Sample viewer

vx.netlux.org/Virus.DOS.PS-MPC.Bamestra.531

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:08.95402008Z 26 PC: 12a78 | Set disk transfer address
2018-12-17T22:55:08.955650904Z 53 PC: 12a7d | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:08.956822153Z 37 PC: 12a8d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:08.957862127Z 78 PC: 12a9a | Find first file
2018-12-17T22:55:08.96457227Z 42 PC: 12ac0 | Get date 0x12ac0: cmp al, 0xff
0x12ac2: jne 0x12ad7
0x12ac4: mov ah, 0x2c
0x12ac6: int 0x21
0x12ac8: cmp ch, 0xff
0x12acb: jne 0x12ad7
0x12acd: cmp cl, 0xff
0x12ad0: jne 0x12ad7
0x12ad2: cmp dh, 0xff
0x12ad5: jne 0x12ad7
0x12ad7: mov ax, 0x2524
0x12ada: lds dx, ptr [bp + 0x345]
0x12ade: int 0x21
0x12ae0: push cs
0x12ae1: pop ds
0x12ae2: mov ah, 0x1a
0x12ae4: mov dx, 0x80
0x12ae7: pop es
0x12ae8: pop ds
0x12ae9: int 0x21
2018-12-17T22:55:08.966137095Z 37 PC: 12ae0 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:08.967089686Z 26 PC: 12aeb | Set disk transfer address