Sample viewer

vx.netlux.org/Virus.DOS.LAVI.838

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:28.93925652Z 42 PC: 12abe | Get date 0x12abe: cmp dh, 0xb
0x12ac1: jne 0x12acb
0x12ac3: cmp dl, 0x18
0x12ac6: jne 0x12acb
0x12ac8: call 0x12b8d
0x12acb: push cs
0x12acc: pop es
0x12acd: mov si, 0x138
0x12ad0: cmp word ptr [bp + si + 1], 0x414c
0x12ad5: jne 0x12ae0
0x12ad7: mov ah, 0xb9
0x12ad9: int 0x21
0x12adb: cmp ah, 0xb9
0x12ade: je 0x12ae4
0x12ae0: push 0x100
0x12ae3: ret
0x12ae4: push cs
0x12ae5: pop es
0x12ae6: mov di, 0x104
0x12ae9: mov si, 0x104
2018-12-17T23:04:28.942566236Z 185 PC: 12adb | UNKNOWN!
2018-12-17T23:04:28.944305563Z 74 PC: 12b05 | Reallocate memory
2018-12-17T23:04:28.946265736Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:28.948007005Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:28.949840673Z 75 PC: 12b6b | Execute program
2018-12-17T23:04:28.967815297Z 42 PC: 1331e | Get date 0x1331e: cmp dh, 0xb
0x13321: jne 0x1332b
0x13323: cmp dl, 0x18
0x13326: jne 0x1332b
0x13328: call 0x133ed
0x1332b: push cs
0x1332c: pop es
0x1332d: mov si, 0x138
0x13330: cmp word ptr [bp + si + 1], 0x414c
0x13335: jne 0x13340
0x13337: mov ah, 0xb9
0x13339: int 0x21
0x1333b: cmp ah, 0xb9
0x1333e: je 0x13344
0x13340: push 0x100
0x13343: ret
0x13344: push cs
0x13345: pop es
0x13346: mov di, 0x104
0x13349: mov si, 0x104
2018-12-17T23:04:28.970635811Z 76 PC: 132a4 | Terminate with return code (Return code = '1')
2018-12-17T23:04:28.974316618Z 73 PC: 12b77 | Release memory
2018-12-17T23:04:28.976612623Z 49 PC: 12b81 | Terminate and stay resident (Return code = '1' | Memory size = '128')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14891,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:59.0208077Z 42 PC: 12abe | Get date 0x12abe: cmp dh, 0xb
0x12ac1: jne 0x12acb
0x12ac3: cmp dl, 0x18
0x12ac6: jne 0x12acb
0x12ac8: call 0x12b8d
0x12acb: push cs
0x12acc: pop es
0x12acd: mov si, 0x138
0x12ad0: cmp word ptr [bp + si + 1], 0x414c
0x12ad5: jne 0x12ae0
0x12ad7: mov ah, 0xb9
0x12ad9: int 0x21
0x12adb: cmp ah, 0xb9
0x12ade: je 0x12ae4
0x12ae0: push 0x100
0x12ae3: ret
0x12ae4: push cs
0x12ae5: pop es
0x12ae6: mov di, 0x104
0x12ae9: mov si, 0x104
2018-12-25T12:41:59.023386064Z 185 PC: 12adb | UNKNOWN!
2018-12-25T12:41:59.025832376Z 74 PC: 12b05 | Reallocate memory
2018-12-25T12:41:59.027842461Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:59.029601275Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:59.032135965Z 75 PC: 12b6b | Execute program
2018-12-25T12:41:59.048644359Z 42 PC: 1331e | Get date 0x1331e: cmp dh, 0xb
0x13321: jne 0x1332b
0x13323: cmp dl, 0x18
0x13326: jne 0x1332b
0x13328: call 0x133ed
0x1332b: push cs
0x1332c: pop es
0x1332d: mov si, 0x138
0x13330: cmp word ptr [bp + si + 1], 0x414c
0x13335: jne 0x13340
0x13337: mov ah, 0xb9
0x13339: int 0x21
0x1333b: cmp ah, 0xb9
0x1333e: je 0x13344
0x13340: push 0x100
0x13343: ret
0x13344: push cs
0x13345: pop es
0x13346: mov di, 0x104
0x13349: mov si, 0x104
2018-12-25T12:41:59.052842968Z 76 PC: 132a4 | Terminate with return code (Return code = '2')
2018-12-25T12:41:59.05775626Z 73 PC: 12b77 | Release memory
2018-12-25T12:41:59.0597662Z 49 PC: 12b81 | Terminate and stay resident (Return code = '1' | Memory size = '128')

{"DateBased":true,"Day":1,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14891,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:59.600383061Z 42 PC: 12abe | Get date 0x12abe: cmp dh, 0xb
0x12ac1: jne 0x12acb
0x12ac3: cmp dl, 0x18
0x12ac6: jne 0x12acb
0x12ac8: call 0x12b8d
0x12acb: push cs
0x12acc: pop es
0x12acd: mov si, 0x138
0x12ad0: cmp word ptr [bp + si + 1], 0x414c
0x12ad5: jne 0x12ae0
0x12ad7: mov ah, 0xb9
0x12ad9: int 0x21
0x12adb: cmp ah, 0xb9
0x12ade: je 0x12ae4
0x12ae0: push 0x100
0x12ae3: ret
0x12ae4: push cs
0x12ae5: pop es
0x12ae6: mov di, 0x104
0x12ae9: mov si, 0x104
2018-12-25T12:41:59.60324255Z 185 PC: 12adb | UNKNOWN!
2018-12-25T12:41:59.604842273Z 74 PC: 12b05 | Reallocate memory
2018-12-25T12:41:59.60635954Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:59.607700702Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:59.610093621Z 75 PC: 12b6b | Execute program
2018-12-25T12:41:59.626294824Z 42 PC: 1331e | Get date 0x1331e: cmp dh, 0xb
0x13321: jne 0x1332b
0x13323: cmp dl, 0x18
0x13326: jne 0x1332b
0x13328: call 0x133ed
0x1332b: push cs
0x1332c: pop es
0x1332d: mov si, 0x138
0x13330: cmp word ptr [bp + si + 1], 0x414c
0x13335: jne 0x13340
0x13337: mov ah, 0xb9
0x13339: int 0x21
0x1333b: cmp ah, 0xb9
0x1333e: je 0x13344
0x13340: push 0x100
0x13343: ret
0x13344: push cs
0x13345: pop es
0x13346: mov di, 0x104
0x13349: mov si, 0x104
2018-12-25T12:41:59.628803598Z 76 PC: 132a4 | Terminate with return code (Return code = '6')
2018-12-25T12:41:59.633009451Z 73 PC: 12b77 | Release memory
2018-12-25T12:41:59.634528947Z 49 PC: 12b81 | Terminate and stay resident (Return code = '1' | Memory size = '128')

{"DateBased":true,"Day":24,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14891,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:59.813293941Z 42 PC: 12abe | Get date 0x12abe: cmp dh, 0xb
0x12ac1: jne 0x12acb
0x12ac3: cmp dl, 0x18
0x12ac6: jne 0x12acb
0x12ac8: call 0x12b8d
0x12acb: push cs
0x12acc: pop es
0x12acd: mov si, 0x138
0x12ad0: cmp word ptr [bp + si + 1], 0x414c
0x12ad5: jne 0x12ae0
0x12ad7: mov ah, 0xb9
0x12ad9: int 0x21
0x12adb: cmp ah, 0xb9
0x12ade: je 0x12ae4
0x12ae0: push 0x100
0x12ae3: ret
0x12ae4: push cs
0x12ae5: pop es
0x12ae6: mov di, 0x104
0x12ae9: mov si, 0x104
2018-12-25T12:41:59.815793299Z 9 PC: 12b94 | Display string (String= 'I feel a sickness coming on!')
2018-12-25T12:41:59.820225128Z 185 PC: 12adb | UNKNOWN!
2018-12-25T12:41:59.821883764Z 74 PC: 12b05 | Reallocate memory
2018-12-25T12:41:59.8243898Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:59.826820933Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:59.828364267Z 75 PC: 12b6b | Execute program
2018-12-25T12:41:59.846965985Z 42 PC: 1331e | Get date 0x1331e: cmp dh, 0xb
0x13321: jne 0x1332b
0x13323: cmp dl, 0x18
0x13326: jne 0x1332b
0x13328: call 0x133ed
0x1332b: push cs
0x1332c: pop es
0x1332d: mov si, 0x138
0x13330: cmp word ptr [bp + si + 1], 0x414c
0x13335: jne 0x13340
0x13337: mov ah, 0xb9
0x13339: int 0x21
0x1333b: cmp ah, 0xb9
0x1333e: je 0x13344
0x13340: push 0x100
0x13343: ret
0x13344: push cs
0x13345: pop es
0x13346: mov di, 0x104
0x13349: mov si, 0x104
2018-12-25T12:41:59.85522172Z 9 PC: 133f4 | Display string (String= 'I feel a sickness coming on!')
2018-12-25T12:41:59.858932943Z 76 PC: 132a4 | Terminate with return code (Return code = '36')
2018-12-25T12:41:59.862811717Z 73 PC: 12b77 | Release memory
2018-12-25T12:41:59.865024014Z 49 PC: 12b81 | Terminate and stay resident (Return code = '1' | Memory size = '128')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14891,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:59.870784553Z 42 PC: 12abe | Get date 0x12abe: cmp dh, 0xb
0x12ac1: jne 0x12acb
0x12ac3: cmp dl, 0x18
0x12ac6: jne 0x12acb
0x12ac8: call 0x12b8d
0x12acb: push cs
0x12acc: pop es
0x12acd: mov si, 0x138
0x12ad0: cmp word ptr [bp + si + 1], 0x414c
0x12ad5: jne 0x12ae0
0x12ad7: mov ah, 0xb9
0x12ad9: int 0x21
0x12adb: cmp ah, 0xb9
0x12ade: je 0x12ae4
0x12ae0: push 0x100
0x12ae3: ret
0x12ae4: push cs
0x12ae5: pop es
0x12ae6: mov di, 0x104
0x12ae9: mov si, 0x104
2018-12-25T12:41:59.87335935Z 185 PC: 12adb | UNKNOWN!
2018-12-25T12:41:59.874786462Z 74 PC: 12b05 | Reallocate memory
2018-12-25T12:41:59.876439204Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:59.879662085Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:59.880889804Z 75 PC: 12b6b | Execute program
2018-12-25T12:41:59.89980773Z 42 PC: 1331e | Get date 0x1331e: cmp dh, 0xb
0x13321: jne 0x1332b
0x13323: cmp dl, 0x18
0x13326: jne 0x1332b
0x13328: call 0x133ed
0x1332b: push cs
0x1332c: pop es
0x1332d: mov si, 0x138
0x13330: cmp word ptr [bp + si + 1], 0x414c
0x13335: jne 0x13340
0x13337: mov ah, 0xb9
0x13339: int 0x21
0x1333b: cmp ah, 0xb9
0x1333e: je 0x13344
0x13340: push 0x100
0x13343: ret
0x13344: push cs
0x13345: pop es
0x13346: mov di, 0x104
0x13349: mov si, 0x104
2018-12-25T12:41:59.90246445Z 76 PC: 132a4 | Terminate with return code (Return code = '2')
2018-12-25T12:41:59.909648443Z 73 PC: 12b77 | Release memory
2018-12-25T12:41:59.911067601Z 49 PC: 12b81 | Terminate and stay resident (Return code = '1' | Memory size = '128')

{"DateBased":true,"Day":1,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14891,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:42:00.007806997Z 42 PC: 12abe | Get date 0x12abe: cmp dh, 0xb
0x12ac1: jne 0x12acb
0x12ac3: cmp dl, 0x18
0x12ac6: jne 0x12acb
0x12ac8: call 0x12b8d
0x12acb: push cs
0x12acc: pop es
0x12acd: mov si, 0x138
0x12ad0: cmp word ptr [bp + si + 1], 0x414c
0x12ad5: jne 0x12ae0
0x12ad7: mov ah, 0xb9
0x12ad9: int 0x21
0x12adb: cmp ah, 0xb9
0x12ade: je 0x12ae4
0x12ae0: push 0x100
0x12ae3: ret
0x12ae4: push cs
0x12ae5: pop es
0x12ae6: mov di, 0x104
0x12ae9: mov si, 0x104
2018-12-25T12:42:00.013908805Z 185 PC: 12adb | UNKNOWN!
2018-12-25T12:42:00.014877211Z 74 PC: 12b05 | Reallocate memory
2018-12-25T12:42:00.016040362Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:42:00.017238915Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:42:00.01858028Z 75 PC: 12b6b | Execute program
2018-12-25T12:42:00.030302567Z 42 PC: 1331e | Get date 0x1331e: cmp dh, 0xb
0x13321: jne 0x1332b
0x13323: cmp dl, 0x18
0x13326: jne 0x1332b
0x13328: call 0x133ed
0x1332b: push cs
0x1332c: pop es
0x1332d: mov si, 0x138
0x13330: cmp word ptr [bp + si + 1], 0x414c
0x13335: jne 0x13340
0x13337: mov ah, 0xb9
0x13339: int 0x21
0x1333b: cmp ah, 0xb9
0x1333e: je 0x13344
0x13340: push 0x100
0x13343: ret
0x13344: push cs
0x13345: pop es
0x13346: mov di, 0x104
0x13349: mov si, 0x104
2018-12-25T12:42:00.033015973Z 76 PC: 132a4 | Terminate with return code (Return code = '6')
2018-12-25T12:42:00.036850668Z 73 PC: 12b77 | Release memory
2018-12-25T12:42:00.03852871Z 49 PC: 12b81 | Terminate and stay resident (Return code = '1' | Memory size = '128')

{"DateBased":true,"Day":24,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14891,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:42:00.69021201Z 42 PC: 12abe | Get date 0x12abe: cmp dh, 0xb
0x12ac1: jne 0x12acb
0x12ac3: cmp dl, 0x18
0x12ac6: jne 0x12acb
0x12ac8: call 0x12b8d
0x12acb: push cs
0x12acc: pop es
0x12acd: mov si, 0x138
0x12ad0: cmp word ptr [bp + si + 1], 0x414c
0x12ad5: jne 0x12ae0
0x12ad7: mov ah, 0xb9
0x12ad9: int 0x21
0x12adb: cmp ah, 0xb9
0x12ade: je 0x12ae4
0x12ae0: push 0x100
0x12ae3: ret
0x12ae4: push cs
0x12ae5: pop es
0x12ae6: mov di, 0x104
0x12ae9: mov si, 0x104
2018-12-25T12:42:00.692774584Z 9 PC: 12b94 | Display string (String= 'I feel a sickness coming on!')
2018-12-25T12:42:00.695635229Z 185 PC: 12adb | UNKNOWN!
2018-12-25T12:42:00.697271416Z 74 PC: 12b05 | Reallocate memory
2018-12-25T12:42:00.6991124Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:42:00.700811141Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:42:00.702482396Z 75 PC: 12b6b | Execute program
2018-12-25T12:42:00.719071051Z 42 PC: 1331e | Get date 0x1331e: cmp dh, 0xb
0x13321: jne 0x1332b
0x13323: cmp dl, 0x18
0x13326: jne 0x1332b
0x13328: call 0x133ed
0x1332b: push cs
0x1332c: pop es
0x1332d: mov si, 0x138
0x13330: cmp word ptr [bp + si + 1], 0x414c
0x13335: jne 0x13340
0x13337: mov ah, 0xb9
0x13339: int 0x21
0x1333b: cmp ah, 0xb9
0x1333e: je 0x13344
0x13340: push 0x100
0x13343: ret
0x13344: push cs
0x13345: pop es
0x13346: mov di, 0x104
0x13349: mov si, 0x104
2018-12-25T12:42:00.722182418Z 9 PC: 133f4 | Display string (String= 'I feel a sickness coming on!')
2018-12-25T12:42:00.72639082Z 76 PC: 132a4 | Terminate with return code (Return code = '36')
2018-12-25T12:42:00.729734438Z 73 PC: 12b77 | Release memory
2018-12-25T12:42:00.731709219Z 49 PC: 12b81 | Terminate and stay resident (Return code = '1' | Memory size = '128')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14891,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:42:00.792596185Z 42 PC: 12abe | Get date 0x12abe: cmp dh, 0xb
0x12ac1: jne 0x12acb
0x12ac3: cmp dl, 0x18
0x12ac6: jne 0x12acb
0x12ac8: call 0x12b8d
0x12acb: push cs
0x12acc: pop es
0x12acd: mov si, 0x138
0x12ad0: cmp word ptr [bp + si + 1], 0x414c
0x12ad5: jne 0x12ae0
0x12ad7: mov ah, 0xb9
0x12ad9: int 0x21
0x12adb: cmp ah, 0xb9
0x12ade: je 0x12ae4
0x12ae0: push 0x100
0x12ae3: ret
0x12ae4: push cs
0x12ae5: pop es
0x12ae6: mov di, 0x104
0x12ae9: mov si, 0x104
2018-12-25T12:42:00.799901875Z 185 PC: 12adb | UNKNOWN!
2018-12-25T12:42:00.801021695Z 74 PC: 12b05 | Reallocate memory
2018-12-25T12:42:00.802177445Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:42:00.804028901Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:42:00.805015638Z 75 PC: 12b6b | Execute program
2018-12-25T12:42:00.819062762Z 42 PC: 1331e | Get date 0x1331e: cmp dh, 0xb
0x13321: jne 0x1332b
0x13323: cmp dl, 0x18
0x13326: jne 0x1332b
0x13328: call 0x133ed
0x1332b: push cs
0x1332c: pop es
0x1332d: mov si, 0x138
0x13330: cmp word ptr [bp + si + 1], 0x414c
0x13335: jne 0x13340
0x13337: mov ah, 0xb9
0x13339: int 0x21
0x1333b: cmp ah, 0xb9
0x1333e: je 0x13344
0x13340: push 0x100
0x13343: ret
0x13344: push cs
0x13345: pop es
0x13346: mov di, 0x104
0x13349: mov si, 0x104
2018-12-25T12:42:00.821901311Z 76 PC: 132a4 | Terminate with return code (Return code = '2')
2018-12-25T12:42:00.830526714Z 73 PC: 12b77 | Release memory
2018-12-25T12:42:00.831619664Z 49 PC: 12b81 | Terminate and stay resident (Return code = '1' | Memory size = '128')

{"DateBased":true,"Day":1,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14891,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:42:00.895053994Z 42 PC: 12abe | Get date 0x12abe: cmp dh, 0xb
0x12ac1: jne 0x12acb
0x12ac3: cmp dl, 0x18
0x12ac6: jne 0x12acb
0x12ac8: call 0x12b8d
0x12acb: push cs
0x12acc: pop es
0x12acd: mov si, 0x138
0x12ad0: cmp word ptr [bp + si + 1], 0x414c
0x12ad5: jne 0x12ae0
0x12ad7: mov ah, 0xb9
0x12ad9: int 0x21
0x12adb: cmp ah, 0xb9
0x12ade: je 0x12ae4
0x12ae0: push 0x100
0x12ae3: ret
0x12ae4: push cs
0x12ae5: pop es
0x12ae6: mov di, 0x104
0x12ae9: mov si, 0x104
2018-12-25T12:42:00.898341617Z 185 PC: 12adb | UNKNOWN!
2018-12-25T12:42:00.899897646Z 74 PC: 12b05 | Reallocate memory
2018-12-25T12:42:00.901338089Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:42:00.903029725Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:42:00.9046064Z 75 PC: 12b6b | Execute program
2018-12-25T12:42:00.931924816Z 42 PC: 1331e | Get date 0x1331e: cmp dh, 0xb
0x13321: jne 0x1332b
0x13323: cmp dl, 0x18
0x13326: jne 0x1332b
0x13328: call 0x133ed
0x1332b: push cs
0x1332c: pop es
0x1332d: mov si, 0x138
0x13330: cmp word ptr [bp + si + 1], 0x414c
0x13335: jne 0x13340
0x13337: mov ah, 0xb9
0x13339: int 0x21
0x1333b: cmp ah, 0xb9
0x1333e: je 0x13344
0x13340: push 0x100
0x13343: ret
0x13344: push cs
0x13345: pop es
0x13346: mov di, 0x104
0x13349: mov si, 0x104
2018-12-25T12:42:00.936001382Z 76 PC: 132a4 | Terminate with return code (Return code = '6')
2018-12-25T12:42:00.943647161Z 73 PC: 12b77 | Release memory
2018-12-25T12:42:00.945801259Z 49 PC: 12b81 | Terminate and stay resident (Return code = '1' | Memory size = '128')

{"DateBased":true,"Day":24,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14891,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:42:00.938465556Z 42 PC: 12abe | Get date 0x12abe: cmp dh, 0xb
0x12ac1: jne 0x12acb
0x12ac3: cmp dl, 0x18
0x12ac6: jne 0x12acb
0x12ac8: call 0x12b8d
0x12acb: push cs
0x12acc: pop es
0x12acd: mov si, 0x138
0x12ad0: cmp word ptr [bp + si + 1], 0x414c
0x12ad5: jne 0x12ae0
0x12ad7: mov ah, 0xb9
0x12ad9: int 0x21
0x12adb: cmp ah, 0xb9
0x12ade: je 0x12ae4
0x12ae0: push 0x100
0x12ae3: ret
0x12ae4: push cs
0x12ae5: pop es
0x12ae6: mov di, 0x104
0x12ae9: mov si, 0x104
2018-12-25T12:42:00.948987495Z 9 PC: 12b94 | Display string (String= 'I feel a sickness coming on!')
2018-12-25T12:42:00.951974333Z 185 PC: 12adb | UNKNOWN!
2018-12-25T12:42:00.95358735Z 74 PC: 12b05 | Reallocate memory
2018-12-25T12:42:00.955679551Z 53 PC: 12b0a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:42:00.966291155Z 37 PC: 12b1c | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:42:00.967588149Z 75 PC: 12b6b | Execute program
2018-12-25T12:42:00.983607124Z 42 PC: 1331e | Get date 0x1331e: cmp dh, 0xb
0x13321: jne 0x1332b
0x13323: cmp dl, 0x18
0x13326: jne 0x1332b
0x13328: call 0x133ed
0x1332b: push cs
0x1332c: pop es
0x1332d: mov si, 0x138
0x13330: cmp word ptr [bp + si + 1], 0x414c
0x13335: jne 0x13340
0x13337: mov ah, 0xb9
0x13339: int 0x21
0x1333b: cmp ah, 0xb9
0x1333e: je 0x13344
0x13340: push 0x100
0x13343: ret
0x13344: push cs
0x13345: pop es
0x13346: mov di, 0x104
0x13349: mov si, 0x104
2018-12-25T12:42:00.98654205Z 9 PC: 133f4 | Display string (String= 'I feel a sickness coming on!')
2018-12-25T12:42:00.990987934Z 76 PC: 132a4 | Terminate with return code (Return code = '36')
2018-12-25T12:42:00.994677814Z 73 PC: 12b77 | Release memory
2018-12-25T12:42:01.007556218Z 49 PC: 12b81 | Terminate and stay resident (Return code = '1' | Memory size = '128')