Sample viewer

vx.netlux.org/Virus.DOS.TPE.Duwende.1852

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:41.677976496Z 255 PC: 12b2c | UNKNOWN!
2018-12-17T22:54:41.679897598Z 74 PC: 12b47 | Reallocate memory
2018-12-17T22:54:41.681803389Z 72 PC: 12b4f | Allocate memory
2018-12-17T22:54:41.683918274Z 44 PC: 9fb57 | Get time 0x9fb57: in al, 0x40
0x9fb59: mov ah, al
0x9fb5b: in al, 0x40
0x9fb5d: xor ax, cx
0x9fb5f: xor dx, ax
0x9fb61: jmp 0x9fb7e
0x9fb63: push dx
0x9fb64: push cx
0x9fb65: push bx
0x9fb66: mov ax, 0x23c5
0x9fb69: mov dx, 0x3006
0x9fb6c: mov cx, 7
0x9fb6f: shl ax, 1
0x9fb71: rcl dx, 1
0x9fb73: mov bl, al
0x9fb75: xor bl, dh
0x9fb77: jns 0x9fb7b
0x9fb79: inc al
0x9fb7b: loop 0x9fb6f
0x9fb7d: pop bx
2018-12-17T22:54:41.687936486Z 53 PC: 9f4d9 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:54:41.689466586Z 37 PC: 9f4e8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:54:41.690903284Z 9 PC: 12ad3 | Display string (String= ' Mabuhay! This program came from Bahay Kawayan at http://come.to/hexfiles Putoksa Kawayan [email protected] ')
2018-12-17T22:54:41.707017556Z 76 PC: 12ad7 | Terminate with return code (Return code = '36')