Sample viewer

vx.netlux.org/Virus.DOS.ARCV.Joanna.912

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:50:52.239647144Z 42 PC: 12a7c | Get date 0x12a7c: cmp dx, 0x1210
0x12a80: jne 0x12a8a
0x12a82: mov ah, 9
0x12a84: lea dx, word ptr [si + 0x3c8]
0x12a88: int 0x21
0x12a8a: mov di, 0x100
0x12a8d: push si
0x12a8e: mov ax, 0x482
0x12a91: add si, ax
0x12a93: mov cx, 5
0x12a96: cld
0x12a97: rep movsb byte ptr es:[di], byte ptr [si]
0x12a99: mov ax, 0xffa4
0x12a9c: int 0x21
0x12a9e: pop si
0x12a9f: cmp ax, 0x42a1
0x12aa2: je 0x12afd
0x12aa4: xor ax, ax
0x12aa6: push ax
0x12aa7: mov ax, ds
2018-12-17T22:50:52.242912178Z 255 PC: 12a9e | UNKNOWN!
2018-12-17T22:50:52.245830952Z 76 PC: 12a45 | Terminate with return code (Return code = '0')