Sample viewer

vx.netlux.org/Virus.DOS.Itavir.3187

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:01:37.521012218Z 53 PC: 12f70 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:01:37.522425707Z 37 PC: 12f82 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:01:37.524106987Z 25 PC: 12fc7 | Get default drive
2018-12-17T23:01:37.525271085Z 14 PC: 12fd0 | Set default drive (Drive = 'A')
2018-12-17T23:01:37.526524101Z 28 PC: 12fde | Get allocation info for specified drive
2018-12-17T23:01:37.544674256Z 28 PC: 1305d | Get allocation info for specified drive
2018-12-17T23:01:37.546327068Z 28 PC: 1305d | Get allocation info for specified drive
2018-12-17T23:01:37.548082828Z 28 PC: 1305d | Get allocation info for specified drive
2018-12-17T23:01:37.598830543Z 50 PC: 130fe | Get disk parameter block for specified drive
2018-12-17T23:01:37.601787558Z 13 PC: 1316f | Disk reset
2018-12-17T23:01:37.603776786Z 13 PC: 134fb | Disk reset
2018-12-17T23:01:37.606480648Z 42 PC: 134ff | Get date 0x134ff: and dh, byte ptr [0xd64]
0x13503: cmp dh, 0
0x13506: je 0x1350b
0x13508: jmp 0x13618
0x1350b: cmp dl, byte ptr [0xd63]
0x1350f: je 0x13514
0x13511: jmp 0x13618
0x13514: mov ah, 0x2c
0x13516: int 0x21
0x13518: cmp ch, byte ptr [0xd62]
0x1351c: jae 0x13521
0x1351e: jmp 0x13618
0x13521: nop
0x13522: mov al, 0x28
0x13524: mov dx, 0xbd1
0x13527: mov ah, 0x25
0x13529: int 0x21
0x1352b: mov al, 0x16
0x1352d: mov dx, 0xbd1
0x13530: mov ah, 0x25
2018-12-17T23:01:37.60919212Z 37 PC: 13638 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')