byte COM test, 1994 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":9554,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:23:19.233331378Z 255 PC: 12e6f | UNKNOWN!
2018-12-25T12:23:19.234542821Z 53 PC: 12ec1 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:23:19.23617494Z 37 PC: 12ed0 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:23:19.237470289Z 42 PC: 130fd | Get date 0x130fd: cmp cx, 0x7c9
0x13101: jb 0x13127
0x13103: cmp dl, 0x1f
0x13106: jne 0x13127
0x13108: mov ax, 0x301
0x1310b: mov cx, 1
0x1310e: mov dx, 0x80
0x13111: int 0x13
0x13113: mov ax, 0x351c
0x13116: int 0x21
0x13118: mov word ptr [0x121], bx
0x1311c: mov word ptr [0x123], es
0x13120: mov dx, 0x400
0x13123: mov ah, 0x25
0x13125: int 0x21
0x13127: ret
0x13128: push ax
0x13129: push es
0x1312a: push di
0x1312b: push si
2018-12-25T12:23:19.239920106Z 9 PC: 12e26 | Display string (String= 'BCDEF- This is a 1000 byte COM test, 1994 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1993,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":9554,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:23:19.523950836Z 255 PC: 12e6f | UNKNOWN!
2018-12-25T12:23:19.525619579Z 53 PC: 12ec1 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:23:19.527141837Z 37 PC: 12ed0 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:23:19.528593303Z 42 PC: 130fd | Get date 0x130fd: cmp cx, 0x7c9
0x13101: jb 0x13127
0x13103: cmp dl, 0x1f
0x13106: jne 0x13127
0x13108: mov ax, 0x301
0x1310b: mov cx, 1
0x1310e: mov dx, 0x80
0x13111: int 0x13
0x13113: mov ax, 0x351c
0x13116: int 0x21
0x13118: mov word ptr [0x121], bx
0x1311c: mov word ptr [0x123], es
0x13120: mov dx, 0x400
0x13123: mov ah, 0x25
0x13125: int 0x21
0x13127: ret
0x13128: push ax
0x13129: push es
0x1312a: push di
0x1312b: push si
2018-12-25T12:23:19.531533748Z 9 PC: 12e26 | Display string (String= 'BCDEF- This is a 1000 byte COM test, 1994 ')

{"DateBased":true,"Day":31,"Month":1,"Year":1993,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":9554,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:23:19.539561025Z 255 PC: 12e6f | UNKNOWN!
2018-12-25T12:23:19.541114166Z 53 PC: 12ec1 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:23:19.542898382Z 37 PC: 12ed0 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:23:19.544563732Z 42 PC: 130fd | Get date 0x130fd: cmp cx, 0x7c9
0x13101: jb 0x13127
0x13103: cmp dl, 0x1f
0x13106: jne 0x13127
0x13108: mov ax, 0x301
0x1310b: mov cx, 1
0x1310e: mov dx, 0x80
0x13111: int 0x13
0x13113: mov ax, 0x351c
0x13116: int 0x21
0x13118: mov word ptr [0x121], bx
0x1311c: mov word ptr [0x123], es
0x13120: mov dx, 0x400
0x13123: mov ah, 0x25
0x13125: int 0x21
0x13127: ret
0x13128: push ax
0x13129: push es
0x1312a: push di
0x1312b: push si
2018-12-25T12:23:19.993190664Z 53 PC: 13118 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:23:19.996430242Z 37 PC: 13127 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-25T12:23:19.998564585Z 9 PC: 12e26 | Display string (String= 'BCDEF- This is a 1000 byte COM test, 1994 ')