Sample viewer

vx.netlux.org/Virus.DOS.Emmie.2241

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:05:04.242689917Z 42 PC: 15502 | Get date 0x15502: mov byte ptr [bp - 0x37], 0
0x15506: cmp cx, 0x7bc
0x1550a: je 0x1551a
0x1550c: cmp dh, byte ptr [bp - 0x49]
0x1550f: jne 0x1551a
0x15511: cmp cx, word ptr [bp - 0x48]
0x15514: jne 0x1551a
0x15516: mov byte ptr [bp - 0x37], 1
0x1551a: mov byte ptr [bp - 0x49], dh
0x1551d: mov word ptr [bp - 0x48], cx
0x15520: xor bx, bx
0x15522: mov ax, 0xface
0x15525: int 0x21
0x15527: cmp ax, 0xcefa
0x1552a: jne 0x15534
0x1552c: cmp bx, 7
0x1552f: jge 0x1554e
0x15531: call 0x25481
0x15534: mov ax, 0x2c00
0x15537: int 0x13
2018-12-17T23:05:04.260150036Z 250 PC: 15527 | UNKNOWN!
2018-12-17T23:05:04.26260497Z 53 PC: 9f477 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:05:04.264001115Z 53 PC: 9f486 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T23:05:04.265410368Z 53 PC: 9f495 | Get interrupt vector (Interrupt = '38' AKA 'Create PSP')
2018-12-17T23:05:04.267407556Z 53 PC: 9f606 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:05:04.268746959Z 37 PC: 9f624 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:05:04.270381363Z 25 PC: 9f634 | Get default drive
2018-12-17T23:05:04.27277318Z 37 PC: 9f643 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:05:04.274188747Z 53 PC: 9f53c | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:05:04.275523285Z 37 PC: 9f55a | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:05:04.278335499Z 37 PC: 9f57c | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:05:04.279697387Z 53 PC: 9f6c2 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:05:04.280936294Z 37 PC: 9f6da | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:05:04.283636515Z 37 PC: 9f6fd | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:05:04.285526601Z 37 PC: 9f883 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:05:04.286985719Z 53 PC: 9f883 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T23:05:04.293944563Z 37 PC: 9f883 | Set interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T23:05:04.295403529Z 53 PC: 9f883 | Get interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-17T23:05:04.296801987Z 37 PC: 9f883 | Set interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-17T23:05:04.298148469Z 53 PC: 9f883 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:05:04.314544642Z 37 PC: 9f883 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:05:04.316055702Z 99 PC: 14296 | Get DBCS lead byte table pointer
2018-12-17T23:05:04.317316354Z 68 PC: 142b0 | I/O control for devices (Set for = '')
2018-12-17T23:05:04.319158757Z 68 PC: 142bb | I/O control for devices (Set for = '')
2018-12-17T23:05:04.321258243Z 68 PC: 142c6 | I/O control for devices (Set for = '')
2018-12-17T23:05:04.32278057Z 68 PC: 142ce | I/O control for devices (Set for = '��b���g�t�S3����[r�2��W�<t�<u�6�u����>��>W')
2018-12-17T23:05:04.324718856Z 48 PC: 142d3 | Get DOS version
2018-12-17T23:05:04.326680287Z 64 PC: 14411 | Write file or device (Write 23 bytes on handle 2)
2018-12-17T23:05:04.332002322Z 76 PC: 131dc | Terminate with return code (Return code = '4')