Sample viewer

vx.netlux.org/Virus.DOS.Camel.514

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:58:06.027739495Z 44 PC: 12a51 | Get time 0x12a51: mov bl, dl
0x12a53: mov ah, 0xb
0x12a55: int 0x21
0x12a57: cmp ah, 0
0x12a5a: jne 0x12a63
0x12a5c: add bx, bp
0x12a5e: cmp al, byte ptr cs:[bx]
0x12a61: je 0x12ac2
0x12a63: push ds
0x12a64: push es
0x12a65: mov ah, 0x2c
0x12a67: xor ah, 0x66
0x12a6a: mov bx, 0xffff
0x12a6d: int 0x21
0x12a6f: sub bx, 0x22
0x12a73: mov ax, 0x2c00
0x12a76: xor ax, 0x6600
0x12a79: int 0x21
0x12a7b: mov ax, 0x2c00
0x12a7e: xor ax, 0x6400
2018-12-17T22:58:06.03076199Z 11 PC: 12a57 | Get input status
2018-12-17T22:58:06.033429705Z 74 PC: 12a6f | Reallocate memory
2018-12-17T22:58:06.035072338Z 74 PC: 12a7b | Reallocate memory
2018-12-17T22:58:06.036570225Z 72 PC: 12a86 | Allocate memory
2018-12-17T22:58:06.038920276Z 37 PC: 12ac0 | Set interrupt vector (Interrupt = '33' AKA 'Random read')