Sample viewer

vx.netlux.org/Virus.DOS.V.343

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:05:23.316093134Z 44 PC: 13cbd | Get time 0x13cbd: cmp dl, 0x4a
0x13cc0: jne 0x13ccc
0x13cc2: mov dx, 0x3d4
0x13cc5: mov al, 0xd
0x13cc7: out dx, al
0x13cc8: inc dx
0x13cc9: mov al, 0x28
0x13ccb: out dx, al
0x13ccc: mov ax, 0x54
0x13ccf: mov ds, ax
0x13cd1: cmp byte ptr [0], 0x1e
0x13cd6: je 0x13d08
0x13cd8: cmp byte ptr [0xc0], 0xbe
0x13cdd: je 0x13d08
0x13cdf: call 0x13ce2
0x13ce2: pop di
0x13ce3: sub di, 0x2e
0x13ce7: mov bx, 0x157
0x13cea: mov al, byte ptr cs:[bx + di]
0x13ced: mov byte ptr [bx], al
2018-12-17T23:05:23.319315699Z 53 PC: 13cf7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:05:23.320672349Z 37 PC: 13d08 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:05:23.322053028Z 9 PC: 13bf5 | Display string (String= ' Ok , EXE test 1 completed ... ')
2018-12-17T23:05:23.328336865Z 76 PC: 13bf9 | Terminate with return code (Return code = '36')