Sample viewer

vx.netlux.org/Virus.DOS.FaxFree.Topo

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:03:05.218376559Z 74 PC: 16fd0 | Reallocate memory
2018-12-17T23:03:05.225426054Z 72 PC: 16fd7 | Allocate memory
2018-12-17T23:03:05.229627247Z 42 PC: 13498 | Get date 0x13498: ret
0x13499: pop es
0x1349a: add word ptr cs:[0x40], 1
0x134a0: cli
0x134a1: push ax
0x134a2: xor ax, ax
0x134a4: mov es, ax
0x134a6: mov ax, word ptr cs:[0x37]
0x134aa: mov word ptr es:[0x84], ax
0x134ae: mov ax, word ptr cs:[0x39]
0x134b2: mov word ptr es:[0x86], ax
0x134b6: pop ax
0x134b7: call 0x2319e
0x134ba: cmp byte ptr cs:[0x335], 7
0x134c0: je 0x134b7
0x134c2: int 0x21
0x134c4: call 0x2317b
0x134c7: cli
0x134c8: xor ax, ax
0x134ca: mov es, ax
2018-12-17T23:03:05.23297676Z 72 PC: 13247 | Allocate memory
2018-12-17T23:03:05.239937338Z 75 PC: 13281 | Execute program
2018-12-17T23:03:05.257215681Z 9 PC: 17d81 | Display string (Could not find end pointer)
2018-12-17T23:03:05.268178289Z 76 PC: 17d86 | Terminate with return code (Return code = '0')
2018-12-17T23:03:05.275529952Z 53 PC: 13295 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:05.277384997Z 37 PC: 132ac | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:05.278957341Z 77 PC: 132b0 | Get program return code
2018-12-17T23:03:05.281179326Z 49 PC: 132b7 | Terminate and stay resident (Return code = '0' | Memory size = '96')