Sample viewer

vx.netlux.org/Virus.DOS.TPE.Duwende.1849

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:53.733001778Z 255 PC: 12b2e | UNKNOWN!
2018-12-17T23:04:53.733960602Z 74 PC: 12b49 | Reallocate memory
2018-12-17T23:04:53.735886534Z 72 PC: 12b51 | Allocate memory
2018-12-17T23:04:53.738557076Z 44 PC: 9fb47 | Get time 0x9fb47: in al, 0x40
0x9fb49: mov ah, al
0x9fb4b: in al, 0x40
0x9fb4d: xor ax, cx
0x9fb4f: xor dx, ax
0x9fb51: jmp 0x9fb70
0x9fb53: push dx
0x9fb54: push cx
0x9fb55: push bx
0x9fb56: in al, 0x40
0x9fb58: add ax, 0xa77d
0x9fb5b: mov dx, 0xb2b6
0x9fb5e: mov cx, 7
0x9fb61: shl ax, 1
0x9fb63: rcl dx, 1
0x9fb65: mov bl, al
0x9fb67: xor bl, dh
0x9fb69: jns 0x9fb6d
0x9fb6b: inc al
0x9fb6d: loop 0x9fb61
2018-12-17T23:04:53.74125519Z 53 PC: 9f4d9 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:53.74342978Z 37 PC: 9f4e8 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:53.744956581Z 9 PC: 12ad3 | Display string (String= ' Mabuhay! This program came from Bahay Kawayan at http://come.to/hexfiles Putoksa Kawayan [email protected] ')
2018-12-17T23:04:53.758809964Z 76 PC: 12ad7 | Terminate with return code (Return code = '36')