Sample viewer

vx.netlux.org/Virus.DOS.LittBrother.395

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:55.414394821Z 42 PC: 12bca | Get date 0x12bca: ret
0x12bcb: fiadd word ptr [bx + si]
0x12bcd: add word ptr [bp - 0x47], dx
0x12bd0: mov byte ptr [bx + si], 0xc7
0x12bd3: add al, 0xd0
0x12bd5: mov dh, al
0x12bd7: inc sp
0x12bd8: add al, dl
0x12bda: xor word ptr [si], 0x6040
0x12bde: inc si
0x12bdf: inc si
0x12be0: loop 0x12bda
0x12be2: xor si, si
0x12be4: xor cx, cx
0x12be6: ret
0x12be7: add byte ptr [bx + di], ah
0x12be9: mov ax, 0x3000
0x12bec: int 0x21
0x12bee: cmp ax, 0x1606
0x12bf1: je 0x12c04
2018-12-17T23:06:55.577926921Z 37 PC: 12aad | Set interrupt vector (Interrupt = '33' AKA 'Random read')