Sample viewer

vx.netlux.org/Virus.DOS.Chaos.1241

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:41.962194317Z 74 PC: 12ae8 | Reallocate memory
2018-12-17T22:56:41.96812584Z 42 PC: 12aec | Get date 0x12aec: cli
0x12aed: push es
0x12aee: mov word ptr [0x17b], es
0x12af2: mov word ptr [0x17f], es
0x12af6: mov word ptr [0x183], es
0x12afa: xor ax, ax
0x12afc: mov es, ax
0x12afe: mov byte ptr [0x4f6], al
0x12b01: cmp dh, 9
0x12b04: jne 0x12b0d
0x12b06: inc byte ptr [0x4f6]
0x12b0a: mov cx, 0x7cf
0x12b0d: add cl, dh
0x12b0f: and cl, 0xf
0x12b12: add cl, 5
0x12b15: cmp cl, dl
0x12b17: jne 0x12b40
0x12b19: mov byte ptr [0x4f8], 0x27
0x12b1e: nop
0x12b1f: mov byte ptr [0x4f7], 0
2018-12-17T22:56:41.972065958Z 75 PC: 12b8c | Execute program
2018-12-17T22:56:41.999618733Z 9 PC: 131c7 | Display string (String= 'This is 1241/1256 virus ..! Caught By Peter Ferng ..!')
2018-12-17T22:56:42.004570824Z 49 PC: 1fde5 | Terminate and stay resident (Return code = '1' | Memory size = '114')