Sample viewer

vx.netlux.org/Virus.DOS.Kaabum.1100

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:01:24.230825069Z 42 PC: 13dd4 | Get date 0x13dd4: mov word ptr [si + 0x53a], 0x44c
0x13dda: mov cx, ax
0x13ddc: xor ch, ch
0x13dde: add word ptr [si + 0x53a], 0x64
0x13de3: loop 0x13dde
0x13de5: cmp dh, 6
0x13de8: jb 0x13e37
0x13dea: or al, al
0x13dec: je 0x13e52
0x13dee: mov ah, 0x96
0x13df0: int 0x21
0x13df2: cmp ah, 0x69
0x13df5: je 0x13e37
0x13df7: mov ah, 9
0x13df9: lea dx, word ptr [si + 0x33d]
0x13dfd: int 0x21
0x13dff: mov ax, 0x3509
0x13e02: int 0x21
0x13e04: mov word ptr [si + 0x2e4], bx
0x13e08: mov ax, es
2018-12-17T22:01:24.232803029Z 150 PC: 13df2 | UNKNOWN!
2018-12-17T22:01:24.233511945Z 9 PC: 13dff | Display string (String= 'Bad command or file name')
2018-12-17T22:01:24.235072871Z 53 PC: 13e04 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:01:24.23639202Z 37 PC: 13e17 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:01:24.237380095Z 53 PC: 13e1c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:01:24.238292707Z 37 PC: 13e2f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:01:24.241224784Z 49 PC: 13e37 | Terminate and stay resident (Return code = '0' | Memory size = '398')