Sample viewer

vx.netlux.org/Virus.DOS.Lokjaw.1046

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:58:41.443104212Z 44 PC: 12aa2 | Get time 0x12aa2: cmp ax, 0xdcd
0x12aa5: je 0x12b02
0x12aa7: mov ax, cs
0x12aa9: dec ax
0x12aaa: mov ds, ax
0x12aac: cmp byte ptr [0], 0x5a
0x12ab1: jne 0x12afa
0x12ab3: mov ax, word ptr [3]
0x12ab6: sub ax, 0x100
0x12ab9: mov word ptr [3], ax
0x12abc: mov bx, ax
0x12abe: mov ax, es
0x12ac0: add ax, bx
0x12ac2: mov es, ax
0x12ac4: mov cx, 0x416
0x12ac7: mov ax, ds
0x12ac9: inc ax
0x12aca: mov ds, ax
0x12acc: lea si, word ptr [bp + 0x106]
0x12ad0: mov di, 0x100
2018-12-17T22:58:41.445753539Z 53 PC: 12ae4 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:58:41.446913484Z 37 PC: 12af9 | Set interrupt vector (Interrupt = '33' AKA 'Random read')