Sample viewer

vx.netlux.org/Virus.DOS.Pizelun.3599.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:00.046231166Z 75 PC: 12e79 | Execute program
2018-12-17T22:51:00.048631735Z 48 PC: 12e8a | Get DOS version
2018-12-17T22:51:00.050270644Z 53 PC: 12ef2 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:00.052290278Z 82 PC: 12f44 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:51:00.053737687Z 37 PC: 12f59 | Set interrupt vector (Interrupt = '105' AKA 'Get or set media id')
2018-12-17T22:51:00.057178041Z 53 PC: 12f60 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:51:00.066316238Z 53 PC: 12f72 | Get interrupt vector (Interrupt = '21' AKA 'Sequential write')
2018-12-17T22:51:00.06822276Z 53 PC: 12f84 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:51:00.071032789Z 82 PC: 12f95 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:51:00.073006005Z 37 PC: 1302b | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:00.07454673Z 42 PC: 13036 | Get date 0x13036: mov word ptr [0xdfc], cx
0x1303a: rol cx, 1
0x1303c: cmp dh, 5
0x1303f: je 0x13044
0x13041: jmp 0x130e0
0x13044: mov cx, word ptr [0xdfc]
0x13048: cmp cx, 0x7cb
0x1304c: je 0x130a0
0x1304e: jmp 0x130e0
0x13051: or ax, 0x500a
0x13054: dec cx
0x13055: pop dx
0x13056: inc bp
0x13057: dec sp
0x13058: push bp
0x13059: dec si
0x1305a: and byte ptr [bx + di + 0x74], ah
0x1305d: je 0x130c8
0x1305f: jbe 0x130c2
0x13061: je 0x130d2