Sample viewer

vx.netlux.org/Virus.DOS.Xtac.1564

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:07:01.153540409Z 186 PC: 1ab50 | UNKNOWN!
2018-12-17T23:07:01.155833863Z 53 PC: 12e8e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:01.157344322Z 37 PC: 12ea5 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:07:01.159141815Z 73 PC: 12dc7 | Release memory
2018-12-17T23:07:01.161676437Z 49 PC: 12dc7 | Terminate and stay resident (Return code = '147' | Memory size = '121')
2018-12-17T23:07:01.171136416Z 48 PC: 12dc7 | Get DOS version
2018-12-17T23:07:01.173165538Z 75 PC: 12dc7 | Execute program
2018-12-17T23:07:01.20070856Z 48 PC: 18a84 | Get DOS version
2018-12-17T23:07:01.202781965Z 74 PC: 18ae6 | Reallocate memory
2018-12-17T23:07:01.205053365Z 48 PC: 17068 | Get DOS version
2018-12-17T23:07:01.206959424Z 53 PC: 17070 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:01.20917105Z 37 PC: 17082 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:01.211133799Z 68 PC: 17106 | I/O control for devices (Set for = '�V����')
2018-12-17T23:07:01.213297441Z 68 PC: 17106 | I/O control for devices
2018-12-17T23:07:01.220960893Z 68 PC: 17106 | I/O control for devices (Set for = '')
2018-12-17T23:07:01.222695522Z 68 PC: 17106 | I/O control for devices (Set for = '')
2018-12-17T23:07:01.224873237Z 68 PC: 17106 | I/O control for devices (Set for = '')
2018-12-17T23:07:01.228672099Z 99 PC: 18dbb | Get DBCS lead byte table pointer
2018-12-17T23:07:01.230245439Z 68 PC: 18dd5 | I/O control for devices (Set for = '')
2018-12-17T23:07:01.23190948Z 68 PC: 18de0 | I/O control for devices (Set for = '')
2018-12-17T23:07:01.234357798Z 68 PC: 18deb | I/O control for devices (Set for = '')
2018-12-17T23:07:01.239952183Z 68 PC: 18df3 | I/O control for devices (Set for = '��b���g�t�S3����[r�2��W�<t�<u�6�u����>��>W')
2018-12-17T23:07:01.254384151Z 48 PC: 18df8 | Get DOS version
2018-12-17T23:07:01.25808538Z 64 PC: 19073 | Write file or device (Write 23 bytes on handle 2)
2018-12-17T23:07:01.264201237Z 37 PC: 1719b | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:07:01.266026353Z 76 PC: 17184 | Terminate with return code (Return code = '1')
2018-12-17T23:07:01.269587642Z 42 PC: 12dc7 | Get date 0x12dc7: ret
0x12dc8: mov cx, 0x21
0x12dcb: xor dx, dx
0x12dcd: lodsw ax, word ptr [si]
0x12dce: add dx, ax
0x12dd0: loop 0x12dcd
0x12dd2: cmp dx, 0xf456
0x12dd6: je 0x12dd9
0x12dd8: stc
0x12dd9: ret
0x12dda: xor dx, dx
0x12ddc: xor cx, cx
0x12dde: mov bx, word ptr cs:[0xa]
0x12de3: mov ax, 0x4200
0x12de6: call 0x22db7
0x12de9: ret
0x12dea: mov dx, word ptr [6]
0x12dee: mov cx, word ptr [8]
0x12df2: mov ax, 0x4200
0x12df5: call 0x22db7
2018-12-17T23:07:01.273210748Z 77 PC: 12dc7 | Get program return code