Sample viewer

vx.netlux.org/Virus.DOS.Foma.1733

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:58:14.058472351Z 48 PC: 13178 | Get DOS version
2018-12-17T22:58:14.060113107Z 42 PC: 13180 | Get date 0x13180: mov byte ptr cs:[si + 0x2f2], al
0x13185: mov ax, 0xfe54
0x13188: int 0x21
0x1318a: cmp ax, 0x4d5a
0x1318d: je 0x131d3
0x1318f: mov ah, 0x49
0x13191: int 0x21
0x13193: jb 0x131d3
0x13195: mov ah, 0x48
0x13197: mov bx, 0xffff
0x1319a: int 0x21
0x1319c: sub bx, 0x6d
0x1319f: nop
0x131a0: jb 0x131d3
0x131a2: mov cx, es
0x131a4: add cx, bx
0x131a6: mov ah, 0x4a
0x131a8: int 0x21
0x131aa: mov bx, 0x6d
0x131ad: sub word ptr es:[2], bx
2018-12-17T22:58:14.06234502Z 254 PC: 1318a | UNKNOWN!
2018-12-17T22:58:14.063103866Z 73 PC: 13193 | Release memory
2018-12-17T22:58:14.064777609Z 72 PC: 1319c | Allocate memory
2018-12-17T22:58:14.066434347Z 74 PC: 131aa | Reallocate memory
2018-12-17T22:58:14.067641439Z 74 PC: 131b8 | Reallocate memory
2018-12-17T22:58:14.069688034Z 9 PC: 12a4e | Display string (String= 'Test New Shtamm Program ')
2018-12-17T22:58:14.074139291Z 76 PC: 12a53 | Terminate with return code (Return code = '0')