Sample viewer

vx.netlux.org/Virus.DOS.BackFont.821

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:50:09.27672744Z 48 PC: 12c4f | Get DOS version
2018-12-17T22:50:09.278277643Z 194 PC: 12c5b | UNKNOWN!
2018-12-17T22:50:09.280813748Z 53 PC: 9ebc4 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:09.282400739Z 37 PC: 9ebd4 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:09.283985526Z 42 PC: 9eb88 | Get date 0x9eb88: cmp cx, word ptr [0x1e]
0x9eb8c: jb 0x9eb9e
0x9eb8e: ja 0x9eba3
0x9eb90: cmp dh, byte ptr [0x1d]
0x9eb94: jb 0x9eb9e
0x9eb96: ja 0x9eba3
0x9eb98: cmp dl, byte ptr [0x1c]
0x9eb9c: jae 0x9eba3
0x9eb9e: and byte ptr [0x343], 0xfe
0x9eba3: add dh, 3
0x9eba6: cmp dh, 0xc
0x9eba9: jbe 0x9ebaf
0x9ebab: sub dh, 0xc
0x9ebae: inc cx
0x9ebaf: mov word ptr [0x1e], cx
0x9ebb3: mov word ptr [0x1c], dx
0x9ebb7: ret
0x9ebb8: push cs
0x9ebb9: pop ds
0x9ebba: mov byte ptr [0x343], 1
2018-12-17T22:50:09.28783088Z 76 PC: 12c17 | Terminate with return code (Return code = '0')