Sample viewer

vx.netlux.org/Virus.DOS.KbrBug.1568

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:02:41.445814747Z 48 PC: 13fbf | Get DOS version
2018-12-17T22:02:41.448160872Z 42 PC: 13ec6 | Get date 0x13ec6: mov bx, word ptr cs:[di + 0x700]
0x13ecb: mov al, byte ptr cs:[di + 0x702]
0x13ed0: cmp dh, bh
0x13ed2: jne 0x13edf
0x13ed4: add bl, 4
0x13ed7: add bl, al
0x13ed9: cmp bl, dl
0x13edb: jb 0x13edf
0x13edd: xor dh, dh
0x13edf: ret
0x13ee0: nop
0x13ee1: xor ax, ax
0x13ee3: mov es, ax
0x13ee5: int 0x1a
0x13ee7: mov word ptr cs:[di + 0x5ef], cx
0x13eec: mov ax, word ptr es:[0x70]
0x13ef0: mov bx, word ptr es:[0x72]
0x13ef5: mov word ptr cs:[di + 0x6f2], ax
0x13efa: mov word ptr cs:[di + 0x6f4], bx
0x13eff: mov ds, word ptr es:[0x2b2]
2018-12-17T22:02:41.450924359Z 48 PC: 139ec | Get DOS version
2018-12-17T22:02:41.452488854Z 9 PC: 139fe | Display string (String= ' Incorrect DOS version ')