Sample viewer

vx.netlux.org/Virus.DOS.DarkRevenge.1024

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:49:36.197030891Z 74 PC: 12ae3 | Reallocate memory
2018-12-17T22:49:36.199017509Z 75 PC: 12aee | Execute program
2018-12-17T22:49:36.218719527Z 53 PC: 12bef | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:49:36.220114231Z 42 PC: 12b2d | Get date 0x12b2d: cmp al, 1
0x12b2f: jne 0x12b34
0x12b31: call 0x12b91
0x12b34: push es
0x12b35: mov ax, 0x3521
0x12b38: int 0x21
0x12b3a: mov word ptr [0x12d], bx
0x12b3e: mov word ptr [0x12f], es
0x12b42: pop es
0x12b43: mov dx, 0x327
0x12b46: mov ax, 0x2521
0x12b49: int 0x21
0x12b4b: push es
0x12b4c: mov ax, word ptr cs:[0x2c]
0x12b50: mov es, ax
0x12b52: mov ah, 0x49
0x12b54: int 0x21
0x12b56: pop es
0x12b57: mov ah, 0x4d
0x12b59: int 0x21
2018-12-17T22:49:36.222426106Z 53 PC: 12b9a | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:49:36.224676494Z 37 PC: 12bab | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:49:36.226047736Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:49:36.227372459Z 37 PC: 12b4b | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:49:36.228640007Z 73 PC: 12b56 | Release memory
2018-12-17T22:49:36.230709392Z 77 PC: 12b5b | Get program return code
2018-12-17T22:49:36.231998831Z 49 PC: 12b62 | Terminate and stay resident (Return code = '0' | Memory size = '80')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":9944,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:26:46.006699531Z 74 PC: 12ae3 | Reallocate memory
2018-12-25T12:26:46.009192977Z 75 PC: 12aee | Execute program
2018-12-25T12:26:46.026729956Z 53 PC: 12bef | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:26:46.028257881Z 42 PC: 12b2d | Get date 0x12b2d: cmp al, 1
0x12b2f: jne 0x12b34
0x12b31: call 0x12b91
0x12b34: push es
0x12b35: mov ax, 0x3521
0x12b38: int 0x21
0x12b3a: mov word ptr [0x12d], bx
0x12b3e: mov word ptr [0x12f], es
0x12b42: pop es
0x12b43: mov dx, 0x327
0x12b46: mov ax, 0x2521
0x12b49: int 0x21
0x12b4b: push es
0x12b4c: mov ax, word ptr cs:[0x2c]
0x12b50: mov es, ax
0x12b52: mov ah, 0x49
0x12b54: int 0x21
0x12b56: pop es
0x12b57: mov ah, 0x4d
0x12b59: int 0x21
2018-12-25T12:26:46.030705065Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:26:46.032614096Z 37 PC: 12b4b | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:26:46.033973452Z 73 PC: 12b56 | Release memory
2018-12-25T12:26:46.035480332Z 77 PC: 12b5b | Get program return code
2018-12-25T12:26:46.037539211Z 49 PC: 12b62 | Terminate and stay resident (Return code = '0' | Memory size = '80')

{"DateBased":true,"Day":7,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":9944,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:26:46.195120747Z 74 PC: 12ae3 | Reallocate memory
2018-12-25T12:26:46.199409133Z 75 PC: 12aee | Execute program
2018-12-25T12:26:46.22105048Z 53 PC: 12bef | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:26:46.230220558Z 42 PC: 12b2d | Get date 0x12b2d: cmp al, 1
0x12b2f: jne 0x12b34
0x12b31: call 0x12b91
0x12b34: push es
0x12b35: mov ax, 0x3521
0x12b38: int 0x21
0x12b3a: mov word ptr [0x12d], bx
0x12b3e: mov word ptr [0x12f], es
0x12b42: pop es
0x12b43: mov dx, 0x327
0x12b46: mov ax, 0x2521
0x12b49: int 0x21
0x12b4b: push es
0x12b4c: mov ax, word ptr cs:[0x2c]
0x12b50: mov es, ax
0x12b52: mov ah, 0x49
0x12b54: int 0x21
0x12b56: pop es
0x12b57: mov ah, 0x4d
0x12b59: int 0x21
2018-12-25T12:26:46.23365168Z 53 PC: 12b9a | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:26:46.235548163Z 37 PC: 12bab | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-25T12:26:46.237346474Z 53 PC: 12b3a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:26:46.239173116Z 37 PC: 12b4b | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:26:46.241511282Z 73 PC: 12b56 | Release memory
2018-12-25T12:26:46.243220513Z 77 PC: 12b5b | Get program return code
2018-12-25T12:26:46.244773519Z 49 PC: 12b62 | Terminate and stay resident (Return code = '0' | Memory size = '80')