Sample viewer

vx.netlux.org/Virus.DOS.Phardera.5824

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:50:38.961439937Z 48 PC: 13620 | Get DOS version
2018-12-17T22:50:38.964471672Z 44 PC: 13640 | Get time 0x13640: cmp ax, 0x312c
0x13643: jmp 0x13646
0x13645: lcall 0x1209:0xd4e8
0x1364a: add bl, ch
0x1364c: add word ptr [bp + si + 0x675], bx
0x13650: jmp 0x13653
0x13652: lcall 0xeb00:0xd5e9
0x13657: add word ptr [bp + si - 0x5018], bx
0x1365b: or cl, al
0x1365d: add byte ptr [si - 0x3bda], bl
0x13661: cmp al, 0x24
0x13663: popf
0x13664: inc dx
0x13665: jl 0x13610
0x13667: pop bx
0x13668: inc bx
0x1366a: mov al, byte ptr ds:[0xf283]
0x1366e: xchg ax, bx
0x1366f: aam 0x82
0x13671: fstp dword ptr [bp - 0x3a16]
2018-12-17T22:50:38.968103175Z 72 PC: 13675 | Allocate memory
2018-12-17T22:50:38.970004551Z 74 PC: 13688 | Reallocate memory
2018-12-17T22:50:38.979718958Z 72 PC: 13675 | Allocate memory
2018-12-17T22:50:38.982054384Z 37 PC: 1372b | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:50:38.983370749Z 9 PC: 12b37 | Display string (String= ' DummyC - Program Pemancing Virus Dibuat oleh xxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx xxxxxxxxxxxxxxxxxxxxxxxxxxx (c) 1995 xxxxxxxxxxxxe. Ukuran asli: 2560 byte Hati-Hati Virus Telah Aktif!! ')
2018-12-17T22:50:38.99991299Z 76 PC: 12b3c | Terminate with return code (Return code = '0')