Sample viewer

vx.netlux.org/Virus.DOS.Deicide.Comment.2568

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:09.251287364Z 26 PC: 12a63 | Set disk transfer address
2018-12-17T22:53:09.252763436Z 78 PC: 12a6d | Find first file
2018-12-17T22:53:09.259452696Z 79 PC: 12aac | Find next file
2018-12-17T22:53:09.261862551Z 79 PC: 12aac | Find next file
2018-12-17T22:53:09.272791437Z 79 PC: 12aac | Find next file
2018-12-17T22:53:09.275258911Z 79 PC: 12aac | Find next file
2018-12-17T22:53:09.277597579Z 79 PC: 12aac | Find next file
2018-12-17T22:53:09.28047124Z 79 PC: 12aac | Find next file
2018-12-17T22:53:09.282941692Z 79 PC: 12aac | Find next file
2018-12-17T22:53:09.28541526Z 61 PC: 12a8c | Open file (Filename = 'TEST.COM')
2018-12-17T22:53:09.292192321Z 63 PC: 12a9b | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:53:09.294681421Z 62 PC: 12a9f | Close file
2018-12-17T22:53:09.296306115Z 79 PC: 12aac | Find next file
2018-12-17T22:53:09.299399352Z 26 PC: 12b3c | Set disk transfer address
2018-12-17T22:53:09.300490878Z 44 PC: 12b40 | Get time 0x12b40: xor dl, dl
0x12b42: xchg dl, dh
0x12b44: add dx, dx
0x12b46: add dx, 0x218
0x12b4a: mov si, dx
0x12b4c: mov dx, word ptr cs:[si]
0x12b4f: mov ah, 9
0x12b51: int 0x21
0x12b53: jmp word ptr cs:[0xace]
0x12b58: nop
0x12b59: add ch, byte ptr [bp + si - 0x42fe]
0x12b5d: add bl, ch
0x12b5f: add al, byte ptr [bp + di]
0x12b61: add sp, word ptr [bx]
0x12b63: add ax, word ptr [si + 3]
0x12b66: insw word ptr es:[di], dx
0x12b67: add cx, word ptr [bp + si - 0x52fd]
0x12b6b: add cx, cx
0x12b6d: add sp, cx
0x12b6f: add di, cx
2018-12-17T22:53:09.302471193Z 9 PC: 12b53 | Display string (String= ' Yech, you are reminding me of my mother-in-law... ')