Sample viewer

vx.netlux.org/Virus.DOS.Rogue.1213

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:00.98728485Z 254 PC: 1c9f3 | UNKNOWN!
2018-12-17T22:51:00.988706847Z 74 PC: 1ca36 | Reallocate memory
2018-12-17T22:51:00.990443444Z 74 PC: 1ca3e | Reallocate memory
2018-12-17T22:51:00.991873263Z 72 PC: 1ca45 | Allocate memory
2018-12-17T22:51:00.994862815Z 53 PC: 1ca58 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:00.996118736Z 37 PC: 1ca76 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:00.997360224Z 42 PC: 1ca7a | Get date 0x1ca7a: push cx
0x1ca7b: mov cx, 8
0x1ca7e: shr dx, cl
0x1ca80: pop cx
0x1ca81: add cx, dx
0x1ca83: cmp cx, 0x7d0
0x1ca87: jb 0x1caad
0x1ca89: cmp al, 1
0x1ca8b: jne 0x1caad
0x1ca8d: mov ax, 0x3508
0x1ca90: int 0x21
0x1ca92: mov word ptr [0x488], 0x7e90
0x1ca98: mov word ptr [0x107], bx
0x1ca9c: mov word ptr [0x109], es
0x1caa0: mov ax, 0x2508
0x1caa3: mov dx, 0x1e2
0x1caa6: int 0x21
0x1caa8: mov byte ptr [0x132], 1
0x1caad: pop ax
0x1caae: mov es, ax
2018-12-17T22:51:01.000678686Z 53 PC: 1ca92 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:51:01.002265622Z 37 PC: 1caa8 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:51:01.019157317Z 74 PC: 12add | Reallocate memory
2018-12-17T22:51:01.022090862Z 48 PC: 12af9 | Get DOS version
2018-12-17T22:51:01.023932211Z 55 PC: 12b08 | Get or set switch character
2018-12-17T22:51:01.025432012Z 48 PC: 12b21 | Get DOS version
2018-12-17T22:51:01.038400371Z 56 PC: 1f6ab | Get or set country info
2018-12-17T22:51:01.039807137Z 102 PC: 1f6b7 | Get or set code page
2018-12-17T22:51:01.041782086Z 2 PC: 1f0d7 | Character output (Char = '41')
2018-12-17T22:51:01.044266919Z 2 PC: 1f0d7 | Character output (Char = '44')
2018-12-17T22:51:01.046752951Z 2 PC: 1f0d7 | Character output (Char = '2d')
2018-12-17T22:51:01.048789434Z 2 PC: 1f0d7 | Character output (Char = '41')
2018-12-17T22:51:01.051238495Z 2 PC: 1f0d7 | Character output (Char = '63')
2018-12-17T22:51:01.053353622Z 2 PC: 1f0d7 | Character output (Char = '65')
2018-12-17T22:51:01.055374068Z 2 PC: 1f0d7 | Character output (Char = '6c')
2018-12-17T22:51:01.069425319Z 2 PC: 1f0d7 | Character output (Char = '65')
2018-12-17T22:51:01.07145188Z 2 PC: 1f0d7 | Character output (Char = '72')
2018-12-17T22:51:01.073439159Z 2 PC: 1f0d7 | Character output (Char = '61')
2018-12-17T22:51:01.075876492Z 2 PC: 1f0d7 | Character output (Char = '72')