Sample viewer

vx.netlux.org/Virus.DOS.PeaceKeeper.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:59:16.446808587Z 48 PC: 12be4 | Get DOS version
2018-12-17T22:59:16.449380431Z 222 PC: 12bf7 | UNKNOWN!
2018-12-17T22:59:16.450514982Z 53 PC: 12c24 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:59:16.451712532Z 53 PC: 12c31 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:59:16.453445894Z 52 PC: 12b79 | Get InDOS flag pointer
2018-12-17T22:59:16.455277117Z 42 PC: 12c65 | Get date 0x12c65: mov byte ptr [si + 0xa71], dh
0x12c69: mov bx, word ptr [si + 0xa21]
0x12c6d: dec bx
0x12c6e: mov es, bx
0x12c70: sub bx, bx
0x12c72: cmp byte ptr es:[bx], 0x5a
0x12c76: je 0x12c7b
0x12c78: jmp 0x12b17
0x12c7b: mov ax, 0x183
0x12c7e: sub word ptr es:[bx + 3], ax
0x12c82: sub word ptr es:[bx + 0x12], ax
0x12c86: mov es, word ptr es:[bx + 0x12]
0x12c8a: push si
0x12c8b: sub cx, cx
0x12c8d: sub di, di
0x12c8f: or di, 0x100
0x12c93: or cx, 0xed8
0x12c97: rep movsb byte ptr es:[di], byte ptr [si]
0x12c99: pop si
0x12c9a: mov ax, 0x2521