Sample viewer

vx.netlux.org/Virus.DOS.DNA.1206.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:07:12.748316817Z 48 PC: 12b50 | Get DOS version
2018-12-17T23:07:12.75047827Z 44 PC: 12b55 | Get time 0x12b55: cmp dl, 0
0x12b58: je 0x12b51
0x12b5a: ret
0x12b5b: add al, ch
0x12b5d: add byte ptr [bx + si], al
0x12b5f: pop bp
0x12b60: sub bp, 4
0x12b63: mov dl, byte ptr [bp]
0x12b66: lea bx, word ptr [bp + 0x27]
0x12b69: nop
0x12b6a: cmp dl, 0
0x12b6d: je 0x12b7e
0x12b6f: mov dh, dl
0x12b71: mov cx, 0x475
0x12b74: xor byte ptr [bx], dl
0x12b76: sub dl, dh
0x12b78: sub dh, 0x2e
0x12b7b: inc bx
0x12b7c: loop 0x12b74
0x12b7e: ret
2018-12-17T23:07:12.753253718Z 48 PC: 12b50 | Get DOS version
2018-12-17T23:07:12.754899141Z 25 PC: 12cd8 | Get default drive
2018-12-17T23:07:12.757244179Z 71 PC: 12d5a | Get current directory
2018-12-17T23:07:12.76056381Z 222 PC: 12ed8 | UNKNOWN!
2018-12-17T23:07:12.761789785Z 61 PC: 12ee5 | Open file (Filename = '>v�u&�v')
2018-12-17T23:07:12.766531618Z 53 PC: 12ef2 | Get interrupt vector (Interrupt = '208' AKA 'UNKNOWN!')
2018-12-17T23:07:12.767946178Z 37 PC: 12f15 | Set interrupt vector (Interrupt = '208' AKA 'UNKNOWN!')
2018-12-17T23:07:12.768966225Z 53 PC: 12d78 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:07:12.769949093Z 37 PC: 12d88 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:07:12.771435427Z 53 PC: 12da6 | Get interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-17T23:07:12.772472767Z 44 PC: 12b55 | Get time 0x12b55: cmp dl, 0
0x12b58: je 0x12b51
0x12b5a: ret
0x12b5b: add al, ch
0x12b5d: add byte ptr [bx + si], al
0x12b5f: pop bp
0x12b60: sub bp, 4
0x12b63: mov dl, byte ptr [bp]
0x12b66: lea bx, word ptr [bp + 0x27]
0x12b69: nop
0x12b6a: cmp dl, 0
0x12b6d: je 0x12b7e
0x12b6f: mov dh, dl
0x12b71: mov cx, 0x475
0x12b74: xor byte ptr [bx], dl
0x12b76: sub dl, dh
0x12b78: sub dh, 0x2e
0x12b7b: inc bx
0x12b7c: loop 0x12b74
0x12b7e: ret
2018-12-17T23:07:12.774295152Z 47 PC: 12d5f | Get disk transfer address
2018-12-17T23:07:12.775988165Z 26 PC: 12d6b | Set disk transfer address