Sample viewer

vx.netlux.org/Virus.DOS.PS-MPC.Bamestra.535

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:03:51.929756139Z 26 PC: 12a77 | Set disk transfer address
2018-12-17T23:03:51.932044368Z 53 PC: 12a7c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:51.933598687Z 37 PC: 12a8c | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:51.934997087Z 78 PC: 12a99 | Find first file
2018-12-17T23:03:51.94107232Z 42 PC: 12abf | Get date 0x12abf: cmp al, 0xff
0x12ac1: jne 0x12ad6
0x12ac3: mov ah, 0x2c
0x12ac5: int 0x21
0x12ac7: cmp ch, 0xff
0x12aca: jne 0x12ad6
0x12acc: cmp cl, 0xff
0x12acf: jne 0x12ad6
0x12ad1: cmp dh, 0xff
0x12ad4: jne 0x12ad6
0x12ad6: mov ax, 0x2524
0x12ad9: lds dx, ptr [bp + 0x347]
0x12add: int 0x21
0x12adf: push cs
0x12ae0: pop ds
0x12ae1: mov ah, 0x1a
0x12ae3: mov dx, 0x80
0x12ae6: pop es
0x12ae7: pop ds
0x12ae8: int 0x21
2018-12-17T23:03:51.944301111Z 37 PC: 12adf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:51.945687795Z 26 PC: 12aea | Set disk transfer address