Sample viewer

vx.netlux.org/Virus.DOS.Anger.395

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:52.784697807Z 44 PC: 12a7a | Get time 0x12a7a: cmp dl, 6
0x12a7d: jg 0x12a82
0x12a7f: call 0x12b3c
0x12a82: ret
0x12a83: mov ah, 0x2f
0x12a85: int 0x6d
0x12a87: mov word ptr [0x132], bx
0x12a8b: mov word ptr [0x134], es
0x12a8f: mov ah, 0x1a
0x12a91: mov dx, 0x1cf
0x12a94: int 0x6d
0x12a96: mov ah, 0x4e
0x12a98: mov cx, 0
0x12a9b: mov dx, 0x1c9
0x12a9e: int 0x6d
0x12aa0: jae 0x12aa5
0x12aa2: jmp 0x12af3
0x12aa4: nop
0x12aa5: mov di, 0x1ed
0x12aa8: mov si, 0x1c2
2018-12-17T22:57:52.78740715Z 48 PC: 12b7d | Get DOS version
2018-12-17T22:57:52.789112255Z 53 PC: 12b88 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:52.791876341Z 37 PC: 12b99 | Set interrupt vector (Interrupt = '109' AKA 'UNKNOWN!')
2018-12-17T22:57:52.793834101Z 37 PC: 12ba3 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:52.795406527Z 49 PC: 12bad | Terminate and stay resident (Return code = '0' | Memory size = '128')