Sample viewer

vx.netlux.org/Virus.DOS.CivilWar.611

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:33.118144614Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:53:33.120598333Z 42 PC: 12a56 | Get date 0x12a56: in al, 0x21
0x12a58: cmp cx, 0x7c9
0x12a5c: ja 0x12a66
0x12a5e: cmp dh, 4
0x12a61: ja 0x12a66
0x12a63: jmp 0x12ada
0x12a66: or al, 2
0x12a68: push ax
0x12a69: mov ax, 0x351c
0x12a6c: int 0x21
0x12a6e: mov word ptr cs:[bp + 0x2a9], bx
0x12a73: mov word ptr cs:[bp + 0x2ab], es
0x12a78: pop ax
0x12a79: out 0x21, al
0x12a7b: mov ax, 0x3521
0x12a7e: int 0x21
0x12a80: mov word ptr cs:[bp + 0x1c9], bx
0x12a85: mov word ptr cs:[bp + 0x1cb], es
0x12a8a: in al, 0x21
0x12a8c: and al, 2
2018-12-17T22:53:33.123796341Z 53 PC: 12a6e | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:53:33.125407367Z 53 PC: 12a80 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:33.12713907Z 37 PC: 12ad2 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:53:33.130257437Z 37 PC: 12ada | Set interrupt vector (Interrupt = '33' AKA 'Random read')