Sample viewer

vx.netlux.org/Virus.DOS.XPEH.5792

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:00:11.194324179Z 48 PC: 13907 | Get DOS version
2018-12-17T23:00:11.196415383Z 42 PC: 13559 | Get date 0x13559: cmp cx, word ptr [bp + 4]
0x1355c: jb 0x13566
0x1355e: cmp dh, byte ptr [bp + 6]
0x13561: jb 0x13566
0x13563: clc
0x13564: jmp 0x13567
0x13566: stc
0x13567: pop dx
0x13568: pop cx
0x13569: pop ax
0x1356a: pop bp
0x1356b: ret 4
0x1356e: push ax
0x1356f: push cx
0x13570: push di
0x13571: push es
0x13572: cld
0x13573: mov di, word ptr cs:[0x86]
0x13578: add di, 0x1f
0x1357b: mov ax, word ptr cs:[0x84]
2018-12-17T23:00:11.198538995Z 193 PC: 13937 | UNKNOWN!
2018-12-17T23:00:11.202593152Z 37 PC: 13ae7 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:00:11.217351952Z 9 PC: 12e26 | Display string (String= 'Hello - Copyright S & S International, 1990 ')