Sample viewer

vx.netlux.org/Virus.DOS.Emmie.2604

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:01.246256043Z 42 PC: 13b1f | Get date 0x13b1f: mov byte ptr [bp - 0x62], 0
0x13b23: cmp cx, 0x7bc
0x13b27: je 0x13b37
0x13b29: cmp dh, byte ptr [bp - 0x74]
0x13b2c: jne 0x13b37
0x13b2e: cmp cx, word ptr [bp - 0x73]
0x13b31: jne 0x13b37
0x13b33: mov byte ptr [bp - 0x62], 1
0x13b37: mov byte ptr [bp - 0x74], dh
0x13b3a: mov word ptr [bp - 0x73], cx
0x13b3d: xor bx, bx
0x13b3f: mov ax, 0xface
0x13b42: int 0x21
0x13b44: cmp ax, 0xcefa
0x13b47: jne 0x13b51
0x13b49: cmp bx, 0xa
0x13b4c: jge 0x13b6b
0x13b4e: call 0x23a70
0x13b51: mov ax, 0x2c00
0x13b54: int 0x13
2018-12-17T22:51:01.249411729Z 250 PC: 13b44 | UNKNOWN!
2018-12-17T22:51:01.251412163Z 53 PC: 9f436 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:01.253378999Z 53 PC: 9f445 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:51:01.255738997Z 53 PC: 9f454 | Get interrupt vector (Interrupt = '38' AKA 'Create PSP')
2018-12-17T22:51:01.257450512Z 53 PC: 9f5fe | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:51:01.2591029Z 37 PC: 9f61c | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:51:01.261426617Z 25 PC: 9f62c | Get default drive
2018-12-17T22:51:01.262622078Z 37 PC: 9f63b | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:51:01.263928165Z 53 PC: 9f525 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:51:01.266323487Z 37 PC: 9f543 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:51:01.26879466Z 37 PC: 9f565 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:51:01.270048836Z 53 PC: 9f6ba | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:51:01.273841176Z 37 PC: 9f6d2 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:51:01.275779527Z 37 PC: 9f6f5 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:51:01.283771831Z 37 PC: 9f8a6 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:01.285276335Z 53 PC: 9f8a6 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:51:01.287035643Z 37 PC: 9f8a6 | Set interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:51:01.288284712Z 53 PC: 9f8a6 | Get interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-17T22:51:01.289618525Z 37 PC: 9f8a6 | Set interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-17T22:51:01.292027989Z 53 PC: 9f8a6 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:51:01.293470828Z 37 PC: 9f8a6 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T22:51:01.294893888Z 53 PC: 9f8a6 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:51:01.296822425Z 37 PC: 9f8a6 | Set interrupt vector (Interrupt = '9' AKA 'Display string')