Sample viewer

vx.netlux.org/Virus.DOS.Rat.664

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:59:50.830513255Z 42 PC: 12c37 | Get date 0x12c37: cwde
0x12c38: ret
0x12c39: mov ah, 0x2a
0x12c3b: int 0x21
0x12c3d: xchg ax, cx
0x12c3e: ret
0x12c3f: pop bx
0x12c40: push si
0x12c41: inc bx
0x12c42: dec sp
0x12c43: pop bp
0x12c44: add byte ptr [si + 0x68], dl
0x12c47: imul si, word ptr [bp + di + 0x20], 0x7369
0x12c4c: and byte ptr [si + 0x65], ah
0x12c4f: imul sp, word ptr fs:[bp + di + 0x61], 0x6574
0x12c55: and byte ptr fs:[si + 0x6f], dh
0x12c59: and byte ptr [si + 0x68], dh
0x12c5c: and byte ptr gs:[bx + si], ah
0x12c5f: and byte ptr [bx + si], ah
0x12c61: add byte ptr [bp + si + 0x49], al
2018-12-17T22:59:50.832877839Z 42 PC: 12c3d | Get date 0x12c3d: xchg ax, cx
0x12c3e: ret
0x12c3f: pop bx
0x12c40: push si
0x12c41: inc bx
0x12c42: dec sp
0x12c43: pop bp
0x12c44: add byte ptr [si + 0x68], dl
0x12c47: imul si, word ptr [bp + di + 0x20], 0x7369
0x12c4c: and byte ptr [si + 0x65], ah
0x12c4f: imul sp, word ptr fs:[bp + di + 0x61], 0x6574
0x12c55: and byte ptr fs:[si + 0x6f], dh
0x12c59: and byte ptr [si + 0x68], dh
0x12c5c: and byte ptr gs:[bx + si], ah
0x12c5f: and byte ptr [bx + si], ah
0x12c61: add byte ptr [bp + si + 0x49], al
0x12c64: inc di
0x12c65: inc di
0x12c66: inc bp
0x12c67: push bx
2018-12-17T22:59:50.835870773Z 74 PC: 12a84 | Reallocate memory
2018-12-17T22:59:50.837485107Z 81 PC: 12145 | Get current PSP