Sample viewer

vx.netlux.org/Virus.DOS.Australian.Middle.1169

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:21.073302729Z 48 PC: 1323e | Get DOS version
2018-12-17T22:55:21.076826964Z 53 PC: 13270 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:21.078603596Z 37 PC: 13280 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:21.081166809Z 9 PC: 12a8b | Display string (Could not find end pointer)
2018-12-17T22:55:21.085651603Z 42 PC: 12ad0 | Get date 0x12ad0: push cx
0x12ad1: push dx
0x12ad2: mov ah, al
0x12ad4: mov si, 0x511
0x12ad7: mov dx, 0xba
0x12ada: call 0x12bdf
0x12add: pop ax
0x12ade: push ax
0x12adf: cwde
0x12ae0: push ax
0x12ae1: mov dx, 0xde
0x12ae4: call 0x12c0b
0x12ae7: pop ax
0x12ae8: aam
0x12aea: mov bx, 0x5448
0x12aed: cmp ah, 1
0x12af0: je 0x12b08
0x12af2: cmp al, 3
0x12af4: ja 0x12b08
0x12af6: or al, al
2018-12-17T22:55:21.089241015Z 25 PC: 12b83 | Get default drive
2018-12-17T22:55:21.090446413Z 54 PC: 12b90 | Get free disk space
2018-12-17T22:55:21.1009577Z 76 PC: 12bdf | Terminate with return code (Return code = '0')