Sample viewer

vx.netlux.org/Virus.DOS.Foma.1200

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:09.964081724Z 48 PC: 12f3d | Get DOS version
2018-12-17T22:56:09.966185406Z 42 PC: 12f45 | Get date 0x12f45: mov byte ptr cs:[si + 0x80], al
0x12f4a: mov ax, 0xff54
0x12f4d: int 0x21
0x12f4f: cmp ax, 0x4d5a
0x12f52: je 0x12f98
0x12f54: mov ah, 0x49
0x12f56: int 0x21
0x12f58: jb 0x12f98
0x12f5a: mov ah, 0x48
0x12f5c: mov bx, 0xffff
0x12f5f: int 0x21
0x12f61: sub bx, 0x4c
0x12f64: nop
0x12f65: jb 0x12f98
0x12f67: mov cx, es
0x12f69: add cx, bx
0x12f6b: mov ah, 0x4a
0x12f6d: int 0x21
0x12f6f: mov bx, 0x4c
0x12f72: sub word ptr es:[2], bx
2018-12-17T22:56:09.969607329Z 255 PC: 12f4f | UNKNOWN!
2018-12-17T22:56:09.970814582Z 73 PC: 12f58 | Release memory
2018-12-17T22:56:09.972424137Z 72 PC: 12f61 | Allocate memory
2018-12-17T22:56:09.977497501Z 74 PC: 12f6f | Reallocate memory
2018-12-17T22:56:09.979068821Z 74 PC: 12f7d | Reallocate memory
2018-12-17T22:56:09.981213997Z 9 PC: 12a4e | Display string (String= 'Test New Shtamm Program ')
2018-12-17T22:56:09.986423903Z 76 PC: 12a53 | Terminate with return code (Return code = '0')