Sample viewer

vx.netlux.org/Virus.DOS.LittBrother.393

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:07:39.730411176Z 42 PC: 12bc8 | Get date 0x12bc8: ret
0x12bc9: mov ax, 0x5801
0x12bcc: int 0x21
0x12bce: mov bl, ch
0x12bd0: shr bl, 1
0x12bd2: xor bh, bh
0x12bd4: mov ax, 0x5803
0x12bd7: int 0x21
0x12bd9: retf
0x12bda: add byte ptr [bx + si], al
0x12bdc: add byte ptr [bx + si], al
0x12bde: add byte ptr [bx + si], al
0x12be0: mov sp, 0x60a
0x12be3: mov ah, 0x50
0x12be5: mov bx, es
0x12be7: int 0x21
0x12be9: mov ax, 0x3000
0x12bec: int 0x21
0x12bee: cmp ax, 0x1606
0x12bf1: je 0x12c04
2018-12-17T23:07:39.919505333Z 37 PC: 12aac | Set interrupt vector (Interrupt = '33' AKA 'Random read')