Sample viewer

vx.netlux.org/Virus.DOS.V.2653

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:00.215627573Z 42 PC: 13d51 | Get date 0x13d51: sub cx, 0x7bc
0x13d55: mov ax, cx
0x13d57: mov cx, dx
0x13d59: xor dx, dx
0x13d5b: mov bx, 0xc
0x13d5e: mul bx
0x13d60: xchg cl, ch
0x13d62: xor ch, ch
0x13d64: dec cx
0x13d65: add ax, cx
0x13d67: mov word ptr cs:[0x277], ax
0x13d6b: ret
0x13d6c: call 0x23d4d
0x13d6f: mov ax, word ptr cs:[0x277]
0x13d73: cmp ax, word ptr cs:[0x27b]
0x13d78: jb 0x13d85
0x13d7a: mov ah, 0xdd
0x13d7c: int 0x21
0x13d7e: cmp ah, 0x33
0x13d81: je 0x13d85
2018-12-17T22:55:00.21761989Z 221 PC: 13d7e | UNKNOWN!
2018-12-17T22:55:00.218925894Z 74 PC: 12b53 | Reallocate memory
2018-12-17T22:55:00.219930973Z 53 PC: 12b5a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:00.220930732Z 37 PC: 12b6c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:00.222556412Z 75 PC: 12ba2 | Execute program
2018-12-17T22:55:00.240756217Z 42 PC: 14911 | Get date 0x14911: sub cx, 0x7bc
0x14915: mov ax, cx
0x14917: mov cx, dx
0x14919: xor dx, dx
0x1491b: mov bx, 0xc
0x1491e: mul bx
0x14920: xchg cl, ch
0x14922: xor ch, ch
0x14924: dec cx
0x14925: add ax, cx
0x14927: mov word ptr cs:[0x277], ax
0x1492b: ret
0x1492c: call 0x2490d
0x1492f: mov ax, word ptr cs:[0x277]
0x14933: cmp ax, word ptr cs:[0x27b]
0x14938: jb 0x14945
0x1493a: mov ah, 0xdd
0x1493c: int 0x21
0x1493e: cmp ah, 0x33
0x14941: je 0x14945
2018-12-17T22:55:00.445095088Z 76 PC: 1482f | Terminate with return code (Return code = '0')
2018-12-17T22:55:00.447579938Z 73 PC: 12ba8 | Release memory
2018-12-17T22:55:00.448634053Z 77 PC: 12bac | Get program return code
2018-12-17T22:55:00.449643611Z 49 PC: 12bb5 | Terminate and stay resident (Return code = '0' | Memory size = '182')