Sample viewer

vx.netlux.org/Virus.DOS.Ricketty.440

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:15.61231344Z 42 PC: 135fc | Get date 0x135fc: mov ax, word ptr cs:[0x104]
0x13600: add ax, 0x147
0x13603: nop
0x13604: push ax
0x13605: mov bx, 0x10c
0x13608: cmp dh, 6
0x1360b: call bx
0x1360d: mov byte ptr cs:[0x10d], 0x74
0x13613: mov ah, 0x1a
0x13615: mov dx, sp
0x13617: sub dx, 0x100
0x1361b: int 0x21
0x1361d: mov ah, 0x4e
0x1361f: mov dx, 0x106
0x13622: mov cx, 0x20
0x13625: int 0x21
0x13627: mov bx, sp
0x13629: sub bx, 0xe6
0x1362d: mov ax, word ptr [bx]
0x1362f: mov word ptr cs:[0xfa], ax
2018-12-17T22:56:15.950530518Z 26 PC: 1373a | Set disk transfer address
2018-12-17T22:56:15.951682345Z 9 PC: 12b36 | Display string (String= ' YOU HAVE JUST RELEASED A VIRUS! Entry=3h, Size=3000, Stack=0, Overlay(0)=0 not loaded, Fill=FFFF* COM file, code at start, JMP at start, SS:SP != CS:IP ')
2018-12-17T22:56:15.958604157Z 76 PC: 12b3a | Terminate with return code (Return code = '36')