Sample viewer

vx.netlux.org/Virus.DOS.Gle.848

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:58:06.769060277Z 82 PC: 12aae | Get DOS internal pointers (SYSVARS)
2018-12-17T22:58:06.772165493Z 42 PC: 9f50b | Get date 0x9f50b: mov byte ptr cs:[0x120], 0
0x9f511: cmp dx, 0xc18
0x9f515: jne 0x9f51d
0x9f517: mov byte ptr cs:[0x120], 1
0x9f51d: jmp 0x9f439
0x9f520: add byte ptr [bx + 0x6c], al
0x9f523: mov word ptr gs:[bx + di + 0x6c], gs
0x9f527: and byte ptr gs:[edx - 0x5e], ch
0x9f52c: insb byte ptr es:[di], dx
0x9f52d: pop es
0x9f52e: or cl, byte ptr [di]
0x9f530: and al, 0x2e
0x9f532: pop word ptr [0x33b]
0x9f536: nop
0x9f537: pop word ptr cs:[0x33d]
0x9f53c: mov byte ptr cs:[0x33a], 1
0x9f542: pushf
0x9f543: lcall ptr cs:[0x343]
0x9f548: mov byte ptr cs:[0x33a], 0
0x9f54e: push word ptr cs:[0x33d]
2018-12-17T22:58:06.775306307Z 9 PC: 12a49 | Display string (Could not find end pointer)
2018-12-17T22:58:06.779681881Z 76 PC: 12a4e | Terminate with return code (Return code = '0')