Sample viewer

vx.netlux.org/Virus.DOS.Kontragapi

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:55.223343326Z 42 PC: 13665 | Get date 0x13665: cld
0x13666: mov si, 0x500
0x13669: mov cx, 0x100
0x1366c: cmp dx, 0x1998
0x13670: je 0x13686
0x13672: mov di, cx
0x13674: mov cx, 0x8de
0x13677: rep movsb byte ptr es:[di], byte ptr [si]
0x13679: mov di, 0x84
0x1367c: mov ax, es
0x1367e: add ax, 0x10
0x13681: push ax
0x13682: push 0x858
0x13685: retf
0x13686: mov ax, 0x104
0x13689: mov di, 0x108
0x1368c: add si, 0x3eb
0x13690: add di, cx
0x13692: movsw word ptr es:[di], word ptr [si]
0x13693: movsb byte ptr es:[di], byte ptr [si]
2018-12-17T22:51:55.225560873Z 74 PC: 132a0 | Reallocate memory
2018-12-17T22:51:55.226784118Z 75 PC: 12ddd | Execute program
2018-12-17T22:51:55.236436752Z 9 PC: 144a5 | Display string (String= ' Mabuhay! This program came from Bahay Kawayan at http://come.to/hexfiles Putoksa Kawayan [email protected] ')
2018-12-17T22:51:55.251879311Z 76 PC: 144a9 | Terminate with return code (Return code = '36')
2018-12-17T22:51:55.255418641Z 77 PC: 12ddd | Get program return code
2018-12-17T22:51:55.256560773Z 73 PC: 12ddd | Release memory
2018-12-17T22:51:55.257967087Z 49 PC: 1331e | Terminate and stay resident (Return code = '36' | Memory size = '399')