Sample viewer

vx.netlux.org/Virus.DOS.Corea.Nambul.695

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:48.664190076Z 44 PC: 12aa6 | Get time 0x12aa6: mov byte ptr ds:[bp + 0x10e], dl
0x12aab: mov byte ptr ds:[bp + 0x10c], dl
0x12ab0: mov byte ptr ds:[bp + 0x103], dl
0x12ab5: mov byte ptr ds:[bp + 0x104], dl
0x12aba: mov byte ptr ds:[bp + 0x105], dl
0x12abf: mov byte ptr ds:[bp + 0x106], dl
0x12ac4: mov byte ptr ds:[bp + 0x107], dl
0x12ac9: mov byte ptr ds:[bp + 0x108], dl
0x12ace: mov byte ptr ds:[bp + 0x109], dl
0x12ad3: mov byte ptr ds:[bp + 0x10a], dl
0x12ad8: lea si, word ptr [bp + 0x343]
0x12adc: mov cx, 0x2b7
0x12adf: mov al, byte ptr ds:[bp + 0x33a]
0x12ae4: xor byte ptr [si], al
0x12ae6: inc si
0x12ae7: loop 0x12ae4
0x12ae9: mov ah, 0x4e
0x12aeb: lea dx, word ptr [bp + 0x38b]
0x12aef: mov cx, 0
0x12af2: int 0x21
2018-12-17T22:52:48.667812491Z 78 PC: 12af4 | Find first file
2018-12-17T22:52:48.675958143Z 48 PC: 12b11 | Get DOS version
2018-12-17T22:52:48.677473409Z 53 PC: 12b20 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:48.679240148Z 9 PC: 12a47 | Display string (String= 'Mcrack V 3.05 Made By S.K [ ^ ^ ; ] ')